<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No of User ID agents for HQ and sites in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/205923#M60438</link>
    <description>&lt