<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agentless User-ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10274#M7554</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find 'Manage auditing and security log' policy under 'User Rights Assignment' in Group policy management and 'DCOM: Machine Launch restriction...' policy under 'Security options' in same group policy management for DC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Jan 2014 13:46:43 GMT</pubDate>
    <dc:creator>hyadavalli</dc:creator>
    <dc:date>2014-01-02T13:46:43Z</dc:date>
    <item>
      <title>Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10271#M7551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having issues with getting the user-mappings after configuring the PAN as an agentless user-id with an AD. I have followed all the steps in this document&lt;/P&gt;&lt;P&gt;-&amp;gt; &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4332"&gt;https://live.paloaltonetworks.com/docs/DOC-4332&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All are good except that when I run the CLI command&amp;nbsp; &amp;gt; &lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;show user ip-user-mapping all&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 09:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10271#M7551</guid>
      <dc:creator>Suhaimi</dc:creator>
      <dc:date>2014-01-02T09:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10272#M7552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check whether service account created for pulling user-ip mapping has rights for 'Manage auditing and security log' policy and 'DCOM: Machine launch restriction.' policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 12:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10272#M7552</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2014-01-02T12:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10273#M7553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you care to explain further the policy rights assignment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 13:25:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10273#M7553</guid>
      <dc:creator>Suhaimi</dc:creator>
      <dc:date>2014-01-02T13:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10274#M7554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find 'Manage auditing and security log' policy under 'User Rights Assignment' in Group policy management and 'DCOM: Machine Launch restriction...' policy under 'Security options' in same group policy management for DC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 13:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10274#M7554</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2014-01-02T13:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10275#M7555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Ive done the user rights assignment but still the same. I read somewhere that you need to setup an LDAP server. Is this necessary?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 14:52:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10275#M7555</guid>
      <dc:creator>Suhaimi</dc:creator>
      <dc:date>2014-01-02T14:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10276#M7556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ldap server is required for getting group-mappings.&lt;/P&gt;&lt;P&gt;Can you confirm if user-identification is enabled for the zone you wanted to see mapping?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 16:00:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10276#M7556</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2014-01-02T16:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10277#M7557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Suhaimi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, Ldap server is configuration is required to pull user-group mappings, not in this case. If you're sure about the service account privileges(&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Be sure the user is part of the Distributed COM Users, Server Operators and Event Log Readers groups.&lt;/SPAN&gt;), can you ensure the status of the AD shows up as 'Connected' on the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="uid.PNG" class="jive-image" height="110" src="https://live.paloaltonetworks.com/legacyfs/online/10579_uid.PNG" style="width: 158.93877551020407px; height: 110px;" width="159" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can run the following command to check the statistics as well-&lt;/P&gt;&lt;P&gt;&amp;gt; show user server-monitor state all&lt;/P&gt;&lt;P&gt;&amp;gt; show user server-monitor statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please ensure the firewall is connected to all the DC's the users are logging on to. User-ip-mappings are retrieved by the firewall by reading successful logon events from the security logs on DC. You can run 'set l' on the windows command prompt and that will show the DC user is logging onto. If all this is in place, looking at the userid debug logs should help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id on debug&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id set userid servermonitor&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id set userid basic&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id log-ip-user-mapping yes&lt;/P&gt;&lt;P&gt;&amp;gt; tail follow yes mp-log useridd.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To turn these off-&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id log-ip-user-mapping no&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id unset all&lt;/P&gt;&lt;P&gt;&amp;gt;debug user-id on info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will be a helpful document for you:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-5662" style="font-size: 10pt; line-height: 1.5em;"&gt;https://live.paloaltonetworks.com/docs/DOC-5662&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Aditi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 16:09:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id/m-p/10277#M7557</guid>
      <dc:creator>apasupulati</dc:creator>
      <dc:date>2014-01-02T16:09:01Z</dc:date>
    </item>
  </channel>
</rss>

