<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Information in Firewall Database Cache in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-information-in-firewall-database-cache/m-p/12839#M9411</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like the Captive Portal expiration time has yet to be reached for the original user and the guest user is authenticating based on that.&amp;nbsp; You can reduce the expiration time and verify if the guest is recogonized.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Apr 2010 23:23:49 GMT</pubDate>
    <dc:creator>nrice</dc:creator>
    <dc:date>2010-04-26T23:23:49Z</dc:date>
    <item>
      <title>User Information in Firewall Database Cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-information-in-firewall-database-cache/m-p/12838#M9410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1: Captive Portal is set for entire network ( 192.168.1.0) and in Active Directory the group ( IT) is choosen which will be filtered or monitored. There are &lt;BR /&gt;&lt;BR /&gt;two users ( user1/user2) who are member of this group.&lt;BR /&gt;&lt;BR /&gt;Firewall Rule :&lt;BR /&gt;==============&lt;BR /&gt;&lt;BR /&gt;1:&amp;nbsp; Trust to Untrust&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Action&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;1: ( Any known user)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Allow&lt;BR /&gt;2: ( Any Unknown user)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Block&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Issue:&lt;BR /&gt;=====&lt;BR /&gt;&lt;BR /&gt;When user 1 &amp;amp; user 2 login to shared workstation ( WS1) ( One after other)They both are able to browse internet and no issues. However after sometime the local administrator on that pc( WS1) is logged in, Locally on that machine to work and he is trying to browse internet( Ideally that user is unknown he should be prompted for authentication and he can use any guest based user account from AD ( guest 1) to access internet with limited accessibity of sites.This is not happening, the moment the local adminstration is login into that machine ( WS1) and trying to browse internet, that user is getting internet access.Seems like there is some sort of Cached information which shows that ( WS1) is still being used by known users and its not able to refresh it.&lt;BR /&gt;&lt;BR /&gt;I tried to reset the user captive portal session using this command:-&lt;BR /&gt;&lt;BR /&gt;# debug device-server reset captive-portal ip-address 192.168.1.104&lt;BR /&gt;&lt;BR /&gt;It was of no help, &lt;BR /&gt;&lt;BR /&gt;Resolution:&lt;BR /&gt;=============&lt;BR /&gt;&lt;BR /&gt;When i restarted the PAN agent, it started to work and that agent was showing 192.168.1.104 Ip as unknown and when tried to open the IE and browse on that &lt;BR /&gt;&lt;BR /&gt;pc. it showed the authentication .&lt;BR /&gt;&lt;BR /&gt;This is a issue with us, and we will not be able to apply the policies on the users.&lt;BR /&gt;&lt;BR /&gt;Observations:&lt;BR /&gt;&lt;BR /&gt;==============&lt;BR /&gt;&lt;BR /&gt;1: When we checked the logs in Firewall Monitor TAB, It was still showing us last logged in username and the logs were showing his name with latest &lt;BR /&gt;&lt;BR /&gt;timestamp. We even checked by browsing some of the websited and enabled ( Resolve) in the logs to see and synchronize the domain name we were browsing as &lt;BR /&gt;&lt;BR /&gt;current local administrator. However in the logs it was showing as domain user who is no more logged into that machine.&lt;BR /&gt;&lt;BR /&gt;Any Suggestion on this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Apr 2010 19:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-information-in-firewall-database-cache/m-p/12838#M9410</guid>
      <dc:creator>paramount</dc:creator>
      <dc:date>2010-04-24T19:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: User Information in Firewall Database Cache</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-information-in-firewall-database-cache/m-p/12839#M9411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like the Captive Portal expiration time has yet to be reached for the original user and the guest user is authenticating based on that.&amp;nbsp; You can reduce the expiration time and verify if the guest is recogonized.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 23:23:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-information-in-firewall-database-cache/m-p/12839#M9411</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-04-26T23:23:49Z</dc:date>
    </item>
  </channel>
</rss>

