<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Order of preference of source for user and ip mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220930#M63671</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;Thanks. It make sense. Also for one user, I am seeing two IP and both source is AD. How is it possible? The user login on domain machine and one entry is showing IP of that machine. He is also login through remote access VPN (integrated with AD) and other entry showing IP is from remote pool. Any explaination of this?&lt;/P&gt;</description>
    <pubDate>Fri, 06 Jul 2018 14:59:45 GMT</pubDate>
    <dc:creator>faizankhurshid</dc:creator>
    <dc:date>2018-07-06T14:59:45Z</dc:date>
    <item>
      <title>Order of preference of source for user and ip mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220860#M63659</link>
      <description>&lt;P&gt;Hello All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If same user information is coming from AD and from other source like Cisco ISE syslog messages then which one takes preference in firewall?&lt;/P&gt;&lt;P&gt;Also who can I verify that both sources are sending user/ip mapping? As I always see source AD using command 'show user ip-user-mapping'&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 10:09:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220860#M63659</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-07-06T10:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Order of preference of source for user and ip mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220886#M63661</link>
      <description>&lt;P&gt;I don't think there's a "preference" it's "which has most recently occurred."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is an initial update for IP address 1.1.1.1 that came from UIA at 0100hrs.&amp;nbsp; Then for whatever reason there was a CP/SSO update for the same IP of 1.1.1.1 at 0101hrs this would replace the UIA.&amp;nbsp; Then another update from ISE/syslog for the same IP at 0110hrs the recent CP entry would be replace.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is my understanding of how IP mapping works.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 12:49:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220886#M63661</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-07-06T12:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: Order of preference of source for user and ip mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220930#M63671</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;Thanks. It make sense. Also for one user, I am seeing two IP and both source is AD. How is it possible? The user login on domain machine and one entry is showing IP of that machine. He is also login through remote access VPN (integrated with AD) and other entry showing IP is from remote pool. Any explaination of this?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 14:59:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220930#M63671</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-07-06T14:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Order of preference of source for user and ip mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220932#M63673</link>
      <description>&lt;P&gt;You can have 10, 20 (limitless) unique IP to singular user ID mappings.&amp;nbsp; If your agent has it registered then the host machine the user is on, at one point must have authenticated with the second recorded IPs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know I've had 6 or 7 unique IPs tied to my user ID.&amp;nbsp; (RDPing into servers / VPN ... and whatnot)&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 15:07:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220932#M63673</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-07-06T15:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: Order of preference of source for user and ip mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220986#M63675</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;already pointed out the number of IP addresses that a user can be mapped to is a limitless number (outside of the platform limits for UID). I often have users who have upwards of 10 IPs tied to their account due to logging into multiple development or software servers at any one time; one of my System Engineers often have 15+ IPs mapped to his username.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jul 2018 00:49:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/220986#M63675</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-07T00:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Order of preference of source for user and ip mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/221003#M63685</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;thanks. So one user can have mulitple IP but one IP can only be tied to one user? Like one single machine, mulitple account cannot be login simultaneously? It will give bind IP of machine to last login user?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jul 2018 06:34:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/221003#M63685</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-07-07T06:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Order of preference of source for user and ip mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/222408#M63962</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;thanks. So one user can have mulitple IP but one IP can only be tied to one user?&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, an IP will only ever be tied to a single user.&amp;nbsp; Everytime the firewall gets an update to a specific user ID being tied to a specific IP that new ID will replace what was previously identified as being associated to the IP address.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 15:31:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/order-of-preference-of-source-for-user-and-ip-mapping/m-p/222408#M63962</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-07-16T15:31:06Z</dc:date>
    </item>
  </channel>
</rss>

