I'm currently managing a PA-220 and have setup URL-filtering.
I can see which IP-addresses that tries to access the blocked websites.
Is there any possibility to resolve/match this IP-address to our DHCP server to see exactly which mac/computer it is accessing the blocked sites.
We have it setup so all computers on our company network have unique names.
Currently what I have to do is to check the url filtering log and look for the IP and then crossmatch that IP with dhcp server.
Or is there any other way to do this thats less time consuming.
I know there are some ways to connect the Palo alto to Active directory but im not sure exactly how to solve this.
Hi @Rasmus_Edholm ,
It sound you need User-ID. I would suggest you to take a look at the following links as starting point
If I try to sum it up - As firewall works with IP addresses, you need a way to associate the soure IP (from where the traffic originates) with username. Palo Alto is capable to use different sources for such information. Once the firewall receive user-to-ip mapping you will see the associated username in the logs. You can even create the firewall rules allowing user/user groups.
My personal recommendation is to use GlobalProtect with Internal Gateway as source of user-to-ip mapping.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!