<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UaService (PA User Agent) consuming 50% of bandwith capacity in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15488#M11360</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amount of bandwidth needed depends on how many clients you have, how active they are and how much bandwidth you can spare on your WAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PAN-agent is tailing the security log of the DC's its configured to follow which with many users doing all sorts of thing in your network will be chatty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your case if WAN is an issue you should install PAN-agent on a dedicated server sitting in the same switch as your remote DC, or even better - install the PAN-agent straight on the DC itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then when you configure it you configure it to only tail the security log from localhost (the DC server PAN-agent is installed on) and as an optimization limit client ip's to the ranges which this DC will handle (depending on how your DC structure is setup - DC as in Domain Controller in this case).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For better hitrate you can configure PAN-agent to query clients using WMI (will use just slightly more bandwidth but should be far less than tailing security logs over the network).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then in your PA you configure your PA to query each PAN-agent which should be far less traffic than before (because PA caches the results and the stuff the PAN-agent sends to PA is just user/ip mappings).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Nov 2012 08:54:44 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-11-14T08:54:44Z</dc:date>
    <item>
      <title>UaService (PA User Agent) consuming 50% of bandwith capacity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15486#M11358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we have since a couple of weeks detected an issue with our network bandwith which looked to be caused by domain controllers.&amp;nbsp; if we looked further into detail the domaincontrollers were replicating CIFS at a speed of approx 200kbs/400kbs&amp;nbsp; (which is about 50% of our 2Mbit lines which we have between our plants).&amp;nbsp; Notice that we have the next setup:&lt;/P&gt;&lt;P&gt;each of our factories is equiped with 2 stand-alone domain controllers +&amp;nbsp; 1 virtual domain controller in our central datacenter (most plants have a 2Mbit connection to our central datacenter).&amp;nbsp; and the PA user agent in our central datacenter looks to be constantly replicating data with the PA user agents (or DC's) in our remote plants.&lt;/P&gt;&lt;P&gt;if i take a closer look with Process Monitor, the UAService.exe is constantly "reading" data from &lt;A href="https://live.paloaltonetworks.com/"&gt;\\&amp;lt;serverip&amp;gt;\PIPE\EVENTVIEWER&lt;/A&gt; which looks to cause the massive traffic on our network. at the moment between 30% and 50% of our total WAN network capacity looks to be "eaten" by the PA user agent.&lt;/P&gt;&lt;P&gt;is there anything we can change in the configuration to redruce this traffic?&amp;nbsp; below you can see a part of the user agent XML file which contains the timeouts and session details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV style="text-indent: -2em; margin-left: 1em;"&gt;&lt;SPAN class="b"&gt; &lt;/SPAN&gt; &lt;SPAN class="m"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;server-monitor&lt;/SPAN&gt; &lt;SPAN class="t"&gt;security-log-enabled&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt; security-log-interval&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;3&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt; session-enabled&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;0&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt; session-interval&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;10&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt; edir-interval&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;30&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="m"&gt; /&amp;gt;&lt;/SPAN&gt; &lt;/DIV&gt;&lt;DIV style="text-indent: -2em; margin-left: 1em;"&gt;&lt;SPAN class="b"&gt; &lt;/SPAN&gt; &lt;SPAN class="m"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;probing&lt;/SPAN&gt; &lt;SPAN class="t"&gt;wmi-enabled&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;0&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt; netbios-enabled&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;0&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt; interval&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;20&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt; init-retry-delay&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;3&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="m"&gt; /&amp;gt;&lt;/SPAN&gt; &lt;/DIV&gt;&lt;DIV style="text-indent: -2em; margin-left: 1em;"&gt;&lt;SPAN class="b"&gt; &lt;/SPAN&gt; &lt;SPAN class="m"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;timeout&lt;/SPAN&gt; &lt;SPAN class="t"&gt;enabled&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt; entry-timeout&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;720&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="m"&gt; /&amp;gt;&lt;/SPAN&gt; &lt;/DIV&gt;&lt;DIV style="text-indent: -2em; margin-left: 1em;"&gt;&lt;SPAN class="b"&gt; &lt;/SPAN&gt; &lt;SPAN class="m"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;listening-port&lt;/SPAN&gt;&lt;SPAN class="m"&gt;&amp;gt;&lt;/SPAN&gt;&lt;SPAN class="tx"&gt;5007&lt;/SPAN&gt;&lt;SPAN class="m"&gt;&amp;lt;/&lt;/SPAN&gt;&lt;SPAN class="t"&gt;listening-port&lt;/SPAN&gt;&lt;SPAN class="m"&gt;&amp;gt;&lt;/SPAN&gt; &lt;/DIV&gt;&lt;DIV style="text-indent: -2em; margin-left: 1em;"&gt;&lt;SPAN class="b"&gt; &lt;/SPAN&gt; &lt;SPAN class="m"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;xml-api&lt;/SPAN&gt; &lt;SPAN class="t"&gt;enabled&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;0&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt; xml-api-port&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;5006&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="m"&gt; /&amp;gt;&lt;/SPAN&gt; &lt;/DIV&gt;&lt;DIV style="text-indent: -2em; margin-left: 1em;"&gt;&lt;SPAN class="b"&gt; &lt;/SPAN&gt; &lt;SPAN class="m"&gt;&amp;lt;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;ip-cache&lt;/SPAN&gt; &lt;SPAN class="t"&gt;enabled&lt;/SPAN&gt;&lt;SPAN class="m"&gt;="&lt;/SPAN&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;SPAN class="m"&gt;"&lt;/SPAN&gt;&lt;SPAN class="m"&gt; /&amp;gt;&lt;/SPAN&gt; &lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 15:37:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15486#M11358</guid>
