Two client account on one PC

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L4 Transporter

Two client account on one PC

Hello

Each users have two and four accounts in their office.

All account are authenticated by Active-Directoy.

Each users use several accounts on one PC at the same time.

For example,

Mr, A has 'AAA' account and 'aaa' account.

He uses 'AAA' account when connect Internet.

He uses 'aaa' account when connect office E-Mail.

He uses two accounts on one PC(one IP) at the same time.

I know that one IP has only one User-ID in PaloAlto FW.

My customer wants to enforce security policy about only 'AAA' account.

But PA doesn't enforce security policy when Mr, A use 'aaa' account.

Someone help me!

Are there good ideas resolved?


Accepted Solutions
Highlighted
L5 Sessionator

All Replies
Highlighted
L5 Sessionator

Hi,

You can create ignore list for unwanted accounted but the issue is, User A use AAA account in AD, he will be known as AAA in Palo but it wants to connect to email with aaa and aaa is in ignore list, your user will move to "unknown".

In my minf, the only way to do that should be to open two different OS sesssion then two IP then two account.

hope it help.

V.

Highlighted
L4 Transporter

Thanks, VinceM.

Where is ignore list menu on agentless?

And Is it possible that ignore 'aaa' account is put into ignore list?? I know to configure only ip address.

Highlighted
L5 Sessionator
Highlighted
L5 Sessionator

If you are on 4.1.x OS version then you will have user id agent installed on the DC.

Then you can look at the following docs to create an ignore user list

https://live.paloaltonetworks.com/docs/DOC-1987

https://live.paloaltonetworks.com/docs/DOC-1116

If you are on 5.0.x and are using agentless user id agent then as Vince pointed you can use those docs as reference

https://live.paloaltonetworks.com/docs/DOC-4278#comment-3404

https://live.paloaltonetworks.com/message/22261#22261

Hope this helps.

Thanks

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!