<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserID agent sessions to public IPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/349033#M86782</link>
    <description>&lt;P&gt;(it should be off, otherwise, logically, the firewalls should be querying the agents for UserID info on public IPs too, which would produce WMI queries if the relevant option is enabled...)&lt;/P&gt;</description>
    <pubDate>Mon, 14 Sep 2020 10:38:54 GMT</pubDate>
    <dc:creator>Nikolay-Matveev</dc:creator>
    <dc:date>2020-09-14T10:38:54Z</dc:date>
    <item>
      <title>UserID agent sessions to public IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/348544#M86745</link>
      <description>&lt;P&gt;&amp;nbsp;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are detecting in Palo FW that there are sessions from UseriD-Agent servers to publics IPs. Our SOC confirmed that some of these public IPs are categorized like low reputation. Sessions are in port 135. I know the UserId agent uses this port but its reaching publics IPs.&lt;/P&gt;&lt;P&gt;We have GP enabled, and there are also connections port 135 to the public client IPs. But there are anothe sessions to low reputatio ips&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Why its having this behaviour? Any way to avoid these sessions from UIA to public IPS?&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 12:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/348544#M86745</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-09-11T12:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: UserID agent sessions to public IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/348578#M86748</link>
      <description>&lt;P&gt;Start with disabling NetBIOS in TCP/IP parameters on the UID agents (Control Panel &amp;gt; Network Connections &amp;gt; your connection &amp;gt;&amp;nbsp; Properties &amp;gt; TCP/IPv4 &amp;gt; Advanced &amp;gt; WINS &amp;gt; Disable NetBIOS over TCP/IP). Unless you do use it in your network of course... (but I cannot think of a good reason to do so these days to be honest).&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 13:14:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/348578#M86748</guid>
      <dc:creator>Nikolay-Matveev</dc:creator>
      <dc:date>2020-09-11T13:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: UserID agent sessions to public IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/348824#M86775</link>
      <description>&lt;P&gt;But NEtBIOS is not port 135.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it would have more convenient disabling WMI probing. This can be a&amp;nbsp; risk in the normal behavior for UIA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, i dont understand why UIA are starting sessions to public low reputation IPs&lt;/P&gt;</description>
      <pubDate>Sun, 13 Sep 2020 16:15:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/348824#M86775</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-09-13T16:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: UserID agent sessions to public IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/349032#M86781</link>
      <description>&lt;P&gt;Good point about WMI probing... Perhaps I am too used to have it switched off in my environment &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Do you have UserID switched off for the Internet zone on the firewalls?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 10:36:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/349032#M86781</guid>
      <dc:creator>Nikolay-Matveev</dc:creator>
      <dc:date>2020-09-14T10:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: UserID agent sessions to public IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/349033#M86782</link>
      <description>&lt;P&gt;(it should be off, otherwise, logically, the firewalls should be querying the agents for UserID info on public IPs too, which would produce WMI queries if the relevant option is enabled...)&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 10:38:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-sessions-to-public-ips/m-p/349033#M86782</guid>
      <dc:creator>Nikolay-Matveev</dc:creator>
      <dc:date>2020-09-14T10:38:54Z</dc:date>
    </item>
  </channel>
</rss>