      <dc:creator>moorken</dc:creator>
      <dc:date>2012-11-13T15:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: UaService (PA User Agent) consuming 50% of bandwith capacity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15487#M11359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;found a topic with the same issue: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/15709"&gt;https://live.paloaltonetworks.com/message/15709&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however i'm still wondering what the best setup in our case would be.&amp;nbsp; Do we need to keep the PA user agents at the remote sites and disable one of the 2 agents, or will the best solution be to only keep the user agent in our central data center and let it communicate with the domaincontrollers in the remote site?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2012 07:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15487#M11359</guid>
      <dc:creator>moorken</dc:creator>
      <dc:date>2012-11-14T07:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: UaService (PA User Agent) consuming 50% of bandwith capacity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15488#M11360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amount of bandwidth needed depends on how many clients you have, how active they are and how much bandwidth you can spare on your WAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PAN-agent is tailing the security log of the DC's its configured to follow which with many users doing all sorts of thing in your network will be chatty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your case if WAN is an issue you should install PAN-agent on a dedicated server sitting in the same switch as your remote DC, or even better - install the PAN-agent straight on the DC itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then when you configure it you configure it to only tail the security log from localhost (the DC server PAN-agent is installed on) and as an optimization limit client ip's to the ranges which this DC will handle (depending on how your DC structure is setup - DC as in Domain Controller in this case).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For better hitrate you can configure PAN-agent to query clients using WMI (will use just slightly more bandwidth but should be far less than tailing security logs over the network).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then in your PA you configure your PA to query each PAN-agent which should be far less traffic than before (because PA caches the results and the stuff the PAN-agent sends to PA is just user/ip mappings).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2012 08:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15488#M11360</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-14T08:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: UaService (PA User Agent) consuming 50% of bandwith capacity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15489#M11361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should probably start to increase the timer "&lt;SPAN class="t" style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; text-indent: -24px; background-color: #ffffff;"&gt;security-log-interval" with a higher value. 30 seconds or more...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t" style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; text-indent: -24px; background-color: #ffffff;"&gt;That's the interval &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;PAN-agent is tailing the security log of the DC&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2012 09:10:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15489#M11361</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-11-14T09:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: UaService (PA User Agent) consuming 50% of bandwith capacity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15490#M11362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks both,&amp;nbsp; we have switched off both the virtual DC and one of the 2 local DCs and this seems to have decreased the traffic in one direction by almost 100% and in the other direction by 75%!&amp;nbsp;&amp;nbsp; We have been thinking over reducing the security-log-internal already but weren't sure yet about how far we could go before this would result in issues.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2012 09:43:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15490#M11362</guid>
      <dc:creator>moorken</dc:creator>
      <dc:date>2012-11-14T09:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: UaService (PA User Agent) consuming 50% of bandwith capacity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15491#M11363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont think that should matter that much bandwidth wise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless the PAN-agent copy the whole security log each time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully it can use some kind of pointer regarding from which row or time it want to read the log which would give that either you download (as example) 1 megabyte each minute or 16.7 kbyte (1/60) each second (if we compare setting this value to read each 60 seconds vs each 1 second).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Nov 2012 09:48:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uaservice-pa-user-agent-consuming-50-of-bandwith-capacity/m-p/15491#M11363</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-14T09:48:46Z</dc:date>
    </item>
  </channel>
</rss>

