<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID Proof Of Concept - With Proxy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-proof-of-concept-with-proxy/m-p/256978#M72903</link>
    <description>&lt;P&gt;Good afternoon Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pardon my stupidity here. I'm running a PoC at the minute and customer is keen on the User-ID aspect. However, the have most of their users behind a proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured the PoC in standard TAP, with LDAP server profile etc etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are picking up users in logs from AD but I'm wondering if there is a way to see users behind proxy as oppose to the proxy ip address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously I can tell them that we'd remove the proxy and employ URL Filtering should they purchase the device but would really like for them to see traffic logs with users populated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for all and any advice&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2019 12:51:56 GMT</pubDate>
    <dc:creator>SirchRettop</dc:creator>
    <dc:date>2019-04-10T12:51:56Z</dc:date>
    <item>
      <title>User-ID Proof Of Concept - With Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-proof-of-concept-with-proxy/m-p/256978#M72903</link>
      <description>&lt;P&gt;Good afternoon Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pardon my stupidity here. I'm running a PoC at the minute and customer is keen on the User-ID aspect. However, the have most of their users behind a proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured the PoC in standard TAP, with LDAP server profile etc etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are picking up users in logs from AD but I'm wondering if there is a way to see users behind proxy as oppose to the proxy ip address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously I can tell them that we'd remove the proxy and employ URL Filtering should they purchase the device but would really like for them to see traffic logs with users populated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for all and any advice&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 12:51:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-proof-of-concept-with-proxy/m-p/256978#M72903</guid>
      <dc:creator>SirchRettop</dc:creator>
      <dc:date>2019-04-10T12:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Proof Of Concept - With Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-proof-of-concept-with-proxy/m-p/256987#M72904</link>
      <description>&lt;P&gt;If you open URL Filtering profile there is "URL Filtering Settings" tab.&lt;BR /&gt;Last option is "X-Forwarded-For"&lt;BR /&gt;If you check it then Palo will capture real source IP from the http session and log it.&lt;BR /&gt;Proxy must add X-Forwarded-For to the traffic and unless you decrypt ssl you see this only for http sessions not https. You would need to be inline with vwire to decrypt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe they can switch proxy to transparent mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if you don't want to expose internal IPs then would be nice to strip this information after it passes Palo.&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;Device &amp;gt; Setup &amp;gt; Content-ID &amp;gt; X-Forwarded-For Headers &amp;gt; Strip X-Forwarded-For Header&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Apr 2019 13:34:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-proof-of-concept-with-proxy/m-p/256987#M72904</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-10T13:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Proof Of Concept - With Proxy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-proof-of-concept-with-proxy/m-p/256991#M72907</link>
      <description>&lt;P&gt;Yes they are using a Cisco WSA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I may ask if they can enable XFF on the proxy, then I will enable XFF in the URL Filtering and Content-ID tabs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We don't really want to place the device inline and perform SSL Decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer is eager to see User-ID in action so hopefully the XFF option will help us alot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate the input.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 13:50:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-proof-of-concept-with-proxy/m-p/256991#M72907</guid>
      <dc:creator>SirchRettop</dc:creator>
      <dc:date>2019-04-10T13:50:02Z</dc:date>
    </item>
  </channel>
</rss>

