<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID not mapping all users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285131#M76386</link>
    <description>&lt;P&gt;I would recommend that you take a look at the following section in the Admin guide for enabling UserID properly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id.html#" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id.html#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Essentially, it gets broken down into 3 parts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Get LDAP/Group Mappings configured on FW.&lt;/P&gt;&lt;P&gt;Create LDAP Server Profile&lt;/P&gt;&lt;P&gt;User-ID Group Mapping Settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Users log into DC/Exchange server(s) like they normally do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) User ID on the source Zone enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the 200 or so computers need to be (generally) Windows machines, on the domain, autheticating to the domain.&lt;/P&gt;&lt;P&gt;When users authenticate, server log entry is created, with username/IP associated.&lt;/P&gt;&lt;P&gt;UserID aget, monitoring the DC, will extract user/IP info and show logs in FW (not in security policy)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, take a look at the UserID docs, and let us know how we can assist further.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Aug 2019 20:12:31 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-08-26T20:12:31Z</dc:date>
    <item>
      <title>User-ID not mapping all users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285113#M76383</link>
      <description>&lt;P&gt;I'm using the PA's integrated User-ID Agent to setup User-ID. The moment I began monitoring DC controllers it begain to pull User-ID mappings. This is before User-ID was configured on any zone. However, when I configured User-ID on a source zone, the firewall doesn't getting any user mappings from that source zone. Select IP addresses (approx. 5) will periodically show a mapping of "unknown" however it appears it's not getting a response from the other source IP addresses ( approx. 200) in that zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas on what could cause this?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 17:46:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285113#M76383</guid>
      <dc:creator>JermaineScott</dc:creator>
      <dc:date>2019-08-26T17:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285131#M76386</link>
      <description>&lt;P&gt;I would recommend that you take a look at the following section in the Admin guide for enabling UserID properly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id.html#" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id.html#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Essentially, it gets broken down into 3 parts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Get LDAP/Group Mappings configured on FW.&lt;/P&gt;&lt;P&gt;Create LDAP Server Profile&lt;/P&gt;&lt;P&gt;User-ID Group Mapping Settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Users log into DC/Exchange server(s) like they normally do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) User ID on the source Zone enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the 200 or so computers need to be (generally) Windows machines, on the domain, autheticating to the domain.&lt;/P&gt;&lt;P&gt;When users authenticate, server log entry is created, with username/IP associated.&lt;/P&gt;&lt;P&gt;UserID aget, monitoring the DC, will extract user/IP info and show logs in FW (not in security policy)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, take a look at the UserID docs, and let us know how we can assist further.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 20:12:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285131#M76386</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-08-26T20:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285133#M76388</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Also check the&amp;nbsp;&lt;SPAN&gt;User Identification Timeout (min) setting. By default its something small like 45 mins. We had to bump ours to 720 mins to keep the users from dropping off during business hours since they might only authenticate in once. Another thing is if you use Exchange and everyone has Outlook, you can monitor&amp;nbsp;the exchange logs and&amp;nbsp;the chance of a use dropping off is slim since Outlook is always authenticating against exchange.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 21:09:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285133#M76388</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-08-26T21:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285284#M76402</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was in a rush and just providing limited information, but&amp;nbsp;I went through the User-ID documentation completely when configuring User-ID, and I've configured User-ID successfully many times before. It was strange that I was getting limited reponses so I unconfigred all lthe setting, cleared the mappings. Then as I configured each piece, I monitored the mappings of the agent&amp;nbsp;to try and dissect where the limited mapping were coming from. From that, I noticed that it began&amp;nbsp;to populate prior to User-ID being enabled no the source zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did some troubleshooting with my AD admin and found out that the AD servers do not log successful Logon events. I'm sure this plays a part in why logon from my source zone aren't being mapped&amp;nbsp;by the agent, but doesn't quite explain withthe other mappings are there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 14:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285284#M76402</guid>
      <dc:creator>JermaineScott</dc:creator>
      <dc:date>2019-08-27T14:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285291#M76407</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My hesitancy&amp;nbsp;with extening user timeout has always been tied to dhcp timeout, and what would happen it if one user dropped of the network and another picked up their IP address. Then they'd potentiall have access (based on policy) to things they shouldn't. Or not have access to things they should.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I&amp;nbsp;like the idea of using&amp;nbsp;Exchange. So would I just configure the FQDN of the Exchange servers in the Server Monitoring tab?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also a note from&amp;nbsp;my other repsponse: I did some troubleshooting with my AD admin and found out that the AD servers do not log successful Logon events. I'm sure this plays a part in why logon from my source zone aren't being mapped&amp;nbsp;by the agent, but doesn't quite explain withthe other mappings are there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would that be a factor, if they same is true for the Exchange Server?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 14:55:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-users/m-p/285291#M76407</guid>
      <dc:creator>JermaineScott</dc:creator>
      <dc:date>2019-08-27T14:55:17Z</dc:date>
    </item>
  </channel>
</rss>

