<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User identification in security policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347241#M86607</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes, the traffic that should be identified by created by me security rule is hit by default deny rule.&lt;/P&gt;&lt;P&gt;The rule created by me have 0 hits.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Mon, 07 Sep 2020 12:44:20 GMT</pubDate>
    <dc:creator>ArkadiuszSmolarek</dc:creator>
    <dc:date>2020-09-07T12:44:20Z</dc:date>
    <item>
      <title>User identification in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347213#M86604</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with configuration of user identification in security policy. What is the target: for some users who login to VPN via GlobalProtect I would like to limit them to some specific subnet. Users login to VPN using their Active Directory accounts (via Radius). I created LDAP profile, group mapping and security policy (with source group). I also in AD created some groups and added users to them. When I check on CLI: show user group name GROUP-NAME I see users belongs to the group but when I login via GP I don't have access to resources permited in policy. Where can be the problem?&lt;/P&gt;&lt;P&gt;Thank you for any help.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 12:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347213#M86604</guid>
      <dc:creator>ArkadiuszSmolarek</dc:creator>
      <dc:date>2020-09-07T12:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: User identification in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347240#M86606</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154209"&gt;@ArkadiuszSmolarek&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would be helpful to know how the firewall is identifying the traffic/session.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is the traffic being denied by your general deny rule ? Can you check the session info (userinfo/zones/destinations/etc ...) and verify if everything is matching according to the rule you've configured ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 07 Sep 2020 12:41:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347240#M86606</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-09-07T12:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: User identification in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347241#M86607</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes, the traffic that should be identified by created by me security rule is hit by default deny rule.&lt;/P&gt;&lt;P&gt;The rule created by me have 0 hits.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 12:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347241#M86607</guid>
      <dc:creator>ArkadiuszSmolarek</dc:creator>
      <dc:date>2020-09-07T12:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: User identification in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347244#M86610</link>
      <description>&lt;P&gt;I would check the Firewall Traffic Logs, and look for the IP of GP-User and see if user-ID has been correctly identified.&amp;nbsp;&lt;/P&gt;&lt;P&gt;check User-ID Logs too&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 13:14:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347244#M86610</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-09-07T13:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: User identification in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347260#M86611</link>
      <description>&lt;P&gt;In the traffic log and User-ID log I see correct user identification:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Traffic-log.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27642iA3DFC745AE9C1DCC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Traffic-log.JPG" alt="Traffic-log.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="User-ID-log.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27641i98A47BD6F4A036FA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="User-ID-log.JPG" alt="User-ID-log.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 13:32:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347260#M86611</guid>
      <dc:creator>ArkadiuszSmolarek</dc:creator>
      <dc:date>2020-09-07T13:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: User identification in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347261#M86612</link>
      <description>&lt;P&gt;can you also share your security Policy pls.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 13:41:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347261#M86612</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-09-07T13:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: User identification in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347265#M86613</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sec-pol.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27643i73B298F59D17F822/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Sec-pol.JPG" alt="Sec-pol.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CLI map.JPG" style="width: 690px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27644i1A632647A9DF1632/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CLI map.JPG" alt="CLI map.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 13:53:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347265#M86613</guid>
      <dc:creator>ArkadiuszSmolarek</dc:creator>
      <dc:date>2020-09-07T13:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: User identification in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347312#M86619</link>
      <description>&lt;P&gt;what you see in traffic log is the User-ID detected from GP login and not same as "Omintech&lt;SPAN&gt;\asmolarek".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;enable User-ID agent, from "Device--&amp;gt;UserIdentification" with the crossponding login-information and make sure you select "Allow Matching username without domains"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;after that the traffic should be matched by the secrutiy&amp;nbsp;&lt;/SPAN&gt;Policy&lt;/P&gt;&lt;P&gt;Good luck.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 18:48:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347312#M86619</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-09-07T18:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: User identification in security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347376#M86624</link>
      <description>&lt;P&gt;Thanks, it works &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 06:17:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-in-security-policy/m-p/347376#M86624</guid>
      <dc:creator>ArkadiuszSmolarek</dc:creator>
      <dc:date>2020-09-08T06:17:09Z</dc:date>
    </item>
  </channel>
</rss>

