<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agentless User-ID Question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-question/m-p/101423#M44508</link>
    <description>&lt;P&gt;Thanks! I started to look into this a little more and found a petter article than what I was seeing previously. Our system engineer just asked why it was hitting the DCs so often since he had to allocate more resources to them; I didn't have the answer since I thought the probing setting was when it was going out to the server and requesting the user-id information, not every 2 seconds.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Aug 2016 19:59:05 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2016-08-08T19:59:05Z</dc:date>
    <item>
      <title>Agentless User-ID Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-question/m-p/101230#M44436</link>
      <description>&lt;P&gt;So I've been under the impression that our PA-3020s contact the ADDC servers to authenticate users every 20 minutes when it's setup to do a probe; then caches this information locally so that it isn't constantly hammering the servers with WMI requests. I've been told that this isn't the case and that they are hitting the server every few seconds. Is there somewhere were I can tell the 3020s to simply look at the cached information unless it identifies a user not in the cache, or the 20 minute window is hit and it needs to go and check for new users/groups?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've included a screenshot of both the User Idnetification field, everything under the actual LDAP server settings are set as follows; Bind Timeout=30 / Search Timeout= 10 / Retry Interval= 60.&lt;/P&gt;&lt;P&gt;Is this something that can actually be modified to use the cache or will it by default do a WMI query every time?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 749px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5079i9330486768B24528/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 15:20:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-question/m-p/101230#M44436</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-08-04T15:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-question/m-p/101421#M44506</link>
      <description>&lt;P&gt;WMI probing is for the end clients not the domain controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As indicated by your screen shot the firewall probes the DCs every 2 seconds for any new event IDs the firewall will then only keep the 4 that it needs for the passive IP to user ID attribution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are you trying to limit? &amp;nbsp;Are you DCs being overworked? &amp;nbsp;The highest you'd probably want to extend that query time out to would probably be 15 seconds. &amp;nbsp;Though 15 seconds might be too long and if your user was quick enough you might have a user that tries to access the Internet or whatever you're mandating user attribution for, before that 15 second timer.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 17:38:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-question/m-p/101421#M44506</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-08-08T17:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-question/m-p/101423#M44508</link>
      <description>&lt;P&gt;Thanks! I started to look into this a little more and found a petter article than what I was seeing previously. Our system engineer just asked why it was hitting the DCs so often since he had to allocate more resources to them; I didn't have the answer since I thought the probing setting was when it was going out to the server and requesting the user-id information, not every 2 seconds.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 19:59:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-question/m-p/101423#M44508</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-08-08T19:59:05Z</dc:date>
    </item>
  </channel>
</rss>

