<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserID issue when using RDP via GlobalProtect client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-issue-when-using-rdp-via-globalprotect-client/m-p/379534#M89579</link>
    <description>&lt;P&gt;&amp;nbsp;Have you tried increasing the user ID timeout.&lt;/P&gt;&lt;P&gt;The default is 45 mins so after that time the original GP auth mapping will be lost.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users can then connect to many devices within the same GP connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would prefer to place users in different groups and then use group membership in the policies.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jan 2021 12:46:06 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2021-01-13T12:46:06Z</dc:date>
    <item>
      <title>UserID issue when using RDP via GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-issue-when-using-rdp-via-globalprotect-client/m-p/379466#M89572</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have the following issue when using RDP via GlobalProtect client.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Situation:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PaloAlto 820 with PAN-OS 9.0.9, GloablProtect Client 5.2.4, Windows 2016 Active Directory&lt;/LI&gt;&lt;LI&gt;For remote access we use GlobalProtect with Active Directory accounts (RADIUS authentication to AD)&lt;/LI&gt;&lt;LI&gt;User-ID is used utilizing an UserID agent installed on the DC&lt;/LI&gt;&lt;LI&gt;User-based policies are used&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When a user connects via Global Protect it's traffic is associated with the domain user name used for establishing VPN connection. It has all access allowed for that user name. At some point, user makes RDP connection to some server or workstation, and logs into it using the same user name (it is his own domain user name, the only one he has). From that moment that user name is mapped to the IP address of remote computer, and is no longer mapped to the IP address he/she was assigned when VPN connection was established. As a result, traffic coming from that user via VPN connection is no longer associated with it's user name, and he/she can't create new connections allowed by user based policies. For example user can't establish second RDP session!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Used Solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We make different IP pools, assign GP users IP addresses from pools according to group membership, and create policies based on IP address. So we don't use user id based policies for VPN users. However, this "solution" is not good for us.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other possible solutions we see&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;Use different User ID for GlobalProtect only. That would be problematic for users, which would need to have one more user/password combination. It will also make administration of policies harder, as we have to use two different usernames for the same user - one for VPN related policies, and another - for other policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have any ideas, or if you I'm getting wrong the reason for that effect, please let me know. Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 10:50:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-issue-when-using-rdp-via-globalprotect-client/m-p/379466#M89572</guid>
      <dc:creator>GeorgeAPH</dc:creator>
      <dc:date>2021-01-13T10:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: UserID issue when using RDP via GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-issue-when-using-rdp-via-globalprotect-client/m-p/379534#M89579</link>
      <description>&lt;P&gt;&amp;nbsp;Have you tried increasing the user ID timeout.&lt;/P&gt;&lt;P&gt;The default is 45 mins so after that time the original GP auth mapping will be lost.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users can then connect to many devices within the same GP connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would prefer to place users in different groups and then use group membership in the policies.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 12:46:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-issue-when-using-rdp-via-globalprotect-client/m-p/379534#M89579</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-01-13T12:46:06Z</dc:date>
    </item>
  </channel>
</rss>

