<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agentless User-ID with PAN5.x - AD Configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27804#M20272</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No one from Palo Alto yet.&amp;nbsp; I will work on rounding someone up.&amp;nbsp; What I have been told is. . . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;USER-ID Update&lt;/P&gt;&lt;P class="p1"&gt;It is no longer necessary to use windows machine for one AD server&lt;/P&gt;&lt;P class="p1"&gt;It is best practice to setup filters to only enumerate groups that will be used in a policy - groups are ONLY used to create policy.&lt;/P&gt;&lt;P class="p1"&gt;The (windows) agent can still be used to check in with multiple AD servers.&amp;nbsp; As you probably know, it looks for kerberos tickets and also polls via Netbios or WMI to see if anyone has moved.&lt;/P&gt;&lt;P class="p1"&gt;Also, it is suggested to use agent if you don't want to use the control plane of the firewall for additional processing.&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;Hope that helps a little for now. . .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Feb 2013 12:58:18 GMT</pubDate>
    <dc:creator>cindyb</dc:creator>
    <dc:date>2013-02-28T12:58:18Z</dc:date>
    <item>
      <title>Agentless User-ID with PAN5.x - AD Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27798#M20266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have read the tech article "&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;How to Configure Agentless User-ID in PAN- OS 5.0.x"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd love to see this document broken into two docs - one that I can send out to customers to prepare for POC - the AD user account setup portion without the PAN firewall config portion . . . does this already exist somewhere?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Feb 2013 17:41:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27798#M20266</guid>
      <dc:creator>cindyb</dc:creator>
      <dc:date>2013-02-26T17:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID with PAN5.x - AD Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27799#M20267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While on the subject: May have been asked before, but what are the advantages/disadvantages of going agentless vs with agent.&lt;/P&gt;&lt;P&gt;How do they compare in terms of reliability (user to ip mapping integrity), performance ?&lt;/P&gt;&lt;P&gt;What does PA recommend ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 13:55:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27799#M20267</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-02-27T13:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID with PAN5.x - AD Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27800#M20268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At the Ignite conference they talked about the fact that they were able to make the agentless User-ID process very efficient.&amp;nbsp; Apparently the process is much faster at identifying when a new domain user, or exchange user, logs in.&amp;nbsp; I suppose it would be handy to have one less piece in the puzzle as well.&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 15:33:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27800#M20268</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2013-02-27T15:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID with PAN5.x - AD Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27801#M20269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where did you find this tech article? I searched and can't locate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 22:55:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27801#M20269</guid>
      <dc:creator>charger</dc:creator>
      <dc:date>2013-02-27T22:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID with PAN5.x - AD Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27802#M20270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The article can be located here - &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4332"&gt;How to Configure Agentless User-ID in PAN-OS 5.0.x&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Personally if I only wanted the customer to setup the user account on the domain and not see the firewall configuration I would write my own version of this with own screenshots so then I could put my own company's branding on the document. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 23:11:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27802#M20270</guid>
      <dc:creator>SCoupland</dc:creator>
      <dc:date>2013-02-27T23:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID with PAN5.x - AD Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27803#M20271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone with PAN to confirm this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2013 07:15:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27803#M20271</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-02-28T07:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID with PAN5.x - AD Configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27804#M20272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No one from Palo Alto yet.&amp;nbsp; I will work on rounding someone up.&amp;nbsp; What I have been told is. . . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;USER-ID Update&lt;/P&gt;&lt;P class="p1"&gt;It is no longer necessary to use windows machine for one AD server&lt;/P&gt;&lt;P class="p1"&gt;It is best practice to setup filters to only enumerate groups that will be used in a policy - groups are ONLY used to create policy.&lt;/P&gt;&lt;P class="p1"&gt;The (windows) agent can still be used to check in with multiple AD servers.&amp;nbsp; As you probably know, it looks for kerberos tickets and also polls via Netbios or WMI to see if anyone has moved.&lt;/P&gt;&lt;P class="p1"&gt;Also, it is suggested to use agent if you don't want to use the control plane of the firewall for additional processing.&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;Hope that helps a little for now. . .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2013 12:58:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-with-pan5-x-ad-configuration/m-p/27804#M20272</guid>
      <dc:creator>cindyb</dc:creator>
      <dc:date>2013-02-28T12:58:18Z</dc:date>
    </item>
  </channel>
</rss>

