<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Service - Client IP Population in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216695#M62744</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for the reply on this.&amp;nbsp; So i started completley from scratch on my configuration in attempts to more easily troubleshoot.&amp;nbsp; Without any networks in the include list, I get no IP addresses in the Monitoring Tab under discovered users.&amp;nbsp; When I add an office IP range to the Discovery, i start seeing logs such as these.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP x.x.x.x is not in the include list&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I add one of these networks which I know has users on it, the error in debug goes away, but the Monitor still shows 0 IPs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15383i36AA7A8CE69DD489/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It's almost like it is seeing the IP's from the domain controllers as it writes them in the log, but then is not saving them.&amp;nbsp; This is why I was asking about normal operation with just log reading on as I was thinking perhaps monitoring only was for addresses that were also polled. Completely confused here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jun 2018 17:13:42 GMT</pubDate>
    <dc:creator>mlinsemier</dc:creator>
    <dc:date>2018-06-05T17:13:42Z</dc:date>
    <item>
      <title>User-ID Service - Client IP Population</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216586#M62731</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we first installed our User-ID Agent service on Windows Server 4-5 years ago we implemented Security Log Reading (from domain controllers logs), AD Session Scanning, and MWI polling.&amp;nbsp; About 5-6 days ago we started running into issues (which we have yet to determine what is causing it), where polling seems to be openeing up multiple connections at a time causing our WAN optimizer to start trying to optimize 10x connections than normal.&amp;nbsp; After delving into the latest best practices, it seems that Session Scanning and MWI polling are no longer recommended, and just reading the AD logs and Syslogs are the best way to go.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question:&amp;nbsp; If I just enable reading the windows logs from the domain controllers, should it be populating the User-ID agent with IP addresses of users?&amp;nbsp; When I turn off session scanning and WMI probing, the IP list is empty.&amp;nbsp; As I've always used all three options, I'm not sure if what is "normal" and I can't find any supporting documentation that explains one way or the other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 01:25:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216586#M62731</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-06-05T01:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Service - Client IP Population</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216612#M62732</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7143"&gt;@mlinsemier&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes, log reading is the main way to populate user-ip mappings&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Logs contain a username + ip which are learned when a user logs on&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WMI probes are used on 'known' ip-user maps to verify if the user is still logged on, or, for 'unknown' ips to probe if a user can be learned (this happens when the firewall gets a connection from an unmapped IP in the user-id enabled zones, it will request the user-id agent for informnation on the IP and if the agent does not already have a mapping it will try a probe)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;'server session reads' are used to detect users with mapped network drives (whenever the drive is touched, the user source + credentials can be refreshed/learned)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so, since your WAN optimizer went into overdrive, and after disabling probing your ip's aren't populating, your log reading may have gotten disabled somehow, causing you to start probing every single IP rather than learning ip's from the log and only periodically probing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 08:00:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216612#M62732</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-06-05T08:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Service - Client IP Population</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216695#M62744</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks for the reply on this.&amp;nbsp; So i started completley from scratch on my configuration in attempts to more easily troubleshoot.&amp;nbsp; Without any networks in the include list, I get no IP addresses in the Monitoring Tab under discovered users.&amp;nbsp; When I add an office IP range to the Discovery, i start seeing logs such as these.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP x.x.x.x is not in the include list&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP x.x.x.x is not in the include list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I add one of these networks which I know has users on it, the error in debug goes away, but the Monitor still shows 0 IPs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15383i36AA7A8CE69DD489/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It's almost like it is seeing the IP's from the domain controllers as it writes them in the log, but then is not saving them.&amp;nbsp; This is why I was asking about normal operation with just log reading on as I was thinking perhaps monitoring only was for addresses that were also polled. Completely confused here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 17:13:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216695#M62744</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-06-05T17:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Service - Client IP Population</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216711#M62750</link>
      <description>The IPs under the x.x.x.x, are they in your expected subnet? It could be that the firewall is polling your agent for "unknown" IPs and that's whats causing these logs (without filter you should get _all_ ips from log)&lt;BR /&gt;&lt;BR /&gt;Just as a sanity check, can you go through the windows event viewer to see if you can find any EventID 4768 (Authentication Ticket Granted), 4769 (Service Ticket Granted), 4770 (Ticket Granted Renewed), or 4624 (Logon Success) logs?&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Jun 2018 18:18:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216711#M62750</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-06-05T18:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Service - Client IP Population</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216713#M62751</link>
      <description>&lt;P&gt;Okay, that makes sense because I paired down the "Allowed IPs" that the remote Palo Alto's are looking for IP to User Mappings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the audit events, are you speaking of the Event Viewer on the domain controller itself?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jun 2018 18:44:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216713#M62751</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-06-05T18:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Service - Client IP Population</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216714#M62752</link>
      <description>Yes, the server that the userID agent is polling should have at least one of these events in the eventviewer&lt;BR /&gt;If they dont show up, you'll want to go into your local security policy and enable auditing for "logon success"</description>
      <pubDate>Tue, 05 Jun 2018 18:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-service-client-ip-population/m-p/216714#M62752</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-06-05T18:51:45Z</dc:date>
    </item>
  </channel>
</rss>

