<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID-Agent Traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41069#M30168</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have user-id-agents on ou core DC's and all our local DC's (across the WAN).&amp;nbsp; We receive reports with high SMB traffic polling from the core DC -&amp;gt; local DC.&amp;nbsp; Anyway to eliminate or reduce?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Sep 2012 16:29:28 GMT</pubDate>
    <dc:creator>rrau</dc:creator>
    <dc:date>2012-09-24T16:29:28Z</dc:date>
    <item>
      <title>User-ID-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41069#M30168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have user-id-agents on ou core DC's and all our local DC's (across the WAN).&amp;nbsp; We receive reports with high SMB traffic polling from the core DC -&amp;gt; local DC.&amp;nbsp; Anyway to eliminate or reduce?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 16:29:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41069#M30168</guid>
      <dc:creator>rrau</dc:creator>
      <dc:date>2012-09-24T16:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41070#M30169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Check the following settings on the User-ID Agents.&lt;/P&gt;&lt;P style="background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: Arial, Helvetica, sans-serif;"&gt;Enable WMI and Disable netbios lookups&amp;nbsp; (Recommended) .&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-size: 12px; font-family: Arial, Helvetica, sans-serif;"&gt;File&amp;gt;Debug : Set the Debug level to None (Debugging could be set if needed).&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Ref :&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/15354#15354"&gt;https://live.paloaltonetworks.com/message/15354#15354&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;-Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 03:21:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41070#M30169</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-09-25T03:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41071#M30170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ameya, I have applied the recommended settings with no change in the high traffic reports.&amp;nbsp; Anything else that could be affecting this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 15:51:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41071#M30170</guid>
      <dc:creator>rrau</dc:creator>
      <dc:date>2012-11-13T15:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41072#M30171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Please make sure customer local agent is only doing a user to ip mapping for its local DC subnet. It should not be doing a mapping of the remote DC subnet&lt;/SPAN&gt;. &lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;So if your agent is reading secuirty logs from one DC only&amp;nbsp; and you have muliple agents reading secuity logs from multiple DC, then you configure those agent on the pan and the PAN would read the user to ip mapping from all the agents.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Please do keep in mind that Communication between the DC and the Agent over the WAN is a bit chatty. Thats why make sure&amp;nbsp; local agent only doing user to ip mapping for its local DC subnet and not be doing a mapping of the remote DC subnet.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Thanks,&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Syed Hasnain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 16:28:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41072#M30171</guid>
      <dc:creator>shasnain</dc:creator>
      <dc:date>2012-11-13T16:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41073#M30172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;where is this setting?&amp;nbsp; we only have user-id agent on the core DC's&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Nov 2012 21:12:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41073#M30172</guid>
      <dc:creator>rrau</dc:creator>
      <dc:date>2012-11-13T21:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41074#M30173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syed, could you please tell me where I would apply that setting?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 14:18:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41074#M30173</guid>
      <dc:creator>rrau</dc:creator>
      <dc:date>2012-11-21T14:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41075#M30174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How does your settings look like?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you run pan-agent directly on the Domain Controller servers I think you can set 127.0.0.1 as Domain Controller Address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you limit in Allow List (and if needed in Ignore List aswell) which ip ranges your clients uses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if this particular DC only handles for example 10.0.1.0/24 then add this as Allow List.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One tricky part if your AD is distributed (regarding allow/ignore list) is if the local DC's dont answer to the client request any other DC can verify and log the ip&amp;lt;-&amp;gt;user in its security log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This gives if you have a 1:1 relation between PAN-agent and DC server (either dedicated machine or runned directly on the DC server) you will have less chat on the network (and if segmented (the local DC's refuse to answer login attempts from remote user of another site) the WMI chat straight to the clients will be less over WAN aswell).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2012 09:34:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-traffic/m-p/41075#M30174</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-22T09:34:43Z</dc:date>
    </item>
  </channel>
</rss>

