<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user if agent and switching between ids in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237758#M68120</link>
    <description>&lt;P&gt;So your scenario, if I understand it, is that you have a user using "switch user" in Windows to switch between sessions?&amp;nbsp; And after he switches to a new session, he can no longer access what he wants to on the network, because the user account that he switched to doesn't meet your rule User-ID criteria?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That sort of sounds like it is working as intended, or else you need to add the account that he's switching to into the rule User-ID criteria.&amp;nbsp; Adding the user account that he's switching to into the user-ignore-list.txt would prevent that account from being "learned" by the Palo Alto - ever.&amp;nbsp; Not just on this machine...any time that account is used, it will not be learned by your firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the background, the user-ID agent is monitoring the authentication logs from your domain controllers.&amp;nbsp; When the user switches, a successful authentication event is recorded on your DCs.&amp;nbsp; The User-ID agent sees that log entry, notes the IP address and the user account, and then updates the firewall with the second user in the IP-to-User-mappings.&amp;nbsp; This is now how your firewall will evaluate that IP address - with the new user account.&amp;nbsp; Switching back to your original user should over-write that entry, because another authentication event takes place.&amp;nbsp; And this is why adding the user to the ignore list will work - your authentication event for your second account will never get recorded by the user-id agent/updated in the IP-to-User-mappings in the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One other option is to deploy a global protect agent to authenticate to an internal (no tunnel) gateway on your firewalls, just to learn the user ID's.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Oct 2018 12:43:39 GMT</pubDate>
    <dc:creator>JW6224</dc:creator>
    <dc:date>2018-10-30T12:43:39Z</dc:date>
    <item>
      <title>user if agent and switching between ids</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237718#M68107</link>
      <description>&lt;P&gt;we have configured rules with group mapping using LDAP.&lt;/P&gt;&lt;P&gt;We have one user where he switch between user ids and when he trieds to login to server with user id not allowed in list he gets&lt;/P&gt;&lt;P&gt;denied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;should he log off and log on as best practice when he switch between user ids?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 23:20:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237718#M68107</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-29T23:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: user if agent and switching between ids</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237726#M68108</link>
      <description>&lt;P&gt;Does this user normally works with his default user but needs to use another one for task that require administrative privileges and the user-ids are switching between these two? Or uses scripts that run as another user, maybe a service account?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 23:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237726#M68108</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-29T23:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: user if agent and switching between ids</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237729#M68109</link>
      <description>&lt;P&gt;works fine with default user account but user need to access some apps for that he has to login to those apps&amp;nbsp; with different user id.&lt;/P&gt;&lt;P&gt;&amp;nbsp;And thats what causes the problem.&lt;/P&gt;&lt;P&gt;Domain is same for both the default user account and other apps.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 01:19:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237729#M68109</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-30T01:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: user if agent and switching between ids</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237732#M68111</link>
      <description>&lt;P&gt;Try to add user to run apps with into ignore list.&lt;/P&gt;&lt;P&gt;&lt;A title="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClklCAC" href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClklCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClklCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 03:11:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237732#M68111</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-30T03:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: user if agent and switching between ids</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237758#M68120</link>
      <description>&lt;P&gt;So your scenario, if I understand it, is that you have a user using "switch user" in Windows to switch between sessions?&amp;nbsp; And after he switches to a new session, he can no longer access what he wants to on the network, because the user account that he switched to doesn't meet your rule User-ID criteria?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That sort of sounds like it is working as intended, or else you need to add the account that he's switching to into the rule User-ID criteria.&amp;nbsp; Adding the user account that he's switching to into the user-ignore-list.txt would prevent that account from being "learned" by the Palo Alto - ever.&amp;nbsp; Not just on this machine...any time that account is used, it will not be learned by your firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the background, the user-ID agent is monitoring the authentication logs from your domain controllers.&amp;nbsp; When the user switches, a successful authentication event is recorded on your DCs.&amp;nbsp; The User-ID agent sees that log entry, notes the IP address and the user account, and then updates the firewall with the second user in the IP-to-User-mappings.&amp;nbsp; This is now how your firewall will evaluate that IP address - with the new user account.&amp;nbsp; Switching back to your original user should over-write that entry, because another authentication event takes place.&amp;nbsp; And this is why adding the user to the ignore list will work - your authentication event for your second account will never get recorded by the user-id agent/updated in the IP-to-User-mappings in the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One other option is to deploy a global protect agent to authenticate to an internal (no tunnel) gateway on your firewalls, just to learn the user ID's.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2018 12:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237758#M68120</guid>
      <dc:creator>JW6224</dc:creator>
      <dc:date>2018-10-30T12:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: user if agent and switching between ids</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237900#M68168</link>
      <description>&lt;P&gt;Thanks everyone for answering the questions&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 03:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-if-agent-and-switching-between-ids/m-p/237900#M68168</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-31T03:38:13Z</dc:date>
    </item>
  </channel>
</rss>

