<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interrogate External Server for UserID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/298821#M78268</link>
    <description>&lt;P&gt;I dont know of any method via cli to add static mappings, this really defeats the object...&lt;/P&gt;&lt;P&gt;so no CLI then no API.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;would you not be better off interrogating the ip mapping via ssh or similar and then import this to a server that the user-id agent can itself interrogate or is this also part of the problem..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2019 14:43:04 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-11-15T14:43:04Z</dc:date>
    <item>
      <title>Interrogate External Server for UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/298788#M78263</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a use case where, upon detection of a session with an unknown userID, we'd like the Palo firewall to interrogate an external service via REST API for the UserID/IP address mapping.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate the normal way is to prepopulate the Palo or UserID Agent servers with data from external sources, but this is not possible in this case.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 12:25:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/298788#M78263</guid>
      <dc:creator>Stephen_Elliott</dc:creator>
      <dc:date>2019-11-15T12:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Interrogate External Server for UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/298821#M78268</link>
      <description>&lt;P&gt;I dont know of any method via cli to add static mappings, this really defeats the object...&lt;/P&gt;&lt;P&gt;so no CLI then no API.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;would you not be better off interrogating the ip mapping via ssh or similar and then import this to a server that the user-id agent can itself interrogate or is this also part of the problem..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 14:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/298821#M78268</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-15T14:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Interrogate External Server for UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300530#M78521</link>
      <description>&lt;P&gt;Thanks for your reply MickBall.&lt;/P&gt;&lt;P&gt;I'm not concerned with the CLI especially. I just want the firewall to send a query to an external source for UserID/IP address mapping when a new session from an 'unknown user' is presented.&lt;/P&gt;&lt;P&gt;The external source is not static and will be constantly updating with new UserID/IP address mappings.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 09:09:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300530#M78521</guid>
      <dc:creator>Stephen_Elliott</dc:creator>
      <dc:date>2019-11-25T09:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Interrogate External Server for UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300531#M78522</link>
      <description>&lt;P&gt;NP.&lt;/P&gt;&lt;P&gt;Of course. i understand...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;would you not be better off posting a similar request in the automation/API discussions area.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW. exactly what server are you looking to interrogate.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 09:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300531#M78522</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-25T09:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Interrogate External Server for UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300539#M78523</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;would you not be better off posting a similar request in the automation/API discussions area."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- Yes, almost definitely!&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'll see if an admin can move it for me.&lt;/P&gt;&lt;P&gt;It's a DDI server, used for IPAM/DHCP, that I want to interrogate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 09:31:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300539#M78523</guid>
      <dc:creator>Stephen_Elliott</dc:creator>
      <dc:date>2019-11-25T09:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Interrogate External Server for UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300850#M78587</link>
      <description>&lt;P&gt;I think you're underestimating the potential query volume this could generate. Even a PA-220 is rated for 4200 CPS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your IPAM solution has APIs available to query user -&amp;gt; IP assignment, I'd periodically query the DB and use the User-ID API to create IP-User mappings on the firewall with that information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 21:09:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300850#M78587</guid>
      <dc:creator>asilliker</dc:creator>
      <dc:date>2019-11-26T21:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Interrogate External Server for UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300866#M78590</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So when you say external, are you referring to external to the PAN or your environment? Seems that User-ID would be the best option if these sessions are internal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps I misunderstood your request?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 22:06:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300866#M78590</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-11-26T22:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: Interrogate External Server for UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300944#M78599</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76229"&gt;@Stephen_Elliott&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The firewall itself directly isn't going to be able to do this, but it is something that could be scripted. You simply need to generate an HTTP call whenever an unknown user is identified in the traffic log that you can grab the source from. The script would need to take that source and query the external service for the user-id information. That information would then need to be fed back to the API so that the firewall can update its user-id database with the user from the external source.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 04:02:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interrogate-external-server-for-userid/m-p/300944#M78599</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-27T04:02:49Z</dc:date>
    </item>
  </channel>
</rss>

