Source User Doesn't Show

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Source User Doesn't Show

L2 Linker

Dears,

          I have a problem with uses coming from WIFI and non-joined domain the source user doesn't show and show a blank please find the image.

I have installed the CA's for our domain and the PA put didn't work.

 

Our infrastructure as shown below.

        Wireless Controller "Cisco Aironet 1850 Series Mobility Experss"

 

 

Infr.jpg

 

 

Capture.JPG 

 

5 REPLIES 5

Cyber Elite
Cyber Elite

There are a few things that could be missing: did you enable user-ID on the wifi-staff zone?

is the user showing up in the user-id agent?

do you have captive portal enabled as backup mechanism?

 

have you set up separate user-id agents for the non-joined domain ?

 

is the user showing in

admin@PA-220> show user ip-user-mapping ip 10.3.11.12

 

Here's an article with more information how to make sure everything is covered: https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-User-ID/ta-p/69321

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Thank you for your response.

 

is the user showing in

admin@PA-220> show user ip-user-mapping ip 10.3.11.12

no didn't shown. 

                                    No matched record

 

 

did you enable user-ID on the wifi-staff zone?

                                   Yes, the user-ID is enabled on WIIF-Staff Zone

 

is the user showing up in the user-id agent?

                                   No, the user doesn't show on the Palo Alto Network User-ID Agent

 

do you have captive portal enabled as a backup mechanism?

                                   No, the captive portal not enabled 

Hi @Mahmoud-Osama

 

Then the behavior on the firewall is normal, you'll need to address one of the perifery issues:

 

-why is the userID agent not populating the logins: is the AD they use to authenticate being polled/monitored, or does it have it's own agent? is 'log audit success' enabled in the local security policies of the AD?

 

 

you may need to install a separate user-id agent for the non-joined domain you mentioned, and attach that to the firewll specifically for these users

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Typically wireless clients are authenticated by Radius, so information about user name and IP address will not appear in the security logs on the domain controllers. So you will have to setup your Radius server or your wireless controllers to send the information to PA. This can be done for example using XML-API or Syslog.

Thanks i will try and let you know what is happen.

  • 3516 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!