- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-06-2013 02:31 AM
Hello
Each users have two and four accounts in their office.
All account are authenticated by Active-Directoy.
Each users use several accounts on one PC at the same time.
For example,
Mr, A has 'AAA' account and 'aaa' account.
He uses 'AAA' account when connect Internet.
He uses 'aaa' account when connect office E-Mail.
He uses two accounts on one PC(one IP) at the same time.
I know that one IP has only one User-ID in PaloAlto FW.
My customer wants to enforce security policy about only 'AAA' account.
But PA doesn't enforce security policy when Mr, A use 'aaa' account.
Someone help me!
Are there good ideas resolved?
08-06-2013 03:00 AM
Hi,
You can create ignore list for unwanted accounted but the issue is, User A use AAA account in AD, he will be known as AAA in Palo but it wants to connect to email with aaa and aaa is in ignore list, your user will move to "unknown".
In my minf, the only way to do that should be to open two different OS sesssion then two IP then two account.
hope it help.
V.
08-06-2013 04:29 AM
Thanks, VinceM.
Where is ignore list menu on agentless?
And Is it possible that ignore 'aaa' account is put into ignore list?? I know to configure only ip address.
08-06-2013 11:21 AM
If you are on 4.1.x OS version then you will have user id agent installed on the DC.
Then you can look at the following docs to create an ignore user list
https://live.paloaltonetworks.com/docs/DOC-1987
https://live.paloaltonetworks.com/docs/DOC-1116
If you are on 5.0.x and are using agentless user id agent then as Vince pointed you can use those docs as reference
https://live.paloaltonetworks.com/docs/DOC-4278#comment-3404
https://live.paloaltonetworks.com/message/22261#22261
Hope this helps.
Thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!