<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to work about multiple User-ID Agent in an appliance ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/64029#M38457</link>
    <description>&lt;P&gt;Hi Rmonvon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that is correct - if you enable UserID redistribution, that information will be shared, but why would you enable it in above scenario, what is the benefit of it? Steve and Vince are both right, Steve elaborated a bit but we could probably tell you better if you explained your situation a bit more, what are you sharing between the sites...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in any case, there is no document that tells bandwidth used between firewalls or UserID towards the firewall, but in terms of having the least traffic possible while all firewalls know information of each-other users, I would say UserID redistribution is the way to go because that should have the least overhead. If one firewall aggregates and distributes to others it is less traffic. Let's represent it this way, X, Y and Z are firewalls while x, y and z are their agents on the respective locations. Now:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If Z is collector, than you have 7 communication directions:&lt;/P&gt;&lt;P&gt;x &amp;lt;- X (firewall X polls agent x)&lt;/P&gt;&lt;P&gt;X &amp;lt;- Z (firewall Z that collects polls firewall X)&lt;/P&gt;&lt;P&gt;y &amp;lt;- Y (firewall Y polls agent y)&lt;/P&gt;&lt;P&gt;Y &amp;lt;- Z&lt;/P&gt;&lt;P&gt;z &amp;lt;- Z&lt;/P&gt;&lt;P&gt;Z -&amp;gt; X (redistribution from Z about Y users goes to X)&lt;/P&gt;&lt;P&gt;Z -&amp;gt; Y&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is no collector, you have nine:&lt;/P&gt;&lt;P&gt;x &amp;lt;- X&lt;/P&gt;&lt;P&gt;y &amp;lt;- X&lt;/P&gt;&lt;P&gt;z &amp;lt;- X&lt;/P&gt;&lt;P&gt;x &amp;lt;- Y&lt;/P&gt;&lt;P&gt;y &amp;lt;- Y&lt;/P&gt;&lt;P&gt;z &amp;lt;- Y&lt;/P&gt;&lt;P&gt;x &amp;lt;- Z&lt;/P&gt;&lt;P&gt;y &amp;lt;- Z&lt;/P&gt;&lt;P&gt;z &amp;lt;- Z&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, I don't think there is any documents stating bandwidth used for UserID or between HA ports (I know I was looking for such documents before and could not find any :D), but for UserID you might be able to calculate it based on one bandwidth between agent and firewall (you can monitor that for a day and multiply for those scenarios above, I don't think there is any difference between information sent from agent to firewall or it being sent from firewall to firewall, almost the same xml file is delivered).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps a bit &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luciano&lt;/P&gt;</description>
    <pubDate>Wed, 02 Sep 2015 17:53:17 GMT</pubDate>
    <dc:creator>Lucky</dc:creator>
    <dc:date>2015-09-02T17:53:17Z</dc:date>
    <item>
      <title>How to work about multiple User-ID Agent in an appliance ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/63930#M38402</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 3 domains in different locations (US, CN, TW) each one have its own User-ID agent.&lt;/P&gt;&lt;P&gt;We deployed PA-3020 in each&amp;nbsp;location and each one had set those&amp;nbsp;3 User-ID agents in the User-ID Agent configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If a user account belong to&amp;nbsp;US and it login at CN, how does the PA appliance to get account information ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the PA in CN ask all 3 User-ID Agent ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My customr&amp;nbsp;concern about there are too many traffic to&amp;nbsp;&lt;SPAN&gt;occupy their MPLS WAN bandwidth.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I need to know the&amp;nbsp;whole process and if we have some Doc. about this would be better.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 11:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/63930#M38402</guid>
      <dc:creator>neilwu</dc:creator>
      <dc:date>2015-09-01T11:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to work about multiple User-ID Agent in an appliance ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/63934#M38403</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Short question, did you not configure AD replication between your site ?&lt;/P&gt;&lt;P&gt;Peaple in the US shold not use AD in TW for opening session ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then 1 palo, 1 agent per site should be enough. Depend of you replication time between ADs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 13:02:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/63934#M38403</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2015-09-01T13:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to work about multiple User-ID Agent in an appliance ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/63976#M38424</link>
      <description>&lt;P&gt;The Palo Alto firewalls do not communicate with each other. &amp;nbsp;They each only know about the user-id associations they get from agents associated with that firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With AD and user-id, the key to remember is that the ip address association for the user login will be in the server event log that authenticates the user. &amp;nbsp;These local event log messages with the user and ip address only exist on the server that authenticates the user locally. &amp;nbsp;These event message do not replicate as AD data does through the AD database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So for each firewall you&amp;nbsp;will need to see how your rules are written for user-id and where the user was authenticated by AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, if all of your rules are based on local users going out of the site, you likely only need the local AD for the firewall. &amp;nbsp;When you login to any of your forest domains, this will be serviced by the local AD and logged there even if the actual account was created in one of the other two domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if your have inbound rules from the other two sites coming into the local site that require user-id, you likely will need the agent input from the remote AD because that is where the authentication took place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other complication could come if you are using nat between any of the sites. &amp;nbsp;Because the user-id will be based on the real ip address and if you nat that address the association would be lost.