<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User ID firewall integration with mapping server or AD in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-firewall-integration-with-mapping-server-or-ad/m-p/523101#M640</link>
    <description>&lt;P&gt;Have to enable User-ID for corporates users. Not able to locate documentation around best practices for user id. for&amp;nbsp; example in my scenario.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have one domain xyz.com with 50 domain controllers to monitor. we have winRM installed on all the domain controllers. So we will be considering doing agentless user id integration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my questions are following.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; Can firewall PA 5250 integrate directly with active directory server using LDAP and capable of monitoring 50 domain controllers using winRM?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; Should we consider having user mapping server which will be integrating with AD server using LDAP and firewall will just monitor 2 user mapping servers (primary &amp;amp; secondary)?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; what are the issue that we may experience with any of the setup in operations?&lt;/P&gt;
&lt;P&gt;&amp;gt; what are other best alternative we can explore?&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2022 04:18:05 GMT</pubDate>
    <dc:creator>Sukhmeet</dc:creator>
    <dc:date>2022-12-02T04:18:05Z</dc:date>
    <item>
      <title>User ID firewall integration with mapping server or AD</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-firewall-integration-with-mapping-server-or-ad/m-p/523101#M640</link>
      <description>&lt;P&gt;Have to enable User-ID for corporates users. Not able to locate documentation around best practices for user id. for&amp;nbsp; example in my scenario.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have one domain xyz.com with 50 domain controllers to monitor. we have winRM installed on all the domain controllers. So we will be considering doing agentless user id integration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my questions are following.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; Can firewall PA 5250 integrate directly with active directory server using LDAP and capable of monitoring 50 domain controllers using winRM?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; Should we consider having user mapping server which will be integrating with AD server using LDAP and firewall will just monitor 2 user mapping servers (primary &amp;amp; secondary)?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; what are the issue that we may experience with any of the setup in operations?&lt;/P&gt;
&lt;P&gt;&amp;gt; what are other best alternative we can explore?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 04:18:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-firewall-integration-with-mapping-server-or-ad/m-p/523101#M640</guid>
      <dc:creator>Sukhmeet</dc:creator>
      <dc:date>2022-12-02T04:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: User ID firewall integration with mapping server or AD</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-firewall-integration-with-mapping-server-or-ad/m-p/523357#M647</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/207164"&gt;@Sukhmeet&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out these links to help you make a better decision.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpICAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpICAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/dotw-windows-based-uid-agent-vs-agentless-uid/ba-p/498217" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/dotw-windows-based-uid-agent-vs-agentless-uid/ba-p/498217&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/dotw-windows-based-uid-agent-vs-agentless-uid/ba-p/498217#:~:text=If%20the%20firewall%20is%20already%20heavily%20loaded%20and%20you%20have%20a%20lot%20of%20DCs%20to%20query%2C%20then%20agentless%20UID%20might%20not%20be%20the%20ideal%20solution.%20In%20this%20case%2C%20using%20a%20user%2DID%20agent%20will%20offload%20some%20processing%20from%20the%20firewall" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/dotw-windows-based-uid-agent-vs-agentless-uid/ba-p/498217#:~:text=If%20the%20firewall%20is%20already%20heavily%20loaded%20and%20you%20have%20a%20lot%20of%20DCs%20to%20query%2C%20then%20agentless%20UID%20might%20not%20be%20the%20ideal%20solution.%20In%20this%20case%2C%20using%20a%20user%2DID%20agent%20will%20offload%20some%20processing%20from%20the%20firewall&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2022 01:18:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-firewall-integration-with-mapping-server-or-ad/m-p/523357#M647</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-12-06T01:18:10Z</dc:date>
    </item>
  </channel>
</rss>

