- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-06-2022 05:39 AM - edited 07-06-2022 05:40 AM
Hi,
I'm currently managing a PA-220 and have setup URL-filtering.
I can see which IP-addresses that tries to access the blocked websites.
Is there any possibility to resolve/match this IP-address to our DHCP server to see exactly which mac/computer it is accessing the blocked sites.
We have it setup so all computers on our company network have unique names.
Currently what I have to do is to check the url filtering log and look for the IP and then crossmatch that IP with dhcp server.
Or is there any other way to do this thats less time consuming.
I know there are some ways to connect the Palo alto to Active directory but im not sure exactly how to solve this.
07-06-2022 06:23 AM
Hi @Rasmus_Edholm ,
It sound you need User-ID. I would suggest you to take a look at the following links as starting point
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/user-id-overview
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRyCAK
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5bCAC
If I try to sum it up - As firewall works with IP addresses, you need a way to associate the soure IP (from where the traffic originates) with username. Palo Alto is capable to use different sources for such information. Once the firewall receive user-to-ip mapping you will see the associated username in the logs. You can even create the firewall rules allowing user/user groups.
My personal recommendation is to use GlobalProtect with Internal Gateway as source of user-to-ip mapping.
07-06-2022 07:16 AM
Hi, thanks for your answer. I will definitely take a look at those links you posted.
But for user-id do I need to have the computers join the AD, or is it enough to just create the computers manually in AD(via powershell).
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!