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 21:52:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/63976#M38424</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-09-01T21:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to work about multiple User-ID Agent in an appliance ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/64006#M38441</link>
      <description>&lt;P&gt;Hi...I just want to clarify on the comment about the PAs &lt;SPAN&gt;not communicating with each other. &amp;nbsp;With respect to userID, when we enable the userID agent on the PA appliance, we can configure redistribution and defining a collector. &amp;nbsp;This will allow the local PA&amp;nbsp;to act as a user mapping redistribution point for other firewalls on your network.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2015 14:29:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/64006#M38441</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2015-09-02T14:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to work about multiple User-ID Agent in an appliance ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/64029#M38457</link>
      <description>&lt;P&gt;Hi Rmonvon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that is correct - if you enable UserID redistribution, that information will be shared, but why would you enable it in above scenario, what is the benefit of it? Steve and Vince are both right, Steve elaborated a bit but we could probably tell you better if you explained your situation a bit more, what are you sharing between the sites...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in any case, there is no document that tells bandwidth used between firewalls or UserID towards the firewall, but in terms of having the least traffic possible while all firewalls know information of each-other users, I would say UserID redistribution is the way to go because that should have the least overhead. If one firewall aggregates and distributes to others it is less traffic. Let's represent it this way, X, Y and Z are firewalls while x, y and z are their agents on the respective locations. Now:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If Z is collector, than you have 7 communication directions:&lt;/P&gt;&lt;P&gt;x &amp;lt;- X (firewall X polls agent x)&lt;/P&gt;&lt;P&gt;X &amp;lt;- Z (firewall Z that collects polls firewall X)&lt;/P&gt;&lt;P&gt;y &amp;lt;- Y (firewall Y polls agent y)&lt;/P&gt;&lt;P&gt;Y &amp;lt;- Z&lt;/P&gt;&lt;P&gt;z &amp;lt;- Z&lt;/P&gt;&lt;P&gt;Z -&amp;gt; X (redistribution from Z about Y users goes to X)&lt;/P&gt;&lt;P&gt;Z -&amp;gt; Y&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is no collector, you have nine:&lt;/P&gt;&lt;P&gt;x &amp;lt;- X&lt;/P&gt;&lt;P&gt;y &amp;lt;- X&lt;/P&gt;&lt;P&gt;z &amp;lt;- X&lt;/P&gt;&lt;P&gt;x &amp;lt;- Y&lt;/P&gt;&lt;P&gt;y &amp;lt;- Y&lt;/P&gt;&lt;P&gt;z &amp;lt;- Y&lt;/P&gt;&lt;P&gt;x &amp;lt;- Z&lt;/P&gt;&lt;P&gt;y &amp;lt;- Z&lt;/P&gt;&lt;P&gt;z &amp;lt;- Z&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, I don't think there is any documents stating bandwidth used for UserID or between HA ports (I know I was looking for such documents before and could not find any :D), but for UserID you might be able to calculate it based on one bandwidth between agent and firewall (you can monitor that for a day and multiply for those scenarios above, I don't think there is any difference between information sent from agent to firewall or it being sent from firewall to firewall, almost the same xml file is delivered).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps a bit &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2015 17:53:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/64029#M38457</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-09-02T17:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to work about multiple User-ID Agent in an appliance ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/64076#M38488</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your&amp;nbsp;&lt;SPAN&gt;suggestion.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;There is no&amp;nbsp;&lt;SPAN&gt;replication so I think I need to deploy all User-ID agenet at each one PA appliance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But that is a good point, I would like to set&amp;nbsp;&lt;SPAN&gt;replication in each site.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 02:23:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/64076#M38488</guid>
      <dc:creator>neilwu</dc:creator>
      <dc:date>2015-09-03T02:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to work about multiple User-ID Agent in an appliance ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/64077#M38489</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for your clearly&amp;nbsp;discription.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2015 02:29:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-work-about-multiple-user-id-agent-in-an-appliance/m-p/64077#M38489</guid>
      <dc:creator>neilwu</dc:creator>
      <dc:date>2015-09-03T02:29:12Z</dc:date>
    </item>
  </channel>
</rss>

