<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Aruba Wireless Authentication User-IP Mapping Question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232506#M66685</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32429"&gt;@Dan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Generally for something like this I would actually build it out with the API and not the&amp;nbsp; user-id agent.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Sep 2018 18:41:12 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-09-26T18:41:12Z</dc:date>
    <item>
      <title>Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232497#M66683</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an Aruba Instant Cluster with an SSID set up to user a radius server to authenticate users. The cluster controller is configured to send syslog data to a Paloalto User Agent running on a Windows server. I've had this set up for a time but am now moving in to a updated OS (Windows 2016) and updated UA (8.0.10-7). My question revolves around wireless disconnects, when radius authenticated users leave the cluster or shut down their devices, I'd like the user-ip mapping to get deleted. In the syslog I get this to capture the authentication and mapping:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2018-09-26 11:12:36 Local1.Notice 10.54.132.240 Sep 26 11:12:36 2018 10.54.132.240 stm[2367]: &amp;lt;501199&amp;gt; &amp;lt;NOTI&amp;gt; &amp;lt;10.1.1.1 AC:A3:1E:C2:D2:9C&amp;gt; User authenticated, mac-a0:cc:2b:80:ad:bb, username-jsmith, IP-10.2.2.2, method-802.1x, role-PrivateSSID&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I don't see anything in the log that captures the disconnect that includes the user name. I do have this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2018-09-26 11:13:39&amp;nbsp;&amp;nbsp; &amp;nbsp;Local1.Notice&amp;nbsp;&amp;nbsp; &amp;nbsp;10.54.132.240&amp;nbsp;&amp;nbsp; &amp;nbsp;Sep 26 11:13:39 2018 10.54.132.240 stm[2367]: &amp;lt;501217&amp;gt; &amp;lt;NOTI&amp;gt; &amp;lt;10.1.1.1 AC:A3:1E:C2:D2:9C&amp;gt;&amp;nbsp; update_ip_mac_role_acl_vlan 15467: user entry deleted for 10.2.2.2-a0:cc:2b:80:ad:bb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in building the syslog logoff filter in the UA GUI, it seems 'username' is required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have suggestions on how I can build out a user agent logoff filter that can capture the wireless client disconnects?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 18:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232497#M66683</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2018-09-26T18:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232506#M66685</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32429"&gt;@Dan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Generally for something like this I would actually build it out with the API and not the&amp;nbsp; user-id agent.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 18:41:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232506#M66685</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-26T18:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232513#M66691</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I havent' worked with the API, where would be a good place to start?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 19:10:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232513#M66691</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2018-09-26T19:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232535#M66701</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32429"&gt;@Dan&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/xml-api/pan-os-xml-api-request-types/apply-user-id-mapping-and-populate-dynamic-address-groups-api#26454" target="_self"&gt;HERE's&lt;/A&gt; some decent documentation that is based on 7.1. Process is the same though&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 19:28:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232535#M66701</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-26T19:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232688#M66750</link>
      <description>&lt;P&gt;We also have Aruba and Palo Alto, but we chose to have our wireless controllers (campus, not Instant) send syslog data directly to the firewall instead of to a Windows server. See if you can find the string 'User de-authenticated' in your controllers logs, those entries should include the user name.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 13:26:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/232688#M66750</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2018-09-27T13:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/234974#M67365</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are you using the built in user-id agent and sending the syslog data to that or are you using the API as BPry suggested above? If you're sending/using the syslog data are you doing a regex expression and might you be able to share what that looks like?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 17:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/234974#M67365</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2018-10-11T17:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/235105#M67403</link>
      <description>&lt;P&gt;We are sending syslog from the controllers direct to our firewall. What you need to do is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;Go to Device -&amp;gt; User Identification and click on the Settings Button for Palo Alto Networks User-ID Agent Setup&lt;/P&gt;&lt;P&gt;2. Go to the tab called Syslog Filters and add the following two profiles:&lt;/P&gt;&lt;PRE&gt;Syslog Parse Profile:	Aruba Login
Type:			Field Identifier
Event String:		Authentication Successful
Username Prefix:	username=
Username Delimiter:	\s
Address Prefix:		IP=
Address Delimiter:	\s

Syslog Parse Profile:	Aruba Logout
Type:			Field Identifier
Event String:		User de-authenticated
Username Prefix:	name=
Username Delimiter:	\s
Address Prefix:		IP=
Address Delimiter:	\s&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Add all your controllers and/or IAPs as Syslog Sender under Device -&amp;gt; User Identification -&amp;gt; Server Monitoring on PA.&amp;nbsp;Set your AD domain as Default Domain Name and set the two Syslog Parse Profiles you added in step 2 as filter for events login and logout repsectively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are other steps you need to do also of course, like configure controllers/IAPs to send syslog to PA for user events. Let me know if you need more info.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS!&amp;nbsp;If I remember correctly the logout event&amp;nbsp;(User de-authenticated) will be logged&amp;nbsp;on controllers if the user manually disconnects from the wireless network. If the device is removed from the wireless network without disconnecting I don't think anything will be logged and the IP-user-mapping will timout on PA according to your setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: I think support for the logout event came in PAN-OS 8. Earlier versions have only login events.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 12:52:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/235105#M67403</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2018-10-12T12:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/246586#M70202</link>
      <description>&lt;P&gt;Hi TerjeLundbo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please, could you post the syslog settings for an Aruba controller?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 09:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/246586#M70202</guid>
      <dc:creator>AndrewLeaver</dc:creator>
      <dc:date>2019-01-18T09:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/246744#M70253</link>
      <description>&lt;P&gt;This worked with me like a charm!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aruba-pc.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18354iD625EDD8428BAFCA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="aruba-pc.png" alt="aruba-pc.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aruba-phone.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18355i67E5774DB46E9D3E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="aruba-phone.png" alt="aruba-phone.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jan 2019 14:35:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/246744#M70253</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2019-01-20T14:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba Wireless Authentication User-IP Mapping Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/246788#M70262</link>
      <description>&lt;P&gt;On each wireless controller you need to enable logging of user authentications and you need to send each authentication event as syslog to the firewall. Commands are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;logging level notifications user process authmgr&lt;BR /&gt;logging &amp;lt;FW&amp;nbsp;IP&amp;nbsp;address&amp;gt; type user severity notifications facility local1 source-interface &amp;lt;mgmt vlan of the controller&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 12:00:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-wireless-authentication-user-ip-mapping-question/m-p/246788#M70262</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2019-01-21T12:00:32Z</dc:date>
    </item>
  </channel>
</rss>

