<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ignoring Users in Mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ignoring-users-in-mapping/m-p/219419#M63368</link>
    <description>&lt;P&gt;If the users are being learned, you have probing enabled: when an unknown IP connects to the firewall, the firewall will ask the UserID agent for information. if it does not havbe a mapping and probing is enabled, it will then probe the IP and detect the local account&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Probing has pro's and cons: it will also periodically probe existing mappings and if a user has logged out or moved to a new ip (wifi roaming), the no-longer-active session/unused ip will be cleared from mapping. This helps prevent other iusers swooping in and abusing the previous user's mappings access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so the best option is to simply exclude the admin accounts from being registered, through the ignore_user_list.txt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jun 2018 08:39:30 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-06-27T08:39:30Z</dc:date>
    <item>
      <title>Ignoring Users in Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignoring-users-in-mapping/m-p/219397#M63364</link>
      <description>&lt;P&gt;Howdy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry if this has been asked thousands of times, but I cannot seem to locate something quite similiar.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have noticed recently, that some users are logging in with a local computer account and then obviously being able to browse the internet falling into a catch all rule for 'Known Users' which is required.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was suggested, as an option that we try to not learn them as 'known Users' etc.&amp;nbsp; However, I am not sure how we would handle that in our case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that the workstation name is not constant like if the user were coming in with their domain\username, so the users are appearing as below in the user mapping tables:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mn2343234\administrator&lt;BR /&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mn12345\administrator&lt;/P&gt;&lt;P&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mn56789\administrator&lt;/P&gt;&lt;P&gt;etc etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if I am reading things correctly the only way to stop this access is that we would need to somehow make that text file the agent uses on the server dynamic and populate it with computer name/username items one per line, then restart the agent to apply the settings? Is there another easier way to ignore these users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 04:06:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignoring-users-in-mapping/m-p/219397#M63364</guid>
      <dc:creator>PIRSA</dc:creator>
      <dc:date>2018-06-27T04:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Ignoring Users in Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignoring-users-in-mapping/m-p/219419#M63368</link>
      <description>&lt;P&gt;If the users are being learned, you have probing enabled: when an unknown IP connects to the firewall, the firewall will ask the UserID agent for information. if it does not havbe a mapping and probing is enabled, it will then probe the IP and detect the local account&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Probing has pro's and cons: it will also periodically probe existing mappings and if a user has logged out or moved to a new ip (wifi roaming), the no-longer-active session/unused ip will be cleared from mapping. This helps prevent other iusers swooping in and abusing the previous user's mappings access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so the best option is to simply exclude the admin accounts from being registered, through the ignore_user_list.txt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 08:39:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignoring-users-in-mapping/m-p/219419#M63368</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-06-27T08:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Ignoring Users in Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignoring-users-in-mapping/m-p/219520#M63390</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;One option would be to use user-id in your allow internet browsing policy. Then anyone who is not a 'domain user' would not be able to browse the internet. In the past I used the group 'Domain User' if anything fell outside of it it would fall int oa more stringent policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 17:12:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignoring-users-in-mapping/m-p/219520#M63390</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-27T17:12:23Z</dc:date>
    </item>
  </channel>
</rss>

