<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserId Agent stating connections port 135 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-stating-connections-port-135/m-p/350447#M86964</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This sounds like you have Client Probing enabled, and if you've verified that User-ID is disabled on the untrust interface you'll also want to go through and verify that it isn't included in your Include Network listing.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2020 16:49:04 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-09-18T16:49:04Z</dc:date>
    <item>
      <title>UserId Agent stating connections port 135</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-stating-connections-port-135/m-p/350342#M86959</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to know why our UIAs are starting sessions to INTERNET in port 135.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can we mitigate this flow? WE disblae UIA in INTERNET zone but we still see these sessions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here you can see the kind of&amp;nbsp; sessions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UBE1.JPG" style="width: 720px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27802iB1456BFB364CF2D4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="UBE1.JPG" alt="UBE1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 07:50:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-stating-connections-port-135/m-p/350342#M86959</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-09-18T07:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: UserId Agent stating connections port 135</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-stating-connections-port-135/m-p/350447#M86964</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This sounds like you have Client Probing enabled, and if you've verified that User-ID is disabled on the untrust interface you'll also want to go through and verify that it isn't included in your Include Network listing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 16:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-stating-connections-port-135/m-p/350447#M86964</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-18T16:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: UserId Agent stating connections port 135</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-stating-connections-port-135/m-p/350478#M86968</link>
      <description>&lt;P&gt;Thanks for your response Bpry&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, you mean&amp;nbsp; in UIA Agent config to add the LAN network in "incluted list of configured networks", right?&lt;/P&gt;&lt;P&gt;or you mean to disable WMI probing (this could cause impact)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbkCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClbkCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we also should disable Probin in PA config? "&lt;SPAN&gt;Go to Device &amp;gt;&amp;gt; User Identification&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;On the "User Mapping" tab, in the "Palo Alto Networks User ID Agent" pane, view the "Enable Probing" check box. If it is selected, this is a finding.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 19:16:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-stating-connections-port-135/m-p/350478#M86968</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-09-18T19:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: UserId Agent stating connections port 135</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-stating-connections-port-135/m-p/350666#M86986</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;verify that you actually have an include network configured on the agent. Client Probing really isn't a recommended configuration anymore, and you definitely don't want to allow sending those probes externally.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Sep 2020 03:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-stating-connections-port-135/m-p/350666#M86986</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-20T03:51:18Z</dc:date>
    </item>
  </channel>
</rss>

