<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Terminal Services Agent in Windows 2016  Citrix - SMB-Sessions not mapped to user in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-in-windows-2016-citrix-smb-sessions-not/m-p/312193#M80746</link>
    <description>&lt;P&gt;This is because fileshares are accessed at the system level rather than the user level on windows machines, This happens below the level where TSAgent is able to intercept and change source port&lt;/P&gt;</description>
    <pubDate>Thu, 20 Feb 2020 10:44:22 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2020-02-20T10:44:22Z</dc:date>
    <item>
      <title>Terminal Services Agent in Windows 2016  Citrix - SMB-Sessions not mapped to user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-in-windows-2016-citrix-smb-sessions-not/m-p/312177#M80742</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we're running W2K16 servers here using Citrix. We also installed the latest TSA and when a user logs in he is properly recognized on the firewall and the TSA assigns a port-range dedicated to the user.&lt;/P&gt;&lt;P&gt;When establishing new TCP-connection that is also properly recognized on the firewall and permissions can be granted depending on the user. So on first sight everything works perfect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now let me explain our problem. Whenever you start a file-explorer or try to open a file within a software (e.g. a Word-Document or Excel-File) access to remote-servers (SMB-Share) is not done from the ports assigned to the user. All traffic seems to be sent from the system-account and therefore the firewall cannot map the user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my problem is now, how could I limit the access to file-servers for requests coming from the Citrix-Server running the TSA to specific users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;User1,2 should be able to access file-server 1 but not 2&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;User 3,4 should be able to access file-server 2 but not 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had already opened a support ticket on Palo Alto and they confirmed this behaivour but they had not been able to provide a solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this is a nightmare as File-Access is one of the core-features each software needs and I can't imagine that we're the only one having that problem. Any one else here having that problem? Any solutions? Is there a magic switch on Windows that enables a SMB-session per User, instead of per Machine?&amp;nbsp;&lt;SPAN&gt;Or is no one else in this community doing file-operations on remote systems?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Walter&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 08:51:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-in-windows-2016-citrix-smb-sessions-not/m-p/312177#M80742</guid>
      <dc:creator>WalterWerther</dc:creator>
      <dc:date>2020-02-20T08:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent in Windows 2016  Citrix - SMB-Sessions not mapped to user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-in-windows-2016-citrix-smb-sessions-not/m-p/312193#M80746</link>
      <description>&lt;P&gt;This is because fileshares are accessed at the system level rather than the user level on windows machines, This happens below the level where TSAgent is able to intercept and change source port&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 10:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-in-windows-2016-citrix-smb-sessions-not/m-p/312193#M80746</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-02-20T10:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services Agent in Windows 2016  Citrix - SMB-Sessions not mapped to user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-in-windows-2016-citrix-smb-sessions-not/m-p/312345#M80774</link>
      <description>&lt;P&gt;Thanks for the answer,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the meantime I found in the internet, that other Terminal Service Agents are facing the same problem. It also seems, that there is no workaround known for that issue.&lt;/P&gt;&lt;P&gt;I'm quite surprised that it seems, that no one has the use-case to allow file access based on detected users. Of course SMB brings some security features and I need to rely on the security of AD anyway when using user-detection. But limiting the access of potentially attackable servers would reduce the attack surface.&lt;/P&gt;&lt;P&gt;So I'm quite surprised that it seems like no vendor (Palo, Cisco, Checkpoint, etc.) is trying to convience Microsoft to modify the behavior on TS-Servers that SMB-Sessions are not handled in System-Context.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone out there having a solution or workaround?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:17:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-agent-in-windows-2016-citrix-smb-sessions-not/m-p/312345#M80774</guid>
      <dc:creator>WalterWerther</dc:creator>
      <dc:date>2020-02-21T06:17:28Z</dc:date>
    </item>
  </channel>
</rss>

