<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: best practice User-ID strategy? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14036#M10308</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently we have 20 User-ID agents connected to our PA-2050. In the last days we had severe problems with our Palo Alto. The CPU was on full load and we were not able to login on CLI or the webinterface. The only solution was to restart the firewall. A few weeks ago we had the same problems but not as many as these days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure but something tells me that the integration of the User-ID agents is the cause of our problems. Is this possible? &lt;/P&gt;&lt;P&gt;&lt;IMG alt="screen.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10131_screen.png" style="width: 620px; height: 287px;" /&gt;&lt;/P&gt;&lt;P&gt;The useridd process consumes a lot of memory. Is this normal?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Dec 2013 07:11:06 GMT</pubDate>
    <dc:creator>LCMember17002</dc:creator>
    <dc:date>2013-12-04T07:11:06Z</dc:date>
    <item>
      <title>best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14033#M10305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;first I try to give you some information. Our headquarter is located in Germany. All of our subsidiaries are connected to Germany via relatively slow VPN lines. Overall we have round about 20 DCs in different countires. Until now we have only 3 Palo Alto firewalls (Germany, USA, Canada) but in the future we plan to buy more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our setup until last week was the following. We installed the software User-ID agent on the DC in Germany. We connected all DCs worldwide to this agent. Unfortunately the agent retrieves all logs and produces a lot of traffic over the VPN lines. So we decided to change our setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are planning to install the User-ID agent on all DCs worldwide and connect the firewall in Germany with all agents. With this solution the traffic should drop significantely. Furthermore the firewall in USA and Canada will be connected with the particular DC in that country and in Germany.&lt;/P&gt;&lt;P&gt;Or is it better to connect these firewalls also with all agents?&lt;/P&gt;&lt;P&gt;Is it possible to distribute the mappings from the firewall in Germany to the other firewalls without the need of connecting agents to the firewalls in USA and Canada?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another question is if all agents should observe all available networks or only the local subnets?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you can help me!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 10:12:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14033#M10305</guid>
      <dc:creator>LCMember17002</dc:creator>
      <dc:date>2013-11-08T10:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14034#M10306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"We are planning to install the User-ID agent on all DCs worldwide and connect the firewall in Germany with all agents. With this solution the traffic should drop significantely."&lt;/P&gt;&lt;P&gt;Yes this will be fine.Also in the agents you may change 1second predefined read logs to 2(or 3) seconds.&lt;/P&gt;&lt;P&gt;Redistribute users is only available for agentless user-id.&lt;/P&gt;&lt;P&gt;to observer all available networks will be fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Nov 2013 19:02:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14034#M10306</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-11-10T19:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14035#M10307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are few good docs regarding the deployment of User id. &lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3120"&gt;https://live.paloaltonetworks.com/docs/DOC-3120&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-5939"&gt;https://live.paloaltonetworks.com/docs/DOC-5939&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 00:37:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14035#M10307</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-11-12T00:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14036#M10308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently we have 20 User-ID agents connected to our PA-2050. In the last days we had severe problems with our Palo Alto. The CPU was on full load and we were not able to login on CLI or the webinterface. The only solution was to restart the firewall. A few weeks ago we had the same problems but not as many as these days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure but something tells me that the integration of the User-ID agents is the cause of our problems. Is this possible? &lt;/P&gt;&lt;P&gt;&lt;IMG alt="screen.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10131_screen.png" style="width: 620px; height: 287px;" /&gt;&lt;/P&gt;&lt;P&gt;The useridd process consumes a lot of memory. Is this normal?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 07:11:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14036#M10308</guid>
      <dc:creator>LCMember17002</dc:creator>
      <dc:date>2013-12-04T07:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14037#M10309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What PANOS and User ID Agent version are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Dec 2013 16:41:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14037#M10309</guid>
      <dc:creator>JimS2</dc:creator>
      <dc:date>2013-12-14T16:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14038#M10310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All the latest. PANOS 5.09 and User-ID Agent 5.0.6-6.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Dec 2013 16:25:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14038#M10310</guid>
      <dc:creator>LCMember17002</dc:creator>
      <dc:date>2013-12-22T16:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14039#M10311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The memory and cpu usage in the screen shot is not all that high.&amp;nbsp; I would be more interested in the memory and cpu usage on the mgmtsrvr and devsrvr.&lt;/P&gt;&lt;P&gt;Run: show system resources follow&lt;/P&gt;&lt;P&gt;Use Shift + m&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Dec 2013 17:51:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14039#M10311</guid>
      <dc:creator>JimS2</dc:creator>
      <dc:date>2013-12-22T17:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14040#M10312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How many User-ID Agents can usally be connected to a PA-2050 without problems?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here another screenshot mit Shift + M.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Unbenannt.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10453_Unbenannt.png" style="width: 620px; height: 424px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Dec 2013 07:51:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14040#M10312</guid>
      <dc:creator>LCMember17002</dc:creator>
      <dc:date>2013-12-23T07:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14041#M10313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN class="j-post-author" style="font-size: 0.9em; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="12205" data-username="admin%40peri" href="https://live.paloaltonetworks.com/people/admin@peri" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;admin@peri&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Per PanOS 4.1 and 5.0, 2050 supports 100 User ID agents.&lt;/P&gt;&lt;P&gt;Though it can support so many agents I would suggest the efficiency of the hardware with user id agents depends on the frequency of the data being retrieved from the agents to the firewall and how much data is being obtained. To some extent we can change the frequency values on the user id agents to retrieve user-ip mapping. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this answers your question !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Dec 2013 16:07:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14041#M10313</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-12-23T16:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14042#M10314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The mgmtsrvr server memory is border line but not extreme by any means.&amp;nbsp; I would open a support case for the performance issue when it occurs again.&amp;nbsp; This will need to be diagnosed live by a technician.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Dec 2013 18:14:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14042#M10314</guid>
      <dc:creator>JimS2</dc:creator>
      <dc:date>2013-12-23T18:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: best practice User-ID strategy?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14043#M10315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello admin@peri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally only local subnet.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because User based policies are normally configured inside to outside direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if User based policy is configured for outside to inside network then its required to learn all the networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that answers the question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Dec 2013 00:14:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practice-user-id-strategy/m-p/14043#M10315</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2013-12-26T00:14:01Z</dc:date>
    </item>
  </channel>
</rss>

