<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID. Is WMI really needed? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146167#M49148</link>
    <description>&lt;P&gt;I know i've been advised to disable it. It's an extra layer, but it wasn't even effective in my case as the logs were filled with messages about the WMI queue being maxed out and it not adding additional clients to probe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no approach seems to be perfect, but for the most part, you should be fine if the AD logs or whathaveyou are providing you with the info. The worst case scenario is since it doesn't handle logouts, you will have a persistent association between a user id and a source IP if a user is logged out, but in that case, your traffic sourced from that IP should be minimal and non-interactive and it will be updated when the next user logs in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Mar 2017 15:54:01 GMT</pubDate>
    <dc:creator>bradk14</dc:creator>
    <dc:date>2017-03-06T15:54:01Z</dc:date>
    <item>
      <title>User-ID. Is WMI really needed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146158#M49147</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an end-customer who is using ServerMonitoring and User-Id agent at the same time. His AD has been audited by Microsoft and discovered that their performance is affected by thew WMI probbing. My questions is. If they remove all ServerMonitoring and kept only the User-Id Agent? Do they need the WMI configuration in both Firewall and AD?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;ACUNTIA COS&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 15:31:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146158#M49147</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2017-03-06T15:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID. Is WMI really needed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146167#M49148</link>
      <description>&lt;P&gt;I know i've been advised to disable it. It's an extra layer, but it wasn't even effective in my case as the logs were filled with messages about the WMI queue being maxed out and it not adding additional clients to probe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no approach seems to be perfect, but for the most part, you should be fine if the AD logs or whathaveyou are providing you with the info. The worst case scenario is since it doesn't handle logouts, you will have a persistent association between a user id and a source IP if a user is logged out, but in that case, your traffic sourced from that IP should be minimal and non-interactive and it will be updated when the next user logs in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 15:54:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146167#M49148</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-06T15:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID. Is WMI really needed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146185#M49152</link>
      <description>&lt;P&gt;We had lot of agent stability issue when we started with firewalls ~3 years back. One of the suggestions over troubleshooting by support was to disable WMI.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 16:49:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146185#M49152</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2017-03-06T16:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID. Is WMI really needed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146417#M49188</link>
      <description>&lt;P&gt;It depends on your environment&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you have a fairly static environment (typical office space) you may not need probing as your users will stay on the same ip address for a long time, you can simply increase the 'user identification timeout' to a workday (9 hours, about the time a kerberos ticket is valid for) and be ok (ip-user maping will be removed after 9 hours)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the big issue with probing comes into play in a dynamic environment with lots of roaming users that switch IP addresses without necessarily logging back in again (creating a new logon event for the UserID to pick up)&lt;/P&gt;
&lt;P&gt;in such an environment you need to make sure user A has abandoned his or her IP and now user B has acquired it and is potentially 'overprivileged'&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 15:37:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146417#M49188</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-07T15:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID. Is WMI really needed?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146556#M49226</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Also WMI is very chatty and unencrypted. We had an internal pen test at one of my previous employers and they were able to sniff the password because their system was being intterogated via WMI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just another thought...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 22:52:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-wmi-really-needed/m-p/146556#M49226</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-03-07T22:52:14Z</dc:date>
    </item>
  </channel>
</rss>

