- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-26-2013 01:05 PM
the mgmt interface on a 3050 is reaching out to a number of internal host over msrpc (tcp/135). i've not been successful in discoving the purpose of this via the admin guide - is anyone else seeing this behavior?
thx,
tommyluke
09-26-2013 02:37 PM
Hello Tom,
What I meant was, we haven't seen any problems/ issues per say - after enabling 'Client Probing' in Agentless setup. It just that we saw un-wanted WMI probes from the User-ID function on port 135.
In fact after further investigation, it looks like the issue has been taken care of in PANOS - 5.0.7 and you can verify that in its release notes by 52967.
Regards,
Kunal Adak.
09-26-2013 01:47 PM
Hello Tom,
Do you have Agentless UserID configured on your firewall? If so, we need to make sure that we disable Client probing under Device > User Identification > User Mapping > Client probing tab.
Regards,
Kunal Adak
09-26-2013 02:13 PM
Thank you kadak. You are correct, I have agentless userid configured. I imagine that, were I to disable client probing, the msrpc data from the management ip would cease. When you stat that we need to "make sure that we disabled client probing" is that because you have experienced problems with client probing?
best,
tommy
09-26-2013 02:37 PM
Hello Tom,
What I meant was, we haven't seen any problems/ issues per say - after enabling 'Client Probing' in Agentless setup. It just that we saw un-wanted WMI probes from the User-ID function on port 135.
In fact after further investigation, it looks like the issue has been taken care of in PANOS - 5.0.7 and you can verify that in its release notes by 52967.
Regards,
Kunal Adak.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!