<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN AGENT CAPACITY BY VSYS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-capacity-by-vsys/m-p/39478#M28974</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another point .. this information is perhaps out of date&amp;nbsp; "Each UIA can connect to up to 10 Domain Controllers"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The older 3.x UIA Agents by "default" would monitor only 10 domain controllers, but if you manually edited the XML config file you could get them to monitor 100&amp;nbsp; e.g &amp;lt;max-dc&amp;gt;100&amp;lt;/max-dc&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the new 4.x UIA have this setting by default now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Apr 2012 09:44:43 GMT</pubDate>
    <dc:creator>ucteam</dc:creator>
    <dc:date>2012-04-25T09:44:43Z</dc:date>
    <item>
      <title>PAN AGENT CAPACITY BY VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-capacity-by-vsys/m-p/39475#M28971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen the following information for pan agent capacity&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-layout-grid-align:none;text-autospace:none"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN-US" style="font-size:14.0pt;font-family:&amp;amp;quot;DINOT-Bold&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-bidi-font-family:DINOT-Bold;mso-ansi-language:EN-US"&gt;Capacity&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-layout-grid-align:none;text-autospace:none"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:SabonLTStd-Roman;mso-bidi-font-family: SabonLTStd-Roman;mso-ansi-language:EN-US"&gt;User Identification capacity limits:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-layout-grid-align:none;text-autospace:none"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:SabonLTStd-Roman;mso-bidi-font-family: SabonLTStd-Roman;mso-ansi-language:EN-US"&gt;• The PA-4000 series can support up to 64,000 concurrent users; the PA-2000 series can&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-layout-grid-align:none;text-autospace:none"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:SabonLTStd-Roman;mso-bidi-font-family: SabonLTStd-Roman;mso-ansi-language:EN-US"&gt;support up to 47,000 concurrent users.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-layout-grid-align:none;text-autospace:none"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:SabonLTStd-Roman;mso-bidi-font-family: SabonLTStd-Roman;mso-ansi-language:EN-US"&gt;• Up to 640 groups can be used in policies for each virtual system (vsys)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-layout-grid-align:none;text-autospace:none"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:SabonLTStd-Roman;mso-bidi-font-family: SabonLTStd-Roman;mso-ansi-language:EN-US"&gt;• Each UIA can connect to up to 10 Domain Controllers&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-layout-grid-align:none;text-autospace:none"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:SabonLTStd-Roman;mso-bidi-font-family: SabonLTStd-Roman;mso-ansi-language:EN-US"&gt;• &lt;SPAN style="background:red; mso-highlight:red"&gt;Each firewall can support up to 100 UIA’s&lt;/SPAN&gt;&lt;SPAN style="color:red"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="mso-layout-grid-align:none;text-autospace:none"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:SabonLTStd-Roman;mso-bidi-font-family: SabonLTStd-Roman;color:red;mso-ansi-language:EN-US"&gt;•&lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:SabonLTStd-Roman;mso-bidi-font-family:SabonLTStd-Roman; mso-ansi-language:EN-US"&gt; Limit of 100 entries each in the Allow and Ignore list on the UIA&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US" style="font-size:12.0pt;font-family:SabonLTStd-Roman; mso-bidi-font-family:SabonLTStd-Roman;mso-ansi-language:EN-US"&gt;• Only 1 NTLM handshake can be in process between a UIA and AD server at a time&lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="mso-ansi-language:EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;And I have the following question : the support of 100 user id agent is for each VSYS or Globally?? because in 4.0 you can not shared pan-agent configuration. And if you have 10 VSYS with 12 PAN AGENT we must configure 120 PAN AGENT on your PA.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;thanks for your answer,&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 16:04:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-capacity-by-vsys/m-p/39475#M28971</guid>
      <dc:creator>alle</dc:creator>
      <dc:date>2012-03-26T16:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: PAN AGENT CAPACITY BY VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-capacity-by-vsys/m-p/39476#M28972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is in total.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VSYS in PAN (and most other devices for that matter) is just to segment the dataplane. You still have a single mgmtplane and its the mgmtplane who does the User-ID Agent identification and stuff.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 19:07:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-capacity-by-vsys/m-p/39476#M28972</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-26T19:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: PAN AGENT CAPACITY BY VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-capacity-by-vsys/m-p/39477#M28973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mikand I confirm, this is in total! when I create more than 100 pan agent I see the following message:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Server error :&amp;nbsp; constraints failed : No. of agents configured exceeds maximum allowed(100)&lt;BR /&gt;[edit]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2012 12:26:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-capacity-by-vsys/m-p/39477#M28973</guid>
      <dc:creator>alle</dc:creator>
      <dc:date>2012-03-28T12:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: PAN AGENT CAPACITY BY VSYS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-capacity-by-vsys/m-p/39478#M28974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another point .. this information is perhaps out of date&amp;nbsp; "Each UIA can connect to up to 10 Domain Controllers"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The older 3.x UIA Agents by "default" would monitor only 10 domain controllers, but if you manually edited the XML config file you could get them to monitor 100&amp;nbsp; e.g &amp;lt;max-dc&amp;gt;100&amp;lt;/max-dc&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the new 4.x UIA have this setting by default now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2012 09:44:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-capacity-by-vsys/m-p/39478#M28974</guid>
      <dc:creator>ucteam</dc:creator>
      <dc:date>2012-04-25T09:44:43Z</dc:date>
    </item>
  </channel>
</rss>

