<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID PanOS 4.1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16849#M12278</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In regard to user identification of traffic, older implementations of PAN we would install the PAN-Agent, but after reading a bit more on the 4.1 it seems I would no longer need to use the agent in an Active Directory installation. &lt;/P&gt;&lt;P&gt;Is there any documentation on how to do this for multiple DCs in multiple domains?&amp;nbsp; We are in the midst of a domain transition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the agent is still required for 4.1 installations?&amp;nbsp; If so what premissions are needed on the member server, user, and domain controllers for it to work?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the agent is not required are there any limitations to the number of DCs that can be added to the groups?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I also use the new way of doing profiles to allow usernames to have certain levels of administration of the appliance itself?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Mar 2012 16:27:03 GMT</pubDate>
    <dc:creator>u10723</dc:creator>
    <dc:date>2012-03-02T16:27:03Z</dc:date>
    <item>
      <title>User-ID PanOS 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16849#M12278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In regard to user identification of traffic, older implementations of PAN we would install the PAN-Agent, but after reading a bit more on the 4.1 it seems I would no longer need to use the agent in an Active Directory installation. &lt;/P&gt;&lt;P&gt;Is there any documentation on how to do this for multiple DCs in multiple domains?&amp;nbsp; We are in the midst of a domain transition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the agent is still required for 4.1 installations?&amp;nbsp; If so what premissions are needed on the member server, user, and domain controllers for it to work?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the agent is not required are there any limitations to the number of DCs that can be added to the groups?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I also use the new way of doing profiles to allow usernames to have certain levels of administration of the appliance itself?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2012 16:27:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16849#M12278</guid>
      <dc:creator>u10723</dc:creator>
      <dc:date>2012-03-02T16:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID PanOS 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16850#M12279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I hope this document will assist you in your upgrade to new user id agent 4.1.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2021" data-containertype="14" data-objectid="3120" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3120" style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #316989; background-color: #ffffff;"&gt;https://live.paloaltonetworks.com/docs/DOC-3120&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Tx,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2012 23:07:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16850#M12279</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-03-02T23:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID PanOS 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16851#M12280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In 4.1 you still need the user-id agent to be installed on the AD server. This user-id agent should be provided with the adminstrator username and password for retrieving the info from the windows security logs. It same as it was in panagent. the only major difference is that for grouping of users, you have to create ldap server profiles which is not necessary in panagent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2012 23:16:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16851#M12280</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-03-02T23:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID PanOS 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16852#M12281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any idea on what user premissions are required to read exchange logs?&amp;nbsp; I have added the user to the Event Log Readers group and can connect/poll from the Domain Controller, but not from Exchange.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Mar 2012 16:28:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16852#M12281</guid>
      <dc:creator>u10723</dc:creator>
      <dc:date>2012-03-03T16:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID PanOS 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16853#M12282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The login credentials should have the Admin rights to read and write the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know if you have any more questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Khubaib &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 00:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16853#M12282</guid>
      <dc:creator>kalavi</dc:creator>
      <dc:date>2012-03-06T00:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID PanOS 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16854#M12283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you know the admin rights name or group?&amp;nbsp; I can't give this service domain administrator rights as for security purposes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 15:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16854#M12283</guid>
      <dc:creator>u10723</dc:creator>
      <dc:date>2012-03-06T15:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID PanOS 4.1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16855#M12284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can grant another user admin rights to READ only&lt;/P&gt;&lt;P&gt;You may want to review documents on the MS knowledge base e.g.&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.microsoft.com/kb/323076"&gt;http://support.microsoft.com/kb/323076&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As this is a setting on the Active Directory so best that you contact MS Support for how to create and grant READ ONLY access to user/admin accounts.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2012 15:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-panos-4-1/m-p/16855#M12284</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2012-03-13T15:31:03Z</dc:date>
    </item>
  </channel>
</rss>

