<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Aruba AP with PAN,  User-ID mapping with IP, Syslog Filters in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-ap-with-pan-user-id-mapping-with-ip-syslog-filters/m-p/352233#M87153</link>
    <description>&lt;P&gt;I'm not sure why you are mentioning Windows.&amp;nbsp; The native integration is where the Aruba Instant controller will directly update a PaloAlto device using the PaloAlto API.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Impossible to say what is wrong.&amp;nbsp; Some troubleshooting tasks that jump to mind&lt;/P&gt;&lt;P&gt;- Do a packet capture on the firewall to see if the syslog messages are arriving&lt;/P&gt;&lt;P&gt;- Check logs.&amp;nbsp; System logs in the UI.&amp;nbsp; From the command line there are mp-log files for useridd.log and syslog-ng.log that could be useful.&lt;/P&gt;&lt;P&gt;- Verify under User Identification that the server sending the syslog messages is configured as a Monitored Server with your regex profile&lt;/P&gt;&lt;P&gt;- Verify the interface receiving the syslog messages has an Interface Management Profile that allows the User-ID Syslog Listener&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2020 17:43:55 GMT</pubDate>
    <dc:creator>alowther_chatham</dc:creator>
    <dc:date>2020-09-25T17:43:55Z</dc:date>
    <item>
      <title>Aruba AP with PAN,  User-ID mapping with IP, Syslog Filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-ap-with-pan-user-id-mapping-with-ip-syslog-filters/m-p/345704#M86378</link>
      <description>&lt;P&gt;I'm trying to map User-ID to IP in our intranet so that we could easily identify User in PAN Traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have Aruba APs adn AC authenticating with external Radius Server,&amp;nbsp; While our PAN is sitting at the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i'm trying to do is using Aruba AC sending debug level logs to PAN,&amp;nbsp; PAN could use Syslog Filters to filter our the mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering Anyone have ever done that succuessfully?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 11:41:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-ap-with-pan-user-id-mapping-with-ip-syslog-filters/m-p/345704#M86378</guid>
      <dc:creator>ZhenGuo</dc:creator>
      <dc:date>2020-08-27T11:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba AP with PAN,  User-ID mapping with IP, Syslog Filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-ap-with-pan-user-id-mapping-with-ip-syslog-filters/m-p/345889#M86409</link>
      <description>&lt;P&gt;Not sure about "AC", but I use Aruba Instant clusters.&amp;nbsp; I integrate user-id with PaloAlto two ways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, there is a native integration option&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.arubanetworks.com/techdocs/Instant_40_Mobile/Advanced/Content/UG_files/RTLS_conf/panFirewallInt.htm" target="_blank"&gt;https://www.arubanetworks.com/techdocs/Instant_40_Mobile/Advanced/Content/UG_files/RTLS_conf/panFirewallInt.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, a syslog filter on the PaloAlto&lt;/P&gt;&lt;P&gt;Event Regex: User [aA]uthenticat(?:ed|ion)&lt;/P&gt;&lt;P&gt;Username Regex: username[-=]([a-zA-Z0-9\\._-]+)&lt;/P&gt;&lt;P&gt;Address Regex: [iI][pP][-=]([0-9.]+)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The syslog filter a backup in case the native integration fails.&amp;nbsp; I am currently trying to report a bug with the native integration where the Aruba will use the PaloAlto API to send a logout followed immediately by a login for an IP.&amp;nbsp; This often results in the login update not taking effect.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 19:43:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-ap-with-pan-user-id-mapping-with-ip-syslog-filters/m-p/345889#M86409</guid>
      <dc:creator>alowther_chatham</dc:creator>
      <dc:date>2020-08-28T19:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba AP with PAN,  User-ID mapping with IP, Syslog Filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-ap-with-pan-user-id-mapping-with-ip-syslog-filters/m-p/351004#M87026</link>
      <description>&lt;P&gt;we don't have any integration on Windows.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only Aruba AP, AC and PAN 850.&amp;nbsp; &amp;nbsp;I have tried with various Syslog Filter settings , but still nothing shows in Monitoring about Source User.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked debug log in Aruba AC (Local), i could see all those '&lt;SPAN&gt;&amp;lt;NOTI&amp;gt; |authmgr| User Authentication Successful' logs, but can't reflect on PAN. no idea where set wrong.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 09:54:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-ap-with-pan-user-id-mapping-with-ip-syslog-filters/m-p/351004#M87026</guid>
      <dc:creator>ZhenGuo</dc:creator>
      <dc:date>2020-09-22T09:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Aruba AP with PAN,  User-ID mapping with IP, Syslog Filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/aruba-ap-with-pan-user-id-mapping-with-ip-syslog-filters/m-p/352233#M87153</link>
      <description>&lt;P&gt;I'm not sure why you are mentioning Windows.&amp;nbsp; The native integration is where the Aruba Instant controller will directly update a PaloAlto device using the PaloAlto API.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Impossible to say what is wrong.&amp;nbsp; Some troubleshooting tasks that jump to mind&lt;/P&gt;&lt;P&gt;- Do a packet capture on the firewall to see if the syslog messages are arriving&lt;/P&gt;&lt;P&gt;- Check logs.&amp;nbsp; System logs in the UI.&amp;nbsp; From the command line there are mp-log files for useridd.log and syslog-ng.log that could be useful.&lt;/P&gt;&lt;P&gt;- Verify under User Identification that the server sending the syslog messages is configured as a Monitored Server with your regex profile&lt;/P&gt;&lt;P&gt;- Verify the interface receiving the syslog messages has an Interface Management Profile that allows the User-ID Syslog Listener&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 17:43:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/aruba-ap-with-pan-user-id-mapping-with-ip-syslog-filters/m-p/352233#M87153</guid>
      <dc:creator>alowther_chatham</dc:creator>
      <dc:date>2020-09-25T17:43:55Z</dc:date>
    </item>
  </channel>
</rss>

