User based ssl decryption

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

User based ssl decryption

L2 Linker

Hi,

 

I try to test ssl forward proxy decryption. It works fine if I use IP address as a source but if I use Users(domain) as a source it doesn't work. I can't use IP's for testing because our IP's floating. What I need to check in configuration?

 

Toni

1 accepted solution

Accepted Solutions

L4 Transporter

It seems the user to group mapping is not happening correctly. See this command for one ip

show user ip-user-mapping ip x.x.x.x

See if user is showing correctly

See also associated groups are showing correctly

If not add group mapping under Device-> user identification-> group mapping

PCNSE-7, ACE-6,ACE 7 , CCNP, CCNA,CCIE(theory) , RHCE
Firewalldog dot com

View solution in original post

12 REPLIES 12

L3 Networker

Is user identified properly and does show up on #show user ip-user-mapping all?

Cyber Elite
Cyber Elite

please take a look through this article to make sure UserID is set up properly:  Getting Started: User-ID

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Yep. User-ID works fine but user based decryption not.

That's odd.  We've been using TLS decryption for quite a while based on Active Directory group membership.  It works fine here (other than the fact that downloads over decrypted TLS sessions are incredibly slow).

Thanks for information. At least I know now that it could work.

Which version of PANOS are you running on?

I am running 7.0.5-h2, use user ID and do user based decryption as part of a pilot for decryption right now. No issues here.

Hello,

 

Our current version is 7.0.5-h2.

 

How you configure policy. Source address any and user domain\user ?

 

br

Toni

L4 Transporter

It seems the user to group mapping is not happening correctly. See this command for one ip

show user ip-user-mapping ip x.x.x.x

See if user is showing correctly

See also associated groups are showing correctly

If not add group mapping under Device-> user identification-> group mapping

PCNSE-7, ACE-6,ACE 7 , CCNP, CCNA,CCIE(theory) , RHCE
Firewalldog dot com

Hi,

 

show user ip-user-mapping ip x.x.x.x  --> I can see my username correctly. But I can't see any groups associated  --> Groups that the user belongs to (used in policy). This is empty.

 

 

I can see my username in group if  --> show user group name "CN=XXXXXXXXX,OU=XXXXXXXX,OU=XXXX,DC=XX,DC=XXXXXX,DC=XXXX,DC=XXX"

 

 

Toni

Sorry that was used in policy so that's also ok.

Hello, I just found solution. It was in group mapping settings. User Domain was missing above Group Objects.

 

Thank you all for help. You put me to right direction!

 

br

Toni

  • 1 accepted solution
  • 6154 Views
  • 12 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!