<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID rule to bypass HIP check not matching. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410595#M92608</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a similar problem. I have some users connect by global protect with HIP Profile that sometimes they have match in one rule and othertimes they have match in another rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still have two rules, one with HIP and one without HIP profile for this reason.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to delete the rule without HIP profile but not for the moment because I have the doubt that if I don't have it... the traffic can go down as it is still maching on both rules&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can anyone help me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 08:36:45 GMT</pubDate>
    <dc:creator>BigPalo</dc:creator>
    <dc:date>2021-06-04T08:36:45Z</dc:date>
    <item>
      <title>User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/351441#M87069</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a rule to allow certain Global Protect users DNS and RDP traffic by matching the user-id. However, even though it looks like the traffic should match when I view the traffic log it's not?! For some users the rule works fine but others it doesn't match and I can't work it out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kevin.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 14:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/351441#M87069</guid>
      <dc:creator>adrianflux</dc:creator>
      <dc:date>2020-09-23T14:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/351631#M87086</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64161"&gt;@adrianflux&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Would really need to look at the logs to figure this out. You've verified that the user-id is recorded in the denied traffic logs and the rulebase entry properly passes when you do a&amp;nbsp;&lt;EM&gt;test security-policy-match?&amp;nbsp;&lt;/EM&gt;Can you give us an output of the security entry and an example of one of the logs that isn't currently working?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 02:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/351631#M87086</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-09-24T02:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/351666#M87092</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the user-id how is formatted in the logs like :&amp;nbsp; domain\bob&lt;/P&gt;&lt;P&gt;Then check the traffic logs that you interested and check there the user , it should be something else and that is the reason why&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then check the security policy to see if you have domain\bob like the user ID .&lt;/P&gt;&lt;P&gt;The HIP collection is taking the username and domain.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 06:57:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/351666#M87092</guid>
      <dc:creator>GeorgiosFakis</dc:creator>
      <dc:date>2020-09-24T06:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410595#M92608</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a similar problem. I have some users connect by global protect with HIP Profile that sometimes they have match in one rule and othertimes they have match in another rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still have two rules, one with HIP and one without HIP profile for this reason.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to delete the rule without HIP profile but not for the moment because I have the doubt that if I don't have it... the traffic can go down as it is still maching on both rules&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can anyone help me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 08:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410595#M92608</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-06-04T08:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410602#M92611</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;are there different HIP profiles specified in the two security policy rules?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 15:41:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410602#M92611</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-02T15:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410605#M92612</link>
      <description>&lt;P&gt;No, We have only one&amp;nbsp;&lt;SPAN&gt;HIP profiles specified in the one security policy rule&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The other rule does not have HIP profile applied&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 15:43:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410605#M92612</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-06-02T15:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410607#M92614</link>
      <description>&lt;P&gt;Then it looks like the HIP profile does not match all the time. What do you check with that HIP profile?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 15:44:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410607#M92614</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-02T15:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410738#M92636</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answer...but I think that it is not the problem because users sometimes match in correct rule If we had HIP profile wrong it never work fine , no?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 06:54:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410738#M92636</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-06-03T06:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410752#M92638</link>
      <description>&lt;P&gt;I was thinking about the HIP profile because of the topic here where you posted this comment. And also because in the screenshot everything is exactly the same. Another possibility would be an URL category in the rule which makes sometime match one and then again the other rule.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 08:03:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410752#M92638</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-03T08:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410787#M92644</link>
      <description>&lt;P&gt;When the user disconnects from GP there are session that will expire, therefore there is no HIP data at the moment . I have seen in my logs that is matching a "catch" rule DENY for those HIP profiles are not working.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 08:56:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410787#M92644</guid>
      <dc:creator>GeorgiosFakis</dc:creator>
      <dc:date>2021-06-03T08:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410913#M92664</link>
      <description>&lt;P&gt;Hi, thanks for your response, I have checked in my logs but I have not found rule DENY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I only see that user change your match for another rule but it is allow rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 15:10:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/410913#M92664</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-06-03T15:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID rule to bypass HIP check not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/411095#M92693</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are they RDP with the same account like the login username of GP ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you defined AD groups in the ACL ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What username is not matching the RDP and the DNS and have you compared that to the username login ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had the same issue and I deleted the source user AD group because I had users like domain\bob and the RDP was done by domain\admbob.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 06:42:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-rule-to-bypass-hip-check-not-matching/m-p/411095#M92693</guid>
      <dc:creator>GeorgiosFakis</dc:creator>
      <dc:date>2021-06-04T06:42:52Z</dc:date>
    </item>
  </channel>
</rss>

