- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
06-01-2012 02:28 AM
Hi,
This might be a really easy thing I have missed but when we try to authenticate against our AD users instead of strictly by IP and zone it works fine the first person to log on. But then if you log off and someone else with less privilages logs on they get whatever access the previous person had, which could be a problem especially if the last person to log on was the domain admin for instance.
Any suggestions as to why this might be?
06-01-2012 07:37 AM
Is it possible that the second user doesn't logon to the domain? The agent monitors logins but is not aware of logouts, so if user "A" logins, then logs out, and then user "B" from the same workstation logs in locally, the agent will not see a new login for that same workstation and thus assume user "A" is still using that IP address.
06-01-2012 08:46 AM
No, they are definatly both domain users.
One thing that might help. I have 2 DC's in my forest. Perhaps my Palo Alto box only picks up logons that have authenticated with DC1?
But the only way I could have seen that happening if it was a one off as DC2 is just there as a fail over in case DC1 becomes unavailable.
Any other suggestions?
06-01-2012 09:17 AM
Please check the userID agent and confirm that it's monitoring both DC's. Also, check the agent's log to ensure that the agent has the permission to read the security log of both DC's. As long as the 2nd user logs into the AD domain, the agent will detect the 2nd user and update the PA device. Thanks.
06-01-2012 11:30 AM
What are the default settings regarding TTL's for the user-cache in the pan-agent?
And how will enabling WMI improve the hitrate?
06-12-2012 07:00 AM
Hi,
I have checked and yes the 2nd DC is set in the Palo Alto and yes they have permissions to read the security logs.
Also the default User TTL is 60 min under User idenfication in the ID agent
06-12-2012 07:33 AM
I would recommend opening a case with Support. Thanks.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!