<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Loosing USER-ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/320475#M82076</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;I like it how you said 4hrs or 8hrs is safer bet.We use WMI probing.The current timeout we have now set is 10hrs. The probe time is set to 20min.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At our company as all of has work from home situation users are jumping on and off the VPN to avoid latency with Zoom/Webex or bypass the FW rules or whatever. Because of this, the IP addresses becomes free and the new user logging onto Pulse gets them.The firewall hasn't reached its 10hour period and the new user gets the old user's User ID and the new user happened to be an executive and gets the block page.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the ideal way to resolve such issues when the IPs are so frequently changed, default of 45min? But what happens if something chnages in that 45min time period? Is there more real time information for firewall somehow?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Apr 2020 05:50:04 GMT</pubDate>
    <dc:creator>pdasari</dc:creator>
    <dc:date>2020-04-03T05:50:04Z</dc:date>
    <item>
      <title>Loosing USER-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244918#M69850</link>
      <description>&lt;P&gt;Our AD based USER-ID seems to keep loosing the IP/USER&amp;nbsp; association.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We only have a few rules which work some of the time and then fail with a blank user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the best solution to get it 100%???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 16:34:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244918#M69850</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-01-04T16:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: Loosing USER-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244925#M69851</link>
      <description>&lt;P&gt;is your user id timeout set to the default 45 mins.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just set it to either 4 hours or 8 hours (mins equiv)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have mine set to 24 hours...&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 17:00:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244925#M69851</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-04T17:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Loosing USER-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244926#M69852</link>
      <description>&lt;P&gt;Yes 45 mins.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do &lt;STRONG&gt;new&lt;/STRONG&gt; users logins on the same system get picked up ok with that setting of 24Hrs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 17:06:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244926#M69852</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2019-01-04T17:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Loosing USER-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244927#M69853</link>
      <description>&lt;P&gt;Rob, not sure what you are asking.&amp;nbsp; but yes..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;although the timeout setting is global to all users, it is not a global timer...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so each user, as they authenticate with AD will start there own 24 hour timer for there own mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i think existing mappings will only pick up the new timeout on next authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;24 hour is overkill, i only have it as we aslo use Network Access Control on our switches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4 hours is good practice as usualyy stop for lunch, (lock laptop) 8 hours is a safer bet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the other option is to use mapping against email server or similar. whatever has the most activity..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 17:18:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244927#M69853</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-04T17:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Loosing USER-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244928#M69854</link>
      <description>&lt;P&gt;&amp;nbsp;please note that if an old mapping exists from earlier and your scope runs out of IP addresses then a non AD user could obtain an address of an old mapping prior to it timing out, probably didn't explain that very well, post back if you neeed more info.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 17:26:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/244928#M69854</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-04T17:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Loosing USER-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/320475#M82076</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;I like it how you said 4hrs or 8hrs is safer bet.We use WMI probing.The current timeout we have now set is 10hrs. The probe time is set to 20min.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At our company as all of has work from home situation users are jumping on and off the VPN to avoid latency with Zoom/Webex or bypass the FW rules or whatever. Because of this, the IP addresses becomes free and the new user logging onto Pulse gets them.The firewall hasn't reached its 10hour period and the new user gets the old user's User ID and the new user happened to be an executive and gets the block page.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the ideal way to resolve such issues when the IPs are so frequently changed, default of 45min? But what happens if something chnages in that 45min time period? Is there more real time information for firewall somehow?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 05:50:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loosing-user-id/m-p/320475#M82076</guid>
      <dc:creator>pdasari</dc:creator>
      <dc:date>2020-04-03T05:50:04Z</dc:date>
    </item>
  </channel>
</rss>

