<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN agent over WAN issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-over-wan-issue/m-p/46624#M34276</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well Ill just jump into this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point in the product there is no means to prioritize which agent will be set as primary nor can we set an order of precedence on the DC's to give one a greater weight than others. This is however a feature request and is under investigation for future builds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Apr 2011 17:24:17 GMT</pubDate>
    <dc:creator>pkruse</dc:creator>
    <dc:date>2011-04-08T17:24:17Z</dc:date>
    <item>
      <title>PAN agent over WAN issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-over-wan-issue/m-p/46623#M34275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just had another issue to discuss about WAN Pan Agent, if you do have time, please go through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Local LAN PAN agent is configured for 10.0.0.0/8 network&lt;/P&gt;&lt;P&gt;WAN PAN agent is configured for site 1 network 10.12.111.x/24&lt;/P&gt;&lt;P&gt;But I have users from Site to with network 10.13.111.x/24 as well logging on to the same DC of site 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think its some AD issue, though site 2 has its own DC, some users of that site log on to site 1.&lt;/P&gt;&lt;P&gt;And so on, some users of site 3 also do the same, and more over, there are users from the local LAN&lt;/P&gt;&lt;P&gt;who some times log on to the WAN DC's !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I configure the pan agent to work in such an environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have had issues when I configured the local PAN Agent and remote PAN Agent with same allowed list of IP's 10.0.0.0/8.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;I have had issues&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;with PA-FW trying to reference every user, even users from&amp;nbsp; the Head Office to the WAN DC PAN agent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;As such, a user who was earlier successfully logging&amp;nbsp; on to the PAN agent in the Head Office,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;now&amp;nbsp; is not able to browse, and it says its blocked,&amp;nbsp; and within in the&amp;nbsp; blocked page it mentions his local IP address as the 'user name'&amp;nbsp; (Source) not the correct user name.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;admin@DP-PAFW01(active)&amp;gt; show user pan-agent&amp;nbsp; statistics&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Timer: interval of group membership retrieval&lt;BR /&gt;State: *:primary pan-agent&amp;nbsp; to retrieve group membership&lt;BR /&gt;----------------&amp;nbsp; --------------- ----- -------&amp;nbsp; ------------------ ------ ------&amp;nbsp; -------- -------- -------- ---------------&amp;nbsp; -----&lt;BR /&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP&amp;nbsp; Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port&amp;nbsp; Vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Users&amp;nbsp; Grps&amp;nbsp;&amp;nbsp; IPs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Activity Timer(s) Domain&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Index&lt;BR /&gt;----------------&amp;nbsp; --------------- ----- ------- ------------------&amp;nbsp; ------ ------ --------&amp;nbsp; -------- -------- ---------------&amp;nbsp; -----&lt;BR /&gt;PAN-Agent-01&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.2.20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7799&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp;&amp;nbsp; connected,&amp;nbsp; ok&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10091&amp;nbsp;&amp;nbsp;&amp;nbsp; 58&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 600&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dpf&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;PAN-Agent-Ghu 10.12.111.14&amp;nbsp;&amp;nbsp;&amp;nbsp; 7799&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp; *connected,&amp;nbsp; ok&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12660&amp;nbsp; 443&amp;nbsp;&amp;nbsp;&amp;nbsp; 59&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 67&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 600&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dpf&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;How can I make the PA-FW understand that the PAN Agent at the head office should&amp;nbsp; be the&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;primary pan-agent to retrieve group membership and not the&amp;nbsp; newly installed WAN Site PAN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;Kindly comment with your inputs,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;Rgds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;Tauseef&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 05:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-over-wan-issue/m-p/46623#M34275</guid>
      <dc:creator>ta185020</dc:creator>
      <dc:date>2011-04-07T05:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: PAN agent over WAN issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-over-wan-issue/m-p/46624#M34276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well Ill just jump into this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point in the product there is no means to prioritize which agent will be set as primary nor can we set an order of precedence on the DC's to give one a greater weight than others. This is however a feature request and is under investigation for future builds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Apr 2011 17:24:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-over-wan-issue/m-p/46624#M34276</guid>
      <dc:creator>pkruse</dc:creator>
      <dc:date>2011-04-08T17:24:17Z</dc:date>
    </item>
  </channel>
</rss>

