<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID/Facebook allow group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-facebook-allow-group/m-p/216350#M62675</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Best place to start would be the logs to see which rule is getting hit. Also I always put allow rules before deny rules just in case they conflict.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jun 2018 19:00:06 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-06-01T19:00:06Z</dc:date>
    <item>
      <title>User-ID/Facebook allow group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-facebook-allow-group/m-p/216291#M62667</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having trouble with this configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a Windows domain environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I installed User-ID on server and confirmed User-ID is running and IP/user mapping is all listed in the monitoring log.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User-ID agent is connected in the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created two AD groups one that permits FB and one that blocks it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created two security rules with two different URL Filtering profiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One URL filtering profile blocks FB the other doesnt.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tagged a group to each rule: (I tweaked the original inbound to outbound rule that was in place before enabling User-ID). The rule without the user tagging worked previous.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ex.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Allow Group has the URL filtering that allows FB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Block Group has the URL filtering that blocks FB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the FB block group precedes the FB allow group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I enable these rules-all outbound traffic stops&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure why...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 15:13:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-facebook-allow-group/m-p/216291#M62667</guid>
      <dc:creator>hussein.gure</dc:creator>
      <dc:date>2018-06-01T15:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID/Facebook allow group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-facebook-allow-group/m-p/216350#M62675</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Best place to start would be the logs to see which rule is getting hit. Also I always put allow rules before deny rules just in case they conflict.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 19:00:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-facebook-allow-group/m-p/216350#M62675</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-01T19:00:06Z</dc:date>
    </item>
  </channel>
</rss>

