<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internet disconnection when switching from wired to wireless in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/296250#M77958</link>
    <description>&lt;P&gt;Yes this is normal.&lt;/P&gt;&lt;P&gt;the user agent reads the security log on the AD server, IP change will not populate to this log but when domain activity is registered it will log this along with the user IP for audit purposes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you need to use other ip mapping methods or invoke a script to force domain activity on ip change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Nov 2019 06:58:38 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-11-05T06:58:38Z</dc:date>
    <item>
      <title>Internet disconnection when switching from wired to wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293207#M77532</link>
      <description>&lt;P&gt;We have newly implemented PaloAlto in our network. Internet access provided for the user using the AD username. Using User-ID Agent in Active directory. When a user is logged in with wired connection and switched to wireless the internet is getting disconnected.Internet is working if the user logoff and logs in again. Is there anything we can do to avoid this disconnection? Is there any configuration to be done in firewall or User-ID agent to avoid this?&lt;/P&gt;&lt;P&gt;Note: Wired and Wireless connection different subnets. The whole subnet is included in the user-id agent.&lt;/P&gt;&lt;P&gt;Appreciate if anyone can help on this regard&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 06:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293207#M77532</guid>
      <dc:creator>regahamz</dc:creator>
      <dc:date>2019-10-17T06:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Internet disconnection when switching from wired to wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293214#M77535</link>
      <description>&lt;P&gt;lan disconnect/connect&amp;nbsp; will cause an event log. perhaps you could invoke a script to map a drive or some other domain activity when the event is logged, this will cause new ip mapping to be registered in AD and user-id will pick this up...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI.&lt;/P&gt;&lt;P&gt;Event ID: 10000 (Network Connection Established)&lt;/P&gt;&lt;P&gt;Event ID: 10001 (Network Connection Removed)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Others may prefer a captive portal option but i cannot advise as don't use it.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 08:04:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293214#M77535</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-10-17T08:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Internet disconnection when switching from wired to wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293216#M77536</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Is there a way in PaloAlto to provide internet in the basis of windows user logon without considering the IP mapped to user account?&lt;/P&gt;&lt;P&gt;The option Group Mapping in Paloalto, will this can be used to achieve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 09:46:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293216#M77536</guid>
      <dc:creator>regahamz</dc:creator>
      <dc:date>2019-10-17T09:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Internet disconnection when switching from wired to wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293217#M77537</link>
      <description>&lt;P&gt;well yes and no!&lt;/P&gt;&lt;P&gt;Group Mapping can be used for policies but to be a member of a group you must have a name, you will only have a name if your IP address is logged in windows AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 09:51:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293217#M77537</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-10-17T09:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: Internet disconnection when switching from wired to wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293218#M77538</link>
      <description>&lt;P&gt;Have a look at captive portal.&amp;nbsp; &amp;nbsp;it can be used transparently as per comments below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;The firewall uses&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/authentication/configure-kerberos-single-sign-on.html" target="_blank" rel="noopener"&gt;Kerberos single sign-on (SSO)&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to transparently obtain user credentials. To use this method, your network requires a Kerberos infrastructure, including a key distribution center (KDC) with an authentication server and ticket granting service. The firewall must have a Kerberos account, including a principal name and password.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;captive portal info here..&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/policies/policies-captive-portal" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/policies/policies-captive-portal&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 10:00:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/293218#M77538</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-10-17T10:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Internet disconnection when switching from wired to wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/296247#M77957</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The log on event is appearing in the domain controller with new source ip address when user switches network, only when there is a domain activity. Is this normal behavior of the Active Directory logs or the logon event should appear in domain immediately when there is change in the ip address in client machine.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 06:33:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/296247#M77957</guid>
      <dc:creator>regahamz</dc:creator>
      <dc:date>2019-11-05T06:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Internet disconnection when switching from wired to wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/296250#M77958</link>
      <description>&lt;P&gt;Yes this is normal.&lt;/P&gt;&lt;P&gt;the user agent reads the security log on the AD server, IP change will not populate to this log but when domain activity is registered it will log this along with the user IP for audit purposes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you need to use other ip mapping methods or invoke a script to force domain activity on ip change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 06:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/296250#M77958</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-05T06:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Internet disconnection when switching from wired to wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/296310#M77963</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124142"&gt;@regahamz&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;We have newly implemented PaloAlto in our network. Internet access provided for the user using the AD username. Using User-ID Agent in Active directory. When a user is logged in with wired connection and switched to wireless the internet is getting disconnected.Internet is working if the user logoff and logs in again. Is there anything we can do to avoid this disconnection? Is there any configuration to be done in firewall or User-ID agent to avoid this?&lt;/P&gt;&lt;P&gt;Note: Wired and Wireless connection different subnets. The whole subnet is included in the user-id agent.&lt;/P&gt;&lt;P&gt;Appreciate if anyone can help on this regard&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I posted about this back in 2015.&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Dual-NIC-IP-Mapping-Issue/m-p/63710#M38291" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Dual-NIC-IP-Mapping-Issue/m-p/63710#M38291&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately it's not as straight forward as you'd think.&amp;nbsp; If you have a windows client that has both a wired and wireless NIC Windows will NOT perform authentication against both NICs.&amp;nbsp; It chooses one or the other.&amp;nbsp; So "those event IDs" that Palo UIAs need to monitor in order to perform IP to ID association will only happen for one NIC at a time, and it's only going to happen once; until another scenario comes along that requires the authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are ways in Windows to make a particular NIC the "preferred" NIC, so say setting Windows use the wireless NIC over wired, Windows won't always adhere to that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your best bet is going to be to use the layered authentication mechanism to catch on-the-fly the user mappings you need.&amp;nbsp; This means using captive portal with NTLM (SSO) authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ultimately Palo will tell you the "fool proof way" to get the user mapping is to deploy Global Protect clients.&amp;nbsp; Merely using them for user tracking will give you a more reliable way of making sure you always have an IP to ID association.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 13:19:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/296310#M77963</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-11-05T13:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Internet disconnection when switching from wired to wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/296311#M77964</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Have a look at captive portal.&amp;nbsp; &amp;nbsp;it can be used transparently as per comments below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;The firewall uses&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/authentication/configure-kerberos-single-sign-on.html" target="_blank" rel="noopener"&gt;Kerberos single sign-on (SSO)&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to transparently obtain user credentials. To use this method, your network requires a Kerberos infrastructure, including a key distribution center (KDC) with an authentication server and ticket granting service. The firewall must have a Kerberos account, including a principal name and password.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;captive portal info here..&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/policies/policies-captive-portal" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/policies/policies-captive-portal&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sure Kerberos could be used for SSO, but it's just easier to use the NTLM credential forwarding or sharing from the web browser.&amp;nbsp; Using CP and NTLM SSO Palo doesn't have a known user association the firewall (I think it's the FW and not the UIAs) will ask the browser via NTLM for the credentials the web browser has.&amp;nbsp; The FW then takes those creds and asks AD if they're valid.&amp;nbsp; If they are then that user mapping association is stored in the FW for the configured time period.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using this NTLM method doesn't require anything additional to be setup in anyone's environment.&amp;nbsp; The draw back here is, it requires the use of a web browser.&amp;nbsp; So if there's an IP change and a lack of user attribution and the user is only using "thick clients" (Like outlook) this NTLM feature won't work.&amp;nbsp; The user would need to browse the web for this attribution process to work.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 13:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internet-disconnection-when-switching-from-wired-to-wireless/m-p/296311#M77964</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-11-05T13:28:58Z</dc:date>
    </item>
  </channel>
</rss>

