cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Cyber Elite
Cyber Elite

my first guess would be that you have probing enabled on the user-id agent.

 

if the firewall receives a connection from an IP in a user-id enabled zone for which there is no mapping, it will query the user-id agent

if the agent has no mapping and probing is enabled, it will poll the machine for the 'logged in' credentials and feed those to the firewall if the machine replies

 

this seems the most likely reason why you're seeing a username you don't have in your ID (its what the machine tells the probe)

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

Who rated this post