User-ID

cancel
Showing results for 
Search instead for 
Did you mean: 

User-ID

L4 Transporter

When enabling user-id where does it check against to get the information to identify  the users? I have it turned on for serveral zones and it only seems to work on the VPN user-id's.

42 REPLIES 42

Hello,

Also check to make sure that the User-ID is enabled on the zone. Its burned me a few times over the years.

 

image.png

 

Cheers!

@MickBall

 

Yes i got the one you sent thanks

@kiwi

Do you have to have a certain version of the userid agent for different OS's of the PA? I don't want to have to upgrage the agents every other month unless it does it automagically

No, i have used same agent for all 7.x versions, only had to upgrade when moved to v8. As requires a device cert.

 

however v8 had other issues so rolled back to v7 and original agent.

 

we have 2 agents so upgrading (if required) can be pretty seemless.

@MickBall

 

good to know thanks for the info

@OtakarKlier

 

Yes it is enabled on the zones but apparently I don't have everything it needs set up because its still not working. I can see how that would be annoying LOL 😉

I see that there is a userid agent method and a clientless userid method. What are people using the most? I know that the clientless method will cause more load on my firewall but i am not sure how to gage how much it will add. Also we do mostly LDAP on a unbuntu box all I saw was what looked like one compatible with active directory and window

@MickBall

I have read over this a couple times and this is no small udertaking, we have a mix of authentication methods active directory, ad-ldap, open ldap and radius. I may try puttin the agent on the AD domain controller and see how much info I get from that. Unfortunately alot of the users are not a part of our domain since they are college student and connect using their own devices

@jdprovine,

Do you seperate your students into a 'student' VLAN? It's possible to simply include IP ranges that you would actually expect to see the user-id information, and you could simply ignore your student BYOD devices. 

@BPry

Yes we do separate them into their own vlans as well as a separate zone on the PA.  A majority of our students use wireless for everything and we authenticate against radius to let them on the wireless(we have more than one wireless). Is it possible to get userid information from Radius? 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!