<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: don't understand the user identification difference between pan-agent of the  and userid-agent. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9228#M6755</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Once users are identified by the agent, their usernames will be populated in the traffic and URL logs.&amp;nbsp; For those users not identified the log field will be blank.&amp;nbsp; This will be true regardless if AD groups are used or not used in security rules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Mar 2012 18:09:09 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-03-13T18:09:09Z</dc:date>
    <item>
      <title>don't understand the user identification difference between pan-agent of the  and userid-agent.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9223#M6750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I use PAN-OS 4.1.3 for test about user identification. I try to use pan-agent by set LDAP server profile and set mapping group already. Then I can use only user groups of AD (user name in group not show) in security policy but can't see user name in "source user" in traffic log.&amp;nbsp; In case I use UserID-agent,&amp;nbsp; I will use user name from AD in security policy and show user name in traffic log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is it correct ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Feb 2012 13:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9223#M6750</guid>
      <dc:creator>manaschai</dc:creator>
      <dc:date>2012-02-23T13:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: don't understand the user identification difference between pan-agent of the  and userid-agent.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9224#M6751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes correct once you install the UserID Agent you can start to use AD usernames in policies and you can see AD usernames in traffic logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgds Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Feb 2012 13:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9224#M6751</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2012-02-23T13:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: don't understand the user identification difference between pan-agent of the  and userid-agent.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9225#M6752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you for your reply&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Feb 2012 00:49:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9225#M6752</guid>
      <dc:creator>manaschai</dc:creator>
      <dc:date>2012-02-24T00:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: don't understand the user identification difference between pan-agent of the  and userid-agent.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9226#M6753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For PAN-OS 4.1.3, you should use the 4.1.3-2 UserID agent to monitor the DC's for user logins.&amp;nbsp;&amp;nbsp; This will produce the usernames in the traffic log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you set the LDAP server, LDAP profile, and the group mapping on the PAN device, this will query the group memberships and make them available to the security rules.&amp;nbsp; There, you can define policies for source user=AD users and./or AD groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Feb 2012 04:32:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9226#M6753</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-24T04:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: don't understand the user identification difference between pan-agent of the  and userid-agent.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9227#M6754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Follow-up question on this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the statements above, it seems to indicate that MS AD user names are not populated into the traffic or URL logs if the access control is based on MS AD group memberships?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2012 17:30:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9227#M6754</guid>
      <dc:creator>jasbeck</dc:creator>
      <dc:date>2012-03-13T17:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: don't understand the user identification difference between pan-agent of the  and userid-agent.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9228#M6755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Once users are identified by the agent, their usernames will be populated in the traffic and URL logs.&amp;nbsp; For those users not identified the log field will be blank.&amp;nbsp; This will be true regardless if AD groups are used or not used in security rules. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2012 18:09:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9228#M6755</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-03-13T18:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: don't understand the user identification difference between pan-agent of the  and userid-agent.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9229#M6756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is that also true for LDAP being proxied through the user id agent 4.1.3-2? Our environment does not lend itself well to LDAP queries from the PAN device, so instead have to leverage the LDAP proxy option through the user id agents. Does this in essence make the 4.1.3-2 agents function like 3.1's?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2012 18:13:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9229#M6756</guid>
      <dc:creator>jasbeck</dc:creator>
      <dc:date>2012-03-13T18:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: don't understand the user identification difference between pan-agent of the  and userid-agent.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9230#M6757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I apologize as I don't understand your question on the LDAP proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 3.1, the agent is perfoming both the user identification and group membership lookup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 4.1, the agent is doing user identification only.&amp;nbsp; The group membership lookup is done on the PA firewall itself, and this lookup is using LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2012 17:03:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/don-t-understand-the-user-identification-difference-between-pan/m-p/9230#M6757</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-03-14T17:03:40Z</dc:date>
    </item>
  </channel>
</rss>

