Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

VM-100 Not recognizing users from Cisco Wireless Lan Controller

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

VM-100 Not recognizing users from Cisco Wireless Lan Controller

L3 Networker

Hi guys,

 

Has anyone managed to successfully have their VM-100/Palo recognise the SNMP authentication requests from the Cisco LAN Controller to use for User-ID?

 

I have followed the below document but to no avail. 

 

https://live.paloaltonetworks.com/t5/Integration-Articles/Use-Syslog-Receiver-to-Integrate-with-Cisc...

 

This is an example of a syslog message that I'm using to put in the "Syslog Parse Profile", as described in the document.

 

2016-06-27 08:45:09       User.Debug       wlc.vallsnet.local             community=ajvrw, enterprise=1.3.6.1.4.1.9.9.599.0.4, uptime=715326600, agent_ip=10.65.100.5, version=Ver2, 1.3.6.1.4.1.9.9.599.1.3.1.1.1.0=T@­'3—, 1.3.6.1.4.1.9.9.513.1.1.1.1.5.0=AP7_c067.afe4.0ae7, 1.3.6.1.4.1.9.9.599.1.3.1.1.8.0=4Ûý¬[`, 1.3.6.1.4.1.9.9.513.1.2.1.1.1.0=0, 1.3.6.1.4.1.9.9.599.1.3.1.1.10.0=10.40.99.29, 1.3.6.1.4.1.9.9.599.1.3.1.1.27.0=jespejo, 1.3.6.1.4.1.9.9.599.1.3.1.1.28.0=DADAAJV
 

 

In this case user id is = jespejo and ip address is =10.40.99.29, this ip address is assigned by dhcp. 

 

 

Has anyone tried setting this up?

 

Kind regards
Jack

 

3 REPLIES 3

L3 Networker

Solved***

 

Address prefix was entered incorrectly. The below value was needed to be in place:

 

1.3.6.1.4.1.9.9.599.1.3.1.1.10.0=

 

 

L1 Bithead

you can grab user-ip mapping secussfully?  in my case, I can see PA has received log messages, but number of auth. success messages keeps none. I can not see your uploaded pic, my syslog parse profile as following,

 

Event String                enterprise=1.3.6.1.4.1.9.9.599.0.4

Username Prefix        1.3.6.1.4.1.9.9.599.1.3.1.1.27.0=

Username Delimiter   ,\s

Address Prefix            1.3.6.1.4.1.9.9.599.1.3.1.1.10.0=

Address Delimiter      ,\s

L1 Bithead

Does anyone have similar experience ?

  • 2287 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!