<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: security policy source user strange behavior in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/375098#M89147</link>
    <description>&lt;P&gt;yes it is configured.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I meant, is server monitor only need for wmi probing ?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Dec 2020 23:20:09 GMT</pubDate>
    <dc:creator>giacomomarconi</dc:creator>
    <dc:date>2020-12-17T23:20:09Z</dc:date>
    <item>
      <title>security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/373483#M88935</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I am using ldap users as source user in security policy.&lt;/P&gt;&lt;P&gt;The policy defines who can access http-service and https-service to the internet.&lt;/P&gt;&lt;P&gt;After the Firewall there are about 500 PCs and about 10% PCs stop to browse the internet every 20-30min, pressing F5 in the browser seems to solve.&lt;/P&gt;&lt;P&gt;The only thing that I understood is that the problem is always in those PC.&lt;/P&gt;&lt;P&gt;Removing the source user limitation this problem disappear.&lt;/P&gt;&lt;P&gt;Any idea on howto debug this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks very much&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 10:57:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/373483#M88935</guid>
      <dc:creator>giacomomarconi</dc:creator>
      <dc:date>2020-12-10T10:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/373605#M88939</link>
      <description>&lt;P&gt;try to increase user identification timeout (min) from default 45 to 8 hours (480)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for debug overide interzone default policy and log session start.&lt;/P&gt;&lt;P&gt;look for traffic with no source user.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 17:27:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/373605#M88939</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T17:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/373712#M88950</link>
      <description>&lt;P&gt;Do you see an intermittent blank 'source user' value on traffic logs (Monitor &amp;gt; Traffic) once it fails?&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may verify this by filtering in traffic logs the following:&amp;nbsp;( user.src neq 'source-user' ) and ( addr.src in x.x.x.x ).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that is the case, most likely the User-to-IP mapping is being lost due to Timeout. Ref doc:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZzCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZzCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can either increase the User Identification Timeout or remove the check from the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Enable User Identification Timeout&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More information about&amp;nbsp;User Identification Timeout:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNVyCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNVyCAO&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 00:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/373712#M88950</guid>
      <dc:creator>saraya</dc:creator>
      <dc:date>2020-12-11T00:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/373942#M88988</link>
      <description>&lt;P&gt;Thank you both for the answers.&lt;/P&gt;&lt;P&gt;at the moment i disabled the user identification in the policies, to keep people work.&lt;/P&gt;&lt;P&gt;I noticed that pc/user with problem are always the same.&lt;/P&gt;&lt;P&gt;And the interruption (i see the empty user in url filtering) is less of the 45min set in the timeout setting.&lt;/P&gt;&lt;P&gt;next week I will set up a little lab where to try to reproduce the problem.&lt;/P&gt;&lt;P&gt;should I look at the user id agent server to find something ?&lt;/P&gt;&lt;P&gt;Giacomo&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 21:39:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/373942#M88988</guid>
      <dc:creator>giacomomarconi</dc:creator>
      <dc:date>2020-12-11T21:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374006#M88992</link>
      <description>&lt;P&gt;this will be easy to diagnose without a lab.&lt;/P&gt;&lt;P&gt;Just clone your HTTP/HTTPS policy that has no user identification and call it user-test.&lt;/P&gt;&lt;P&gt;add this directly above and allow with source user ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will not block users as they will drop down to the next policy that will allow if no user id is found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;monitor the traffic for http(s) and when a user is using user-test then you know user id is working for them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you see a user on the other policy then search for that user on the server agent under "monitoring".&lt;/P&gt;&lt;P&gt;if the search is blank then the ip address associated with that user may have timed out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please note that the user timeout has nothing to do with timestamps on traffic monitor, it is the time since the ip address was last observed in the security logs by the agent. so a user could be fine at 10:44 and at 10:46 no traffic.&amp;nbsp; this is because they registered their ip address at 10:00 and it has now timed out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if it applies to a particular set of users then this could be because their domain activity is not as frequent as others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the server agent you can increase timeout here under setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1607762013818.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29114iCF34C78BF5150209/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1607762013818.jpeg" alt="MickBall_0-1607762013818.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 08:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374006#M88992</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-12T08:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374470#M89061</link>
      <description>&lt;P&gt;I increased the timeout to 600, but when I launch:&lt;/P&gt;&lt;P&gt;show user ip-user-mapping all type UNKNOWN&lt;/P&gt;&lt;P&gt;I always see about 10-15 PCs in the unknown list.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 10:44:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374470#M89061</guid>
      <dc:creator>giacomomarconi</dc:creator>
      <dc:date>2020-12-15T10:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374471#M89062</link>
      <description>&lt;P&gt;The new user mapping timeout will only start on the next new mapping,&amp;nbsp; are you monitoring AD security logs.&lt;/P&gt;&lt;P&gt;If so then get user to log out and back in to update security log on AD.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 10:51:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374471#M89062</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-15T10:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374552#M89067</link>
      <description>&lt;P&gt;&lt;EM&gt;this will be easy to diagnose without a lab.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Just clone your HTTP/HTTPS policy that has no user identification and call it user-test.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;add this directly above and allow with source user ID.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see a lot fo empty "source user" in "Monitor/Url Filtering" also without that rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 16:39:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374552#M89067</guid>
      <dc:creator>giacomomarconi</dc:creator>
      <dc:date>2020-12-15T16:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374967#M89127</link>
      <description>&lt;P&gt;I tried to add a third User-id Agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the need of User Identification &amp;gt; User Mapping &amp;gt; server monitoring tab ?&lt;/P&gt;&lt;P&gt;If I press discover my DC's are listed, but with the access denied error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks very much for yours help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 14:59:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374967#M89127</guid>
      <dc:creator>giacomomarconi</dc:creator>
      <dc:date>2020-12-17T14:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374968#M89128</link>
      <description>&lt;P&gt;have you setup a server monitor account in the agent setup?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 15:08:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/374968#M89128</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-17T15:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: security policy source user strange behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/375098#M89147</link>
      <description>&lt;P&gt;yes it is configured.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I meant, is server monitor only need for wmi probing ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 23:20:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-source-user-strange-behavior/m-p/375098#M89147</guid>
      <dc:creator>giacomomarconi</dc:creator>
      <dc:date>2020-12-17T23:20:09Z</dc:date>
    </item>
  </channel>
</rss>

