<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does GlobalProtect refresh USER-ID bindings mid session? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/does-globalprotect-refresh-user-id-bindings-mid-session/m-p/294383#M77677</link>
    <description>&lt;P&gt;The GlobalProtect section of the Admin guide for PAN-OS 8 says the following:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;For mobile or roaming users, the &lt;STRONG&gt;GlobalProtect client provides the user mapping information&lt;/STRONG&gt; to &lt;STRONG&gt;the firewall directly&lt;/STRONG&gt;. In this case, every GlobalProtect user has an agent or app running on the client that requires the user to enter login credentials for VPN access to the firewall. &lt;STRONG&gt;This login information is then added to the User-ID user mapping table on the firewall for visibility and user-based security policy enforcement&lt;/STRONG&gt;. Because GlobalProtect users must authenticate to gain access to the network, the IP address-to-username mapping is explicitly known.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/user-id/user-id-concepts/user-mapping/globalprotect" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/user-id/user-id-concepts/user-mapping/globalprotect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The USER-ID binding cache is set to expire every 45 minutes. Assuming that client probing is not in use but the Palo Alto GlobalProtect client is being used as a remote access VPN. When a user logs in the timer resets.&amp;nbsp;Will&amp;nbsp;the GlobalProtect agent update the USER-ID cache proactively on the firewall&amp;nbsp;or at regular intervals to prevent the USER-ID binding being lost or will the cache simply be cleared after 45 minutes provided no other login events are detected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Oct 2019 13:19:52 GMT</pubDate>
    <dc:creator>Kieran_Drain</dc:creator>
    <dc:date>2019-10-25T13:19:52Z</dc:date>
    <item>
      <title>Does GlobalProtect refresh USER-ID bindings mid session?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-globalprotect-refresh-user-id-bindings-mid-session/m-p/294383#M77677</link>
      <description>&lt;P&gt;The GlobalProtect section of the Admin guide for PAN-OS 8 says the following:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;For mobile or roaming users, the &lt;STRONG&gt;GlobalProtect client provides the user mapping information&lt;/STRONG&gt; to &lt;STRONG&gt;the firewall directly&lt;/STRONG&gt;. In this case, every GlobalProtect user has an agent or app running on the client that requires the user to enter login credentials for VPN access to the firewall. &lt;STRONG&gt;This login information is then added to the User-ID user mapping table on the firewall for visibility and user-based security policy enforcement&lt;/STRONG&gt;. Because GlobalProtect users must authenticate to gain access to the network, the IP address-to-username mapping is explicitly known.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/user-id/user-id-concepts/user-mapping/globalprotect" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/user-id/user-id-concepts/user-mapping/globalprotect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The USER-ID binding cache is set to expire every 45 minutes. Assuming that client probing is not in use but the Palo Alto GlobalProtect client is being used as a remote access VPN. When a user logs in the timer resets.&amp;nbsp;Will&amp;nbsp;the GlobalProtect agent update the USER-ID cache proactively on the firewall&amp;nbsp;or at regular intervals to prevent the USER-ID binding being lost or will the cache simply be cleared after 45 minutes provided no other login events are detected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 13:19:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-globalprotect-refresh-user-id-bindings-mid-session/m-p/294383#M77677</guid>
      <dc:creator>Kieran_Drain</dc:creator>
      <dc:date>2019-10-25T13:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Does GlobalProtect refresh USER-ID bindings mid session?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-globalprotect-refresh-user-id-bindings-mid-session/m-p/294439#M77685</link>
      <description>&lt;P&gt;It should be just as you wrote.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The User-ID times out after 45 minutes of inactivity, that is, there is no&amp;nbsp; action by that user/IP, and it will drop off the list until there is more activity by that user/IP.&amp;nbsp; As soon as they are active again, then the User-ID information will be re-populated again.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 17:12:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-globalprotect-refresh-user-id-bindings-mid-session/m-p/294439#M77685</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2019-10-25T17:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Does GlobalProtect refresh USER-ID bindings mid session?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-globalprotect-refresh-user-id-bindings-mid-session/m-p/294668#M77702</link>
      <description>&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClWjCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClWjCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This article suggests that even if active the USER-ID will revert to an Unknown state when the timer expires. I am looking to know when the GlobalProect client updates the USER-ID Cache. If it only does it at login then the user will experience possible issues until they re-log in to the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm asking is when does the GlobalProtect client refresh the USER-ID binding.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 08:14:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-globalprotect-refresh-user-id-bindings-mid-session/m-p/294668#M77702</guid>
      <dc:creator>Kieran_Drain</dc:creator>
      <dc:date>2019-10-28T08:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Does GlobalProtect refresh USER-ID bindings mid session?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-globalprotect-refresh-user-id-bindings-mid-session/m-p/436597#M96282</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the true answer but a chunk of it so go to the link that I posted under this clarification:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following is an example of a scenario when a user may become "Unknown" to the Palo Alto Networks firewall:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A user logs in at Time0 (T0), the User-ID Agent sees the login in the AD security log and maps the IP to the user. The entry is sent to the firewall and it also creates an entry with the same lifetime (MaxTimeout) as the UIDAgent&lt;/LI&gt;&lt;LI&gt;30 minutes later (T0 + 30), the user sends data through the firewall. User is still identified.&lt;/LI&gt;&lt;LI&gt;14 minutes later (T0 + 44), the user sends more data. The user still has an active mapping.&lt;/LI&gt;&lt;LI&gt;2 minutes later (T1 = T0 + 46), the mapping on the agent ages out, and the removal is communicated to the firewall. Mapping is deleted on the firewall.&lt;/LI&gt;&lt;LI&gt;58 minutes later (T1 + 58), the user sends more data. The cache on the firewall was expired, so it requests an IP mapping from the agent but receives "Unknown" user&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;This user will remain "Unknown" until&amp;nbsp; :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;UL&gt;&lt;LI&gt;the user logs back into the domain&lt;/LI&gt;&lt;LI&gt;a positive security audit log is picked up by the UIDAgent&lt;/LI&gt;&lt;LI&gt;a wmi/netbios probe positively identifies the user&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;If WMI probing is not used, then increase the&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;user identification timeout&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt;to 600 minutes (either on the firewall or User ID Agent)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClWjCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClWjCAK&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Sep 2021 20:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-globalprotect-refresh-user-id-bindings-mid-session/m-p/436597#M96282</guid>
      <dc:creator>jmora</dc:creator>
      <dc:date>2021-09-25T20:55:08Z</dc:date>
    </item>
  </channel>
</rss>

