<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID not mapping all traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/360935#M88157</link>
    <description>&lt;P&gt;Some critical information is missing from your explanation but I will assuming your setup is the following:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; UserA connects via GP to FirewallA&lt;/P&gt;&lt;P&gt;2. UserA then accesses a resource behind&amp;nbsp; FirewallB&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; FirewallB&amp;nbsp; has an ipsec s2s tunnel to FirewallA and this is how GP users are reaching the resource behind FirewallB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the above&amp;nbsp; is true, then FirewallB needs to be receiving redistributed GP mappings from FirewallA.&amp;nbsp; FirewallB doesn't magically know about the ip to user mapping of UserA that is known to FirewallA.&amp;nbsp; FirewallB must be told wha the ip to user mapping is by configuring user-id redistribution.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Nov 2020 20:01:09 GMT</pubDate>
    <dc:creator>staustin</dc:creator>
    <dc:date>2020-11-05T20:01:09Z</dc:date>
    <item>
      <title>User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/330916#M83847</link>
      <description>&lt;P&gt;Why the user-id is missing for some traffic. This also causes issue with policies using user-id.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below traffic log is for same user/zone/ip&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25943i74E7C970F56FECF3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 21:44:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/330916#M83847</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-01T21:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/330926#M83848</link>
      <description>&lt;P&gt;How is your User-ID mapping implementation configured?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 22:09:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/330926#M83848</guid>
      <dc:creator>staustin</dc:creator>
      <dc:date>2020-06-01T22:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/330961#M83855</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41416"&gt;@staustin&lt;/a&gt;&amp;nbsp;We have agent-less configuration to pull user-ID's from domain controllers&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 04:16:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/330961#M83855</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-02T04:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331219#M83892</link>
      <description>Can anyone suggest what the issue might be.</description>
      <pubDate>Tue, 02 Jun 2020 22:27:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331219#M83892</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-02T22:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331345#M83905</link>
      <description>&lt;P&gt;You might have the timeout set too low. Default is 45 mins. &amp;nbsp;I have mine set to 24 hours. &amp;nbsp;Some suggest 8 is OK but it depends on domain activity. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 10:59:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331345#M83905</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-06-03T10:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331471#M83919</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;We have it for 15 hours and even if it was 45mins that would not explain why within matter of minutes there is username associated for some traffic while not for other.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 18:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331471#M83919</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-03T18:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331476#M83921</link>
      <description>&lt;P&gt;Yes i can now see that in your original post. How many servers are you monitoring. Could it be that one of them is not reading the security logs correctly and overwriting the correct information.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 19:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331476#M83921</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-06-03T19:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331500#M83922</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you are using exchange, I would suggest checking against it. The reason is that when Outlook is open it is authenticating very frequently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 20:50:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331500#M83922</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-06-03T20:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331551#M83937</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;Thanks for suggestions. But how would i check/determine if some server is not reading security logs correctly. We are using 3 of them. Also there is no exchange server, its O365 that we have.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did install agent on 1 of them and it seems better, but i will monitor and update&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 03:06:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331551#M83937</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2020-06-04T03:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331562#M83940</link>
      <description>&lt;P&gt;To test this i would remove 2 servers from user id and see what happens, then add a second, monitor, then add the third.... it should not cause any issues as you seem not to be using id’s for policies.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 05:00:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/331562#M83940</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-06-04T05:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/360904#M88155</link>
      <description>&lt;P&gt;this has become some serious issues in my environment. I have 20 firewalls and 10 ipsec site to site.&amp;nbsp;&lt;/P&gt;&lt;P&gt;the recent issue I just realized is that if a user on GP crossing ipsec tunnel from PA to PA, the user id will be dropped at the destination,&amp;nbsp;&lt;/P&gt;&lt;P&gt;and now all the rules will be denying because it can not see the username.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is very unstable, since 2017, I have been opening tickets 2~3 times a year and still no solid solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 18:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/360904#M88155</guid>
      <dc:creator>Arjang999</dc:creator>
      <dc:date>2020-11-05T18:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/360935#M88157</link>
      <description>&lt;P&gt;Some critical information is missing from your explanation but I will assuming your setup is the following:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; UserA connects via GP to FirewallA&lt;/P&gt;&lt;P&gt;2. UserA then accesses a resource behind&amp;nbsp; FirewallB&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; FirewallB&amp;nbsp; has an ipsec s2s tunnel to FirewallA and this is how GP users are reaching the resource behind FirewallB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the above&amp;nbsp; is true, then FirewallB needs to be receiving redistributed GP mappings from FirewallA.&amp;nbsp; FirewallB doesn't magically know about the ip to user mapping of UserA that is known to FirewallA.&amp;nbsp; FirewallB must be told wha the ip to user mapping is by configuring user-id redistribution.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 20:01:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/360935#M88157</guid>
      <dc:creator>staustin</dc:creator>
      <dc:date>2020-11-05T20:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/360972#M88158</link>
      <description>&lt;P&gt;you are right on the setup.&lt;/P&gt;&lt;P&gt;and I have user identification enabled on the tunnel ZONEs, and both firewall A and B are pointed 4 AD servers for monitoring and user id mapping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but Im guessing I would need the redistribution ?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/panorama-overview/user-id-redistribution-using-panorama.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/8-1/panorama-admin/panorama-overview/user-id-redistribution-using-panorama.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;P&gt;thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 20:24:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/360972#M88158</guid>
      <dc:creator>Arjang999</dc:creator>
      <dc:date>2020-11-05T20:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID not mapping all traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/360973#M88159</link>
      <description>&lt;P&gt;Your guess is correct, you do need user identification, but you also need redistribution.&amp;nbsp; User identification turns on the ability to learn mappings and redistribution actually sends the mapping from FirewallA to FIrewallB.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 20:26:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping-all-traffic/m-p/360973#M88159</guid>
      <dc:creator>staustin</dc:creator>
      <dc:date>2020-11-05T20:26:38Z</dc:date>
    </item>
  </channel>
</rss>

