<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP Rights Query. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-rights-query/m-p/361306#M88168</link>
    <description>&lt;P&gt;- Event Log Readers&amp;nbsp; (The FW needs permission to read the Security Log on the DC, so when a user (fred, authenticates/logs onto his his computer with 172.16.1.55, and the DC authentication is successful, the UserID agent matches fred:172.16.155 and fwds to the FW.&lt;/P&gt;
&lt;P&gt;Now the FW knows that 172.16.1.55 = Fred.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Server Operators&amp;nbsp; (used for File/Print shares.&amp;nbsp; As long as someone has a drive mapped or printer mapped, that share session is in use.&amp;nbsp; The Server Operator confirms the user is still using/has permission to use.&amp;nbsp; The IP of the user is captured.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Distributed COM Users&amp;nbsp; - used for probing unknown IPs within the network.&amp;nbsp; An employee bring laptop in sleep mode, into corporate network.&amp;nbsp; He wakes up computer and then plugs in Ethernet cable.&amp;nbsp; Did he authenticate yet?&amp;nbsp; (NO), but he got a DHCP address.&amp;nbsp; So WHO has this IP.&amp;nbsp;&amp;nbsp; probing IP allows the FW to ask the device "who are you" and the user comes back as "fred".&amp;nbsp; Again, now the FW knows that 172.16.1.55 = Fred)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2020 13:32:52 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2020-11-06T13:32:52Z</dc:date>
    <item>
      <title>LDAP Rights Query.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-rights-query/m-p/361268#M88165</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To create the service account in AD, which is utilized on the device. we know that below rights are needed.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Distributed COM Users&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Event Log Readers&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Server Operators&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My query is why it necessary, what it's justification to be a part of this rights.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In cisco asa it is not necessary that's why I am have this query.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 11:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-rights-query/m-p/361268#M88165</guid>
      <dc:creator>OsamaKhan</dc:creator>
      <dc:date>2020-11-06T11:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Rights Query.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-rights-query/m-p/361306#M88168</link>
      <description>&lt;P&gt;- Event Log Readers&amp;nbsp; (The FW needs permission to read the Security Log on the DC, so when a user (fred, authenticates/logs onto his his computer with 172.16.1.55, and the DC authentication is successful, the UserID agent matches fred:172.16.155 and fwds to the FW.&lt;/P&gt;
&lt;P&gt;Now the FW knows that 172.16.1.55 = Fred.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Server Operators&amp;nbsp; (used for File/Print shares.&amp;nbsp; As long as someone has a drive mapped or printer mapped, that share session is in use.&amp;nbsp; The Server Operator confirms the user is still using/has permission to use.&amp;nbsp; The IP of the user is captured.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Distributed COM Users&amp;nbsp; - used for probing unknown IPs within the network.&amp;nbsp; An employee bring laptop in sleep mode, into corporate network.&amp;nbsp; He wakes up computer and then plugs in Ethernet cable.&amp;nbsp; Did he authenticate yet?&amp;nbsp; (NO), but he got a DHCP address.&amp;nbsp; So WHO has this IP.&amp;nbsp;&amp;nbsp; probing IP allows the FW to ask the device "who are you" and the user comes back as "fred".&amp;nbsp; Again, now the FW knows that 172.16.1.55 = Fred)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 13:32:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-rights-query/m-p/361306#M88168</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-11-06T13:32:52Z</dc:date>
    </item>
  </channel>
</rss>

