Each users have two and four accounts in their office.
All account are authenticated by Active-Directoy.
Each users use several accounts on one PC at the same time.
Mr, A has 'AAA' account and 'aaa' account.
He uses 'AAA' account when connect Internet.
He uses 'aaa' account when connect office E-Mail.
He uses two accounts on one PC(one IP) at the same time.
I know that one IP has only one User-ID in PaloAlto FW.
My customer wants to enforce security policy about only 'AAA' account.
But PA doesn't enforce security policy when Mr, A use 'aaa' account.
Someone help me!
Are there good ideas resolved?
Solved! Go to Solution.
You can create ignore list for unwanted accounted but the issue is, User A use AAA account in AD, he will be known as AAA in Palo but it wants to connect to email with aaa and aaa is in ignore list, your user will move to "unknown".
In my minf, the only way to do that should be to open two different OS sesssion then two IP then two account.
hope it help.
If you are on 4.1.x OS version then you will have user id agent installed on the DC.
Then you can look at the following docs to create an ignore user list
If you are on 5.0.x and are using agentless user id agent then as Vince pointed you can use those docs as reference
Hope this helps.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!