<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Management Setting in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5819#M4252</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A name="1519783"&gt;That&lt;/A&gt;&lt;SPAN style="font-weight: bold;"&gt; &lt;/SPAN&gt;option is needed to allow communication between firewalls when a firewall is acting as a redistribution point to provide user mapping information to other PAN-OS firewalls.Also it is available for management profile.You can distribute user id information as a new feature on panos 5&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 May 2013 18:38:25 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-05-23T18:38:25Z</dc:date>
    <item>
      <title>User-ID Management Setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5818#M4251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the device management settings there is now a "User-ID" checkbox.&amp;nbsp; I have looked at the administrators guide but it doesn't mention it, presumably because it is fairly new.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does this actually control, because the user-id agent on the box works fine without that checked (or seems to).&amp;nbsp; Other options such as SSH, ping etc are obviously management access protocols but user-id doesn't seem to fit in quite the same.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 16:43:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5818#M4251</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2013-05-23T16:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Management Setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5819#M4252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A name="1519783"&gt;That&lt;/A&gt;&lt;SPAN style="font-weight: bold;"&gt; &lt;/SPAN&gt;option is needed to allow communication between firewalls when a firewall is acting as a redistribution point to provide user mapping information to other PAN-OS firewalls.Also it is available for management profile.You can distribute user id information as a new feature on panos 5&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:38:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5819#M4252</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-05-23T18:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Management Setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5820#M4253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The userid option is introduced in 5.0 and need to be enabled when you are using the agentless user id and also when distributing the mappings to other firewalls&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 21:42:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5820#M4253</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-05-23T21:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Management Setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5821#M4254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry to be obtuse, but I still don't get this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had agentless user-id turned on and working with my 5 DCs without this turned on, so it doesn't *appear* to prevent that working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it controls redistribution of the user-id information I can see why I wouldn't have noticed that, but does that then mean that I need the management addresses of the to firewalls to be included in the "permitted addresses" as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 08:05:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5821#M4254</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2013-05-24T08:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Management Setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5822#M4255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The checkbox allows that specific firewall to be the agent for other firewalls. It gives you a central user-ID agent that several firewalls can use without having to deploy software agents or set up the agentless configuration on every firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 16:33:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5822#M4255</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-05-24T16:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Management Setting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5823#M4256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not really, two specific questions then:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Is it needed to permit an XML API connection from an external server&lt;/P&gt;&lt;P&gt;2) Is it needed to replicate user ID data to the HA peer?&lt;/P&gt;&lt;P&gt;2a) If the answer to 2 is "yes", then does the peer firewall need to be in the permitted IPs list?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 16:45:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-management-setting/m-p/5823#M4256</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2013-05-24T16:45:15Z</dc:date>
    </item>
  </channel>
</rss>

