User-Id Agent and "login id attribute name"

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

User-Id Agent and "login id attribute name"

Not applicable

Hi

In one of my customers (Pan-OS v4.0.7) with eDirectory I use User-Id Agent (v3.1.2) to get user IP addresses. In that directory I used the "Login Id Attribute Name" to specify 'CN' as the attribute to use for user account because many users didn't have a "UniqueId" attribute with a value.

Now I am testing the latest version of User-Id Agent (v4.1.4) and to my susprise I cannot specify the attribute for the user name.

Is there any way to specify in User-Id Agent to use the 'CN' attribute?

What attribute does it use by default? 'UniqueID'?

Regards

Emilio

5 REPLIES 5

L5 Sessionator

Emilio,

The latest version of agent does not support group mapping. The group mapping is done by the firewall. You can configure the group mapping under Device -> User Identification -> Group Mapping Settings. You can configure the login attribute here.

Capture.JPG

Thanks,

Sri

Thanks Sri

However in the User-Id Agent not all connected users are shown and after testing a few ones I notice users without 'uid' attribute are not shown. In previous versions of the agent 'uid' was the default and I changed it but now I cannot specify what attribute to use.

I think the agent still uses the 'uid' attribute and if the user hasn't got a value for it the user is not shown. Product documentations doesn't say anything about this. Am I right? Is this a bug or expected behaviour?

Thanks

Emilio

L4 Transporter

User-ID Agent v4.1 and later

  • User-ID Agent v4.1 pulls only the user-ip-mappings and therefore the Login ID Attribute Name is no longer configured on the User-ID Agent.  It is configured on the PAN box. When creating an authentication profile for LDAP auth, the device can use an LDAP server to pull the user-group mapping info.

Hi

I understand what you mean but my problem is that the agent is only showing a small amount of connected users IP's. There are many users connected whose ip address is not shown by the agent in the monitor tab.

I also suggested that maybe ldap 'person' objects whithout an 'uid' attribute are not correctly shown by the agent when connected.

Regards

Emilio Maneiro

Hi Emilio,

   I am having the same issue of yours : some users are not identified by the agent.

I am using  agent 4.1.6 and edirectory 8.8

What I noticed from edirectory is the uid attributes was missing from some users.

Once added the user was successfully added in the user agent list.

Regards.

Walter Doria (wdoria@exclusive-networks.com)

  • 3206 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!