<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user-id user on servers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229402#M65953</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&lt;/P&gt;&lt;P&gt;In most cases physical firewalls (with vsys enabled).&lt;/P&gt;&lt;P&gt;Are you asking about the access frol the servers or the access to the servers? The second is also restricted with groups on the servers itself to the people that need access.&lt;/P&gt;</description>
    <pubDate>Tue, 04 Sep 2018 16:10:55 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-09-04T16:10:55Z</dc:date>
    <item>
      <title>user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/228767#M65765</link>
      <description>&lt;P&gt;How do I stop users who are working on servers from apearing in the logs as matched user-id users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 16:15:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/228767#M65765</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-29T16:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/228781#M65766</link>
      <description>&lt;P&gt;Best way for me was to only allow server admin via a server admin account. Then add them to the user ignore list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 20:03:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/228781#M65766</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-29T20:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/228782#M65767</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I didn't go quite as far as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;; but I did give everyone a seperate 'server-admin' account so that I could ignore just those users with the user ignore list.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 20:40:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/228782#M65767</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-29T20:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/228995#M65819</link>
      <description>&lt;P&gt;Ahh right, had not spotted the ignore list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Guess it will be good for 99% of what we do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 10:52:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/228995#M65819</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-31T10:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229038#M65834</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What we did, it was unintentional but would work in this case, was to only look at Exchange logs. Since our admin accounts dont have email accounts and we dont allow outlook on servers, we dont see user-id's on servers since moving away from active-directory lookups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 16:39:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229038#M65834</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-08-31T16:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229100#M65863</link>
      <description>&lt;P&gt;... or you simply exclude the servernetworks from user-id. This way these users still show up in the logs when they work from a computer in a clientnetwork.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 12:10:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229100#M65863</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-01T12:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229106#M65869</link>
      <description>&lt;P&gt;Hmmm so what is the other 1%......&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 17:59:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229106#M65869</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-01T17:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229107#M65870</link>
      <description>&lt;P&gt;why wouldn't you want to see the admin accounts in the logs? Wouldn't you want to know what they're doing?&lt;/P&gt;</description>
      <pubDate>Sat, 01 Sep 2018 18:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229107#M65870</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-01T18:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229152#M65889</link>
      <description>&lt;P&gt;Thats a valid point&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&amp;nbsp;but we never allow our servers to connect to tinternet.&lt;/P&gt;&lt;P&gt;as soon as a valid user is associated with the server it goes off and does all manner of things..&lt;/P&gt;&lt;P&gt;We could have achieved this via security policy but ignoring users works for us, not everybodys cup of tea...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;others may haVe different reasons.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Sep 2018 18:35:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229152#M65889</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-02T18:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229200#M65902</link>
      <description>&lt;P&gt;We have servers that get DNS (this is required to make the world work)&lt;/P&gt;&lt;P&gt;We have servers that connect to SMTP ( e-mail seems to be a requirement of modern living)&lt;/P&gt;&lt;P&gt;Servers that transfer business related files ( SFTP, FTPS, ETC...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All these run as service accounts, they don't generate a USER-ID...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as an admin logs in, they become the associated user of this "server" traffic. Anythign they may really be initiatin gets lost. So it's a bit pointless.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 07:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229200#M65902</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-09-03T07:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229206#M65904</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;As soon as an admin logs in, they become the associated user of this "server" traffic. Anythign they may really be initiatin gets lost. So it's a bit pointless.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thats why we exclude the servernetworks completely. All servers have specific firewallrules for exactly what they need without internet access. The logins on the servers are restricted to the users that really need to install/change something on the servers, so it isn't possible that an admin from team A connects to a server of team B. So at least in our case it makes more sense to exclude the networks instead of the users, just in case an admin somehow logs in on a device located in the clientnetwork we will see this also in the firewalllogs.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 08:32:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229206#M65904</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-03T08:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229304#M65918</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;unrelated to the topic I guess, but are you using virtual firewalls to control that server access?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 21:44:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229304#M65918</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-09-03T21:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: user-id user on servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229402#M65953</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&lt;/P&gt;&lt;P&gt;In most cases physical firewalls (with vsys enabled).&lt;/P&gt;&lt;P&gt;Are you asking about the access frol the servers or the access to the servers? The second is also restricted with groups on the servers itself to the people that need access.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 16:10:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-on-servers/m-p/229402#M65953</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-04T16:10:55Z</dc:date>
    </item>
  </channel>
</rss>

