<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Keeping UID to IP address Associations Current  - A.K.A. UID Refreshes / Timeouts / Confirmations in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/keeping-uid-to-ip-address-associations-current-a-k-a-uid/m-p/323854#M82723</link>
    <description>&lt;P&gt;This is a question about how a firewall, FW, keeps IP to UID associations current/up-to-date in an environment where such associations might be changing every few seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A FW&amp;nbsp;associates a UID with an internal IP address, e.g. 10.10.10.10,&amp;nbsp;which has no UID associated with it. Let's say that I logon as &lt;STRONG&gt;ipj1965&lt;/STRONG&gt; from &lt;STRONG&gt;10.10.10.10&lt;/STRONG&gt;. The first time a FW sees traffic from 10.10.10.10 it will ask itself "Do I know who's at 10.10.10.10?" If not, it will ask its associated UID servers. They do know the answer,&amp;nbsp;as they're constantly interrogating the Windows AD Server Logs, and will tell the FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If my UID logs off, and nobody else is given 10.10.10.10, no problem. If I 'move' to a new IP address, e.g. 10.10.10.11, that was previously not associated with a UID,&amp;nbsp;the FW&amp;nbsp;will associate&amp;nbsp;ipj1965 with that new IP, again, by asking its UID servers. &lt;STRONG&gt;I think that this is in addition to my prior IP&lt;/STRONG&gt;, 10.10.10.10.&amp;nbsp;I also&amp;nbsp;&lt;STRONG&gt;assume&lt;/STRONG&gt; that this prior association times out after a period set &lt;EM&gt;somewhere&lt;/EM&gt; in the firewall's configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What happens&amp;nbsp;when somebody else, e.g. &lt;STRONG&gt;joeblogs&lt;/STRONG&gt;, is given&amp;nbsp;IP &lt;STRONG&gt;10.10.10.10&lt;/STRONG&gt;? Unless the association between 10.10.10.10 and ipj1965 has timed out, joebloggs will now be permitted through any policies in which ipj1965 is a named user. When, and how, do the FWs confirm their IP address to UID associations?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The UID servers will know almost immediately that the joeblogs is now associated with 10.10.10.10.&amp;nbsp; Do the UID servers send a message to the FWs telling them to drop the IP/UID association whenever they learn that a UID has logged off, or changed IP? Do the UID servers keep track of which UIDs the FWs have asked them about and inform them of any changes? If it all depends on timeouts, what happens with IPs that are only associated with a UID for a short time before quickly being associated with another UID (even though it's only a single UID at any one time)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd also like to know where this timeout is set, if that is the way the FWs keep their IP/UID associations current.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any and all help,&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Apr 2020 16:02:58 GMT</pubDate>
    <dc:creator>johnstoni</dc:creator>
    <dc:date>2020-04-20T16:02:58Z</dc:date>
    <item>
      <title>Keeping UID to IP address Associations Current  - A.K.A. UID Refreshes / Timeouts / Confirmations</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/keeping-uid-to-ip-address-associations-current-a-k-a-uid/m-p/323854#M82723</link>
      <description>&lt;P&gt;This is a question about how a firewall, FW, keeps IP to UID associations current/up-to-date in an environment where such associations might be changing every few seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A FW&amp;nbsp;associates a UID with an internal IP address, e.g. 10.10.10.10,&amp;nbsp;which has no UID associated with it. Let's say that I logon as &lt;STRONG&gt;ipj1965&lt;/STRONG&gt; from &lt;STRONG&gt;10.10.10.10&lt;/STRONG&gt;. The first time a FW sees traffic from 10.10.10.10 it will ask itself "Do I know who's at 10.10.10.10?" If not, it will ask its associated UID servers. They do know the answer,&amp;nbsp;as they're constantly interrogating the Windows AD Server Logs, and will tell the FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If my UID logs off, and nobody else is given 10.10.10.10, no problem. If I 'move' to a new IP address, e.g. 10.10.10.11, that was previously not associated with a UID,&amp;nbsp;the FW&amp;nbsp;will associate&amp;nbsp;ipj1965 with that new IP, again, by asking its UID servers. &lt;STRONG&gt;I think that this is in addition to my prior IP&lt;/STRONG&gt;, 10.10.10.10.&amp;nbsp;I also&amp;nbsp;&lt;STRONG&gt;assume&lt;/STRONG&gt; that this prior association times out after a period set &lt;EM&gt;somewhere&lt;/EM&gt; in the firewall's configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What happens&amp;nbsp;when somebody else, e.g. &lt;STRONG&gt;joeblogs&lt;/STRONG&gt;, is given&amp;nbsp;IP &lt;STRONG&gt;10.10.10.10&lt;/STRONG&gt;? Unless the association between 10.10.10.10 and ipj1965 has timed out, joebloggs will now be permitted through any policies in which ipj1965 is a named user. When, and how, do the FWs confirm their IP address to UID associations?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The UID servers will know almost immediately that the joeblogs is now associated with 10.10.10.10.&amp;nbsp; Do the UID servers send a message to the FWs telling them to drop the IP/UID association whenever they learn that a UID has logged off, or changed IP? Do the UID servers keep track of which UIDs the FWs have asked them about and inform them of any changes? If it all depends on timeouts, what happens with IPs that are only associated with a UID for a short time before quickly being associated with another UID (even though it's only a single UID at any one time)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd also like to know where this timeout is set, if that is the way the FWs keep their IP/UID associations current.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any and all help,&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 16:02:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/keeping-uid-to-ip-address-associations-current-a-k-a-uid/m-p/323854#M82723</guid>
      <dc:creator>johnstoni</dc:creator>
      <dc:date>2020-04-20T16:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Keeping UID to IP address Associations Current  - A.K.A. UID Refreshes / Timeouts / Confirmation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/keeping-uid-to-ip-address-associations-current-a-k-a-uid/m-p/323953#M82745</link>
      <description>&lt;P&gt;Good Day...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me see if I can start to clarify the logic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The UserID agent on the FW or installed on a DC, looks at the last 50k log entries, looking for login/logout request messages.&lt;/P&gt;&lt;P&gt;This list is sent over to the FW, so now the FW has the IP and the username associated with a user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If an IP does not have any User information, then it becomes simply a IP inside your network.&amp;nbsp; You decide if you trust/want unknown users/IP/rogue devices in your network.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You *could* (and probably should....) do an authentication policy/captive portal, to help identify and add the user to the UserID cache of the FW.&amp;nbsp; You could put up a splash page, to ask the user to identify themselves, if NTLM (browser based authentication does not work)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You *could* enabled IP probing (if a windows devices), so that unknown IPs are interrogated and with the correct service account permissions (Distributed COM User) allow the FW to ask the IP about who he is.. and based on the response back, update the IP cache.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When, and how, do the FWs confirm their IP address to UID associations?&amp;nbsp; Customer defined... with the UserID agent.&lt;/P&gt;&lt;P&gt;Mine is set for 2 secs.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_1-1587428681530.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25279i828ED3797F1F509E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SteveCantwell_1-1587428681530.png" alt="SteveCantwell_1-1587428681530.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user timeout is defined in User Identification section of the FW (under the Device tab)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_0-1587428547620.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25278i50B1AF2C120513A8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="SteveCantwell_0-1587428547620.png" alt="SteveCantwell_0-1587428547620.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Granted... I am showing on the integrated UserID agent, but the same information is on the standalong UserID agent as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 00:25:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/keeping-uid-to-ip-address-associations-current-a-k-a-uid/m-p/323953#M82745</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-04-21T00:25:29Z</dc:date>
    </item>
  </channel>
</rss>

