<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Aruba clearpass user id issue with Palo Alto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-clearpass-user-id-issue-with-palo-alto/m-p/338328#M85085</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114565"&gt;@Jatin.Singh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Yes, one user-id can be allocated to multiple IPs. It's looks like you're feeding the authentication through the API?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jul 2020 03:17:17 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-07-14T03:17:17Z</dc:date>
    <item>
      <title>Aruba clearpass user id issue with Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-clearpass-user-id-issue-with-palo-alto/m-p/337982#M85046</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have ClearPass integrated to Palo Alto. ClearPass sends user-id to the firewall upon successful authentication. Customer is experiencing an issue where the laptop (on wireless) would fail to access Internet at re-authentication.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There is another client device that is login with the same user-id. I think the question here is with user-identity, does PA allows a one-to-many (one user-id to multiple IP) relationships???&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also we see the ClearPass re-authenticating the user and it is successful. However, we do not see the corresponding timestamp re-authentication appearing on the PA. The timeout wasn’t reset back to 9 hrs (as configured in the global setting). Is that normal?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In the screen capture seen below for today, I had restarted the wireless at 9.16am. But there was no user-id mapping for the IP address. You can see there is a close correlation on the PA at 9.17am. I did a second restart of the wireless on the client at 9.24am. There was a user-id mapping and it was able to access Internet. The timestamp on PA was at 9.24am. However, at 10.01am, it appears there is another successful mapping of the user-id to IP on the PA but there wasn’t any re-authentication on the ClearPass.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 22:22:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-clearpass-user-id-issue-with-palo-alto/m-p/337982#M85046</guid>
      <dc:creator>Jatin.Singh</dc:creator>
      <dc:date>2020-07-15T22:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba clearpass user id issue with Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-clearpass-user-id-issue-with-palo-alto/m-p/338328#M85085</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114565"&gt;@Jatin.Singh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Yes, one user-id can be allocated to multiple IPs. It's looks like you're feeding the authentication through the API?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 03:17:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-clearpass-user-id-issue-with-palo-alto/m-p/338328#M85085</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-14T03:17:17Z</dc:date>
    </item>
  </channel>
</rss>

