We've run into a problem which I understand, I'm just not sure how to fix. A user on her laptop logs into the domain while her laptop is docked, so UIA has her ip address mapping to the wired connection. Later, she undocks and flips over to wireless, but UIA no longer has a valid mapping for her since she AD still associates her wired IP address with her ID. Once she redocks and starts accessing again with her wired IP, the original mapping is valid again and she is properly identified.
Has anyone encountered this and come up with a good resolution?
the solution is to have your WLC or RADIUS server or whathaveyou to send syslog messages to the PA/UID Agent to map usernames with IPs
@bradk14 is right. I've had this same problem in my environment as well ( https://live.paloaltonetworks.com/t5/General-Topics/Dual-NIC-IP-Mapping-Issue/m-p/5936#M4320 )
I opened a ticket with Microsoft and never could get to the bottom of it...Basically you're at the mercy of the randomness of the Windows OS and what NIC is used when authenticating to the DC.
So really you've got 3 options.
First (probably Palo "recommended") - Use global protect client. While not necessarily ideal for everyone's environment (adding another client to an image) it provides 100% accountability.
Second - Do as Brad suggests and try adding the log source to your user ID environment. This too might be overly burdensome especially if you have a lot of authentication sources.
Third - Leverage Captive Portal and hope for the best
Unfortunately your "cleanest" and most reliable solution will be GP.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!