- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
11-10-2016 03:30 PM
Hi Everyone,
I am trying to intergrate clearpass with Palo alto using xlampi, all was going well however i struck a problem
In clearpass i have two types of users that are autheticating, domain joined machines (which authenticate using "compute authentication" and i also have byod users that authenticate using user based ad authetication.
so when a byod users authenticates with his ad credentials against clear pass and this is passed through to Palo alto all is good . Ihave a xlampi mapping of user and IP.
However when a user authenticates against Clearpass as a domain machine ,I now have a xmlapi mapping of ip and computer name . and considering my palo alto policies are user based policies user cant get internet.
I do have uia in play which works well for domain machines, but i have the problem when both are in play sometimes the xmlapi mapping from clearpass overides the uia mapping.
Hope that makes sense
Kind Regards
Paul
My thought was to set a ignore list as all computers that get authenticated via xmlapi appear domain\computername$
show user ip-user-mapping all | match $
it returns 1026 results so using set vsys vsys1 user-id-collector ignore-user domain\*$ ?
however this brings all users back will ignore 1026
and thats were i am stuck.
01-16-2018 11:55 AM
Do you have the following set?
CPPM > Administration > External Servers > Endpoint Context Servers > (Your PANs) > Username Transformation = Prefix NETBIOS name
I have users connecting with Computer Authentication and they show up as:
(domain)/(computer host name)$
example: abc/my-host$
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!