- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
06-23-2014 12:19 PM
Hey All -
I am just curious to find out how people are doing User-ID? We are currently using the software Agents connected to DC's, and we read syslog from our Wireless Controllers to parse user to IP mappings for wireless. Our wireless solution is only about 50% accurate due to the fact that many times logs are written to the wireless controller before the DHCP process completes, so we see a log that contains a User ID but an IP of 0.0.0.0.
How are others doing user-ID? We have a global environment and don't really have one central place for User-ID.. that being said we have a couple servers here in the US with software agents on them, 2 in AsiaPac, and 2 in Europe. Wondering what other people are doing to help with accurate user-id?
Thanks!
06-23-2014 01:47 PM
Hello matt.rosloniec@amway.com,
This document will get you started:
User-ID Best Practices - PAN-OS 5.0, 6.0
Hope that helps!
Thanks and regards,
Kunal Adak
06-23-2014 02:57 PM
If your wireless solution is Aruba check with your sales engineer. They now have the ability to connect directly from the controllers to PA user-id.
06-24-2014 04:25 PM
Try using WMI probing as one of the most correct methods, but bear in mind to limit the scope of probing to the local network, because you probably dont want to send wmi probes from usa to europe for each unknown user.
Also one other thing you can do is to include the exchange in the monitored servers.
As far as it goes for aruba, check these docs which show you how to get the logs directly to the syslog receiver that can be run on the PA or on the user-id server:
-How to Collect the User-IP Mappings from a Syslog Sender Using an User-ID Agent
-How to Configure a Custom Syslog Sender and Test User Mappings
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!