- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
06-29-2016 01:33 AM
Hi guys,
Has anyone managed to successfully have their VM-100/Palo recognise the SNMP authentication requests from the Cisco LAN Controller to use for User-ID?
I have followed the below document but to no avail.
This is an example of a syslog message that I'm using to put in the "Syslog Parse Profile", as described in the document.
2016-06-27 08:45:09 User.Debug wlc.vallsnet.local community=ajvrw, enterprise=1.3.6.1.4.1.9.9.599.0.4, uptime=715326600, agent_ip=10.65.100.5, version=Ver2, 1.3.6.1.4.1.9.9.599.1.3.1.1.1.0=T@'3—, 1.3.6.1.4.1.9.9.513.1.1.1.1.5.0=AP7_c067.afe4.0ae7, 1.3.6.1.4.1.9.9.599.1.3.1.1.8.0=4Ûý¬[`, 1.3.6.1.4.1.9.9.513.1.2.1.1.1.0=0, 1.3.6.1.4.1.9.9.599.1.3.1.1.10.0=10.40.99.29, 1.3.6.1.4.1.9.9.599.1.3.1.1.27.0=jespejo, 1.3.6.1.4.1.9.9.599.1.3.1.1.28.0=DADAAJV
In this case user id is = jespejo and ip address is =10.40.99.29, this ip address is assigned by dhcp.
Has anyone tried setting this up?
Kind regards
Jack
06-29-2016 03:03 AM
Solved***
Address prefix was entered incorrectly. The below value was needed to be in place:
1.3.6.1.4.1.9.9.599.1.3.1.1.10.0=
06-29-2016 06:36 AM
you can grab user-ip mapping secussfully? in my case, I can see PA has received log messages, but number of auth. success messages keeps none. I can not see your uploaded pic, my syslog parse profile as following,
Event String enterprise=1.3.6.1.4.1.9.9.599.0.4
Username Prefix 1.3.6.1.4.1.9.9.599.1.3.1.1.27.0=
Username Delimiter ,\s
Address Prefix 1.3.6.1.4.1.9.9.599.1.3.1.1.10.0=
Address Delimiter ,\s
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!