<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PaloAlto FW RDP Across multiple AD domains in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-fw-rdp-across-multiple-ad-domains/m-p/381412#M89751</link>
    <description>&lt;P&gt;I'm part of a cloud team that does not manage the FW but am not getting clear answers from them.&lt;/P&gt;&lt;P&gt;My operations counterparts have the following issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Support person logs into IP address x.x.x.x into production domain. As part of their function, they must RDP into servers on prod/dev/pat/sit domains. Each domain with a separate ID once the rdp client hits the end point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After some time passes, RDP stops working to a particular domain or set of domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To resolve this at times, the network team has restarted some agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They can't explain why it happens. It's become a huge nuisance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2021 05:19:56 GMT</pubDate>
    <dc:creator>PhlackJack</dc:creator>
    <dc:date>2021-01-22T05:19:56Z</dc:date>
    <item>
      <title>PaloAlto FW RDP Across multiple AD domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-fw-rdp-across-multiple-ad-domains/m-p/381412#M89751</link>
      <description>&lt;P&gt;I'm part of a cloud team that does not manage the FW but am not getting clear answers from them.&lt;/P&gt;&lt;P&gt;My operations counterparts have the following issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Support person logs into IP address x.x.x.x into production domain. As part of their function, they must RDP into servers on prod/dev/pat/sit domains. Each domain with a separate ID once the rdp client hits the end point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After some time passes, RDP stops working to a particular domain or set of domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To resolve this at times, the network team has restarted some agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They can't explain why it happens. It's become a huge nuisance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 05:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-fw-rdp-across-multiple-ad-domains/m-p/381412#M89751</guid>
      <dc:creator>PhlackJack</dc:creator>
      <dc:date>2021-01-22T05:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto FW RDP Across multiple AD domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-fw-rdp-across-multiple-ad-domains/m-p/381503#M89754</link>
      <description>&lt;P&gt;quick question,,,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does the rdp sessions to that domain get disconnected whilst in use or are new connections not allowed through?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it may be that there is not enough domain activity for the user agent to be updated. if so then it may be worth trying to increase the user timeout from default 45 mins to 8 hours or so...&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 12:23:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-fw-rdp-across-multiple-ad-domains/m-p/381503#M89754</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-01-22T12:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto FW RDP Across multiple AD domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-fw-rdp-across-multiple-ad-domains/m-p/381857#M89780</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169130"&gt;@PhlackJack&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So the thing with RDP is that, depending on the configuration, the endpoint that you are using authenticates the request and user-id on the firewall can switch to the authenticated RD user instead. Depending on the firewalls configuration, this may make it so that the endpoint is identified with a user that doesn't actually have the proper permission on the firewall to work properly. So what the admin is likely doing is simply clearing the user-id entry associated with the endpoint.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It could also easily be that the user-id information is aging out like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;mentioned. Again, this would mean that if user-id is being leveraged in the rulebase they would no longer be able to do certain actions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regardless of the issue, it sounds like you're running into a user-id issue. Your network team should be able to address this relatively easily through various methods.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 04:36:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-fw-rdp-across-multiple-ad-domains/m-p/381857#M89780</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-01-25T04:36:49Z</dc:date>
    </item>
  </channel>
</rss>

