<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panagents and Active Directory sub-domains in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panagents-and-active-directory-sub-domains/m-p/50377#M37085</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update- 4.1 does address this. I upgraded earlier this week, and there appears to be a positive impact. Not only can I manage the multiple domains, I can also point to Exchange servers for authentication.&lt;/P&gt;&lt;P&gt;Thanks for the fixes!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Nov 2011 16:22:00 GMT</pubDate>
    <dc:creator>cloughr</dc:creator>
    <dc:date>2011-11-17T16:22:00Z</dc:date>
    <item>
      <title>Panagents and Active Directory sub-domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panagents-and-active-directory-sub-domains/m-p/50374#M37082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have an Active Directory domain with a sub domain- bar.org and foo.bar.org. We have 4 panagent servers, 2 dedicated to each. Our problem is that when user A.bar.org logs on, PA sometimes identifies him as user B.foo.bar.org,&amp;nbsp; with the same IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can re-create this problem by logging onto a machine first as a member of bar.org, then foo.bar.org. I suspect multiple logons to a single machine, plus short IP lease times are the issue. Is there a solution for this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 19:13:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panagents-and-active-directory-sub-domains/m-p/50374#M37082</guid>
      <dc:creator>cloughr</dc:creator>
      <dc:date>2011-11-07T19:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Panagents and Active Directory sub-domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panagents-and-active-directory-sub-domains/m-p/50375#M37083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is a current design limitation since windows does not create a log off event for us to monitor. I assume you have a pan agent for every domain since currently the pan agent can only monitor a single domain. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the reason you are running into this issue is that pan agent (bar.org) and pan agent (foo.bar.org) will retain the user to ip mapping even though the user has logged off that machine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;one work around for this is if the machines allowing WMI probing. you can enable WMI probing on the palo alto device and also lower the age-out timeout. but that can not be lower the the netbios probing timer which is also the timer for wmi. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;note: you do not want this it o be to aggressive since you will be forcing the mapping to be deleted from pan agent. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to verify but i believe we made some enhancements for this in 4.1 which you can use a single agent for multiple domains. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Nov 2011 04:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panagents-and-active-directory-sub-domains/m-p/50375#M37083</guid>
      <dc:creator>jnguyen</dc:creator>
      <dc:date>2011-11-09T04:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Panagents and Active Directory sub-domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panagents-and-active-directory-sub-domains/m-p/50376#M37084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, that's very helpful. We do have a panagent for each domain, but we don't currently use WMI probing. I don't believe WMI or NETBIOS is enabled on our clients, but it could be for some.&lt;/P&gt;&lt;P&gt;I will upgrade to 4.1 and monitor, then try your suggestions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Nov 2011 12:48:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panagents-and-active-directory-sub-domains/m-p/50376#M37084</guid>
      <dc:creator>cloughr</dc:creator>
      <dc:date>2011-11-09T12:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Panagents and Active Directory sub-domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panagents-and-active-directory-sub-domains/m-p/50377#M37085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update- 4.1 does address this. I upgraded earlier this week, and there appears to be a positive impact. Not only can I manage the multiple domains, I can also point to Exchange servers for authentication.&lt;/P&gt;&lt;P&gt;Thanks for the fixes!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Nov 2011 16:22:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panagents-and-active-directory-sub-domains/m-p/50377#M37085</guid>
      <dc:creator>cloughr</dc:creator>
      <dc:date>2011-11-17T16:22:00Z</dc:date>
    </item>
  </channel>
</rss>

