<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with Captive Portal authenticated by User AD in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8622#M6356</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you ever changed timeout settings on User-id client? If not, then go ahead and change the value to 120 from 45, then commit on user-id client. Reset the connection one more time "&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;debug user-id reset user-id-agent &amp;lt;name&amp;gt;&lt;/SPAN&gt;". And see if mapping is stable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="snap_shot.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4438_snap_shot.PNG" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Oct 2012 13:09:05 GMT</pubDate>
    <dc:creator>ssharma</dc:creator>
    <dc:date>2012-10-11T13:09:05Z</dc:date>
    <item>
      <title>Problem with Captive Portal authenticated by User AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8619#M6353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I got a problem when I use captive portal authenticated by user AD&lt;/P&gt;&lt;P&gt;- First, I install Palo Alto User Agent on AD machine, this job worked fine. On the traffic log of PA, I saw User AD.&lt;/P&gt;&lt;P&gt;- After that, I configure captive portal on PA and it works too, the user AD no need to login to Captive Portal (CP) and user not in AD must login via CP to use network resources. But after 30 mins, the problem occur some of users already in AD must login via CP to use network resources too. And after one day, all of users AD must login via CP.&lt;/P&gt;&lt;P&gt;- The PAN OS that I used is 4.1.7 and the User Agent version 4.1.4-3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone met this issue? Any advise? Please help, thank so much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 01:23:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8619#M6353</guid>
      <dc:creator>nguyenma</dc:creator>
      <dc:date>2012-10-11T01:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Captive Portal authenticated by User AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8620#M6354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems like there is some issue with user to ip-mapping. First check user-id agent status :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show user user-id-agent state all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Agent: usr_id(vsys: vsys1) Host: &amp;lt;agent-ip&amp;gt;:5007&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : conn:idle(Connected to &amp;lt;agent-ip&amp;gt;(source: mgt-ip))&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should say "connected". Also on the agent, check if you are seeing users and also make sure user-id agent service is running. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the option that you can try is to reset the connection between user-id agent and firewall :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug user-id reset user-id-agent &amp;lt;name&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After above, run "show user ip-user-mapping all". You should all your users. This should resolve your issue. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 02:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8620#M6354</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2012-10-11T02:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Captive Portal authenticated by User AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8621#M6355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank for your reply,&lt;/P&gt;&lt;P&gt;I already checked the agent status, it shows "connected". I also reset the connection, it can help but after a period of time, it happen again although the agent status still "connected". I think this is OS bug. Any advise?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 05:11:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8621#M6355</guid>
      <dc:creator>nguyenma</dc:creator>
      <dc:date>2012-10-11T05:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Captive Portal authenticated by User AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8622#M6356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you ever changed timeout settings on User-id client? If not, then go ahead and change the value to 120 from 45, then commit on user-id client. Reset the connection one more time "&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;debug user-id reset user-id-agent &amp;lt;name&amp;gt;&lt;/SPAN&gt;". And see if mapping is stable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="snap_shot.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4438_snap_shot.PNG" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 13:09:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8622#M6356</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2012-10-11T13:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Captive Portal authenticated by User AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8623#M6357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your help. I think it stable now &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 14:07:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-captive-portal-authenticated-by-user-ad/m-p/8623#M6357</guid>
      <dc:creator>nguyenma</dc:creator>
      <dc:date>2012-10-11T14:07:07Z</dc:date>
    </item>
  </channel>
</rss>

