nt-autorität\anonymous-anmeldung

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L2 Linker

nt-autorität\anonymous-anmeldung

Hello Guys,
I have sometimes a problem with the user identification on the PA500. Our Users can only browse the internet with your AD-User. Sometime the User is lost on the PA. The User "nt-autorität\anonymous-anmeldung" is used? Why? How can I find a solution?

 

Thanks

 

cu
Wolfgang


Accepted Solutions
Highlighted
L2 Linker

Hi,

I think the solution is/was to store the ignore_user_list.txt as UniCode!!!

 

Thanks to all

 

cu

Wolfgang

View solution in original post


All Replies
Highlighted
L4 Transporter

You should exclude this user from user id by adding him to the ignore user list.

As far as I know, this user is for anonymous accessing e.g. printers or shares if configured.

Best Regards
Chacko
Highlighted
L2 Linker

Hi Chacko42,

I had this done...but it's not the solution :-(

 

Palo.jpg

 

Any other Idea?

 

Thanks

 

cu

Wolfgang

Highlighted
L4 Transporter

Do you receive user-id updates only by using the integrated agent or are there other sources as well?

I assume you can see this user-mapping in current traffic logs? Are these current sessions or older ones?
Can you see the user by querying "show user ip-user-mapping all" on your FW?

Best Regards
Chacko
Highlighted
Cyber Elite

@w.naderer

Do you have netbios probing enabled on the user id agent?

Highlighted
L2 Linker

We have installed the Palo Agents on our Active Directory Controller.
Yes, the User is switching automatically from userid into nt\authority... in the current traffic log.

How can I do the command?

 

Thanks

 

cu

Wolfgang

L4 Transporter

Alright, there is the problem.

The setting in the web UI is only for the agentless User-ID (FW polls DCs directly).

 

You need to define the ignore-users on the user-id agent on your ADC by creating a file

https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/configure-user-mapping-using... (search for ignore)

Best Regards
Chacko
Highlighted
L7 Applicator

the ignore list needs to be on the agent on the AD controller, adding the ignore user list on the firewall may only exclude it from locally learned user-ID

 

you'll need to add "ignore_user_list.txt" in the User-ID install directory, then add the name to the text file

Tom Piens - PANgurus.com
New to PAN-OS or getting ready to take the PCNSE? check out amazon.com/dp/1789956374
Highlighted
L2 Linker

Netbios Probing is YES and the interval is 20 minutes

 

I also implemented the ignore list on the ADC

user.jpg

 

Thanks

 

cu

Wolfgang

Highlighted
L2 Linker

Hi,

Which settings play a role in the comparison?
Can I evaluate something on the User-ID-Agent or does it make sense to delete such entries manually?

 

Thank you

 

Cu

Wolfgang

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!