<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practices for Agentless UserID in Multiple Domain Environment? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-agentless-userid-in-multiple-domain/m-p/15841#M11569</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if without trust relationship between different domain you should switch to use one user-id agent install on each domain &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Jan 2014 17:20:23 GMT</pubDate>
    <dc:creator>Gregoux</dc:creator>
    <dc:date>2014-01-20T17:20:23Z</dc:date>
    <item>
      <title>Best Practices for Agentless UserID in Multiple Domain Environment?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-agentless-userid-in-multiple-domain/m-p/15838#M11566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm about to install two PA5060s in high availability and I am wondering if you guys have any best practice tips for this kind of install when it comes to UserID and how to add more than one domain to the Agentless install.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;EM&gt;(Now shamelessly accepting the next 72 friend requests.)&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2013 14:41:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-agentless-userid-in-multiple-domain/m-p/15838#M11566</guid>
      <dc:creator>Abs</dc:creator>
      <dc:date>2013-03-05T14:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Agentless UserID in Multiple Domain Environment?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-agentless-userid-in-multiple-domain/m-p/15839#M11567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no Best Practice, due to the many different ways that networks are designed these days. The one item to consider is the service account that is used for the WMI Authentication on the Domain controllers you specify in the Server Monitoring section. This account will need to be a member of the Distributed COM Users, Server Operators, and Event Log Readers groups, as well as have correct CIMV2 security properties on each AD server the firewall connects to. In a multiple domain environment, this can be achieved by adding the service account to the Enterprise Admins group (if in the same forest) or by adding the user to each required group in each domain and ensuring the proper trust is in place. Please see &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4332"&gt;How to Configure Agentless User-ID in PAN-OS 5.0.x &lt;/A&gt; for assistance configuring the Agentless User-ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2013 17:30:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-agentless-userid-in-multiple-domain/m-p/15839#M11567</guid>
      <dc:creator>bnelson</dc:creator>
      <dc:date>2013-03-05T17:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Agentless UserID in Multiple Domain Environment?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-agentless-userid-in-multiple-domain/m-p/15840#M11568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to hear, I figured in the end it would come down to service account permissions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 17:05:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-agentless-userid-in-multiple-domain/m-p/15840#M11568</guid>
      <dc:creator>bnelson</dc:creator>
      <dc:date>2013-03-06T17:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Agentless UserID in Multiple Domain Environment?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-agentless-userid-in-multiple-domain/m-p/15841#M11569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if without trust relationship between different domain you should switch to use one user-id agent install on each domain &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jan 2014 17:20:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-agentless-userid-in-multiple-domain/m-p/15841#M11569</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-01-20T17:20:23Z</dc:date>
    </item>
  </channel>
</rss>

