User-Id Agent and "login id attribute name"

Reply
Highlighted
Not applicable

User-Id Agent and "login id attribute name"

Hi

In one of my customers (Pan-OS v4.0.7) with eDirectory I use User-Id Agent (v3.1.2) to get user IP addresses. In that directory I used the "Login Id Attribute Name" to specify 'CN' as the attribute to use for user account because many users didn't have a "UniqueId" attribute with a value.

Now I am testing the latest version of User-Id Agent (v4.1.4) and to my susprise I cannot specify the attribute for the user name.

Is there any way to specify in User-Id Agent to use the 'CN' attribute?

What attribute does it use by default? 'UniqueID'?

Regards

Emilio

L5 Sessionator

Emilio,

The latest version of agent does not support group mapping. The group mapping is done by the firewall. You can configure the group mapping under Device -> User Identification -> Group Mapping Settings. You can configure the login attribute here.

Capture.JPG

Thanks,

Sri

Highlighted
Not applicable

Thanks Sri

However in the User-Id Agent not all connected users are shown and after testing a few ones I notice users without 'uid' attribute are not shown. In previous versions of the agent 'uid' was the default and I changed it but now I cannot specify what attribute to use.

I think the agent still uses the 'uid' attribute and if the user hasn't got a value for it the user is not shown. Product documentations doesn't say anything about this. Am I right? Is this a bug or expected behaviour?

Thanks

Emilio

Highlighted
L4 Transporter

User-ID Agent v4.1 and later

  • User-ID Agent v4.1 pulls only the user-ip-mappings and therefore the Login ID Attribute Name is no longer configured on the User-ID Agent.  It is configured on the PAN box. When creating an authentication profile for LDAP auth, the device can use an LDAP server to pull the user-group mapping info.
Highlighted
Not applicable

Hi

I understand what you mean but my problem is that the agent is only showing a small amount of connected users IP's. There are many users connected whose ip address is not shown by the agent in the monitor tab.

I also suggested that maybe ldap 'person' objects whithout an 'uid' attribute are not correctly shown by the agent when connected.

Regards

Emilio Maneiro

Highlighted
L2 Linker

Hi Emilio,

   I am having the same issue of yours : some users are not identified by the agent.

I am using  agent 4.1.6 and edirectory 8.8

What I noticed from edirectory is the uid attributes was missing from some users.

Once added the user was successfully added in the user agent list.

Regards.

Walter Doria (wdoria@exclusive-networks.com)

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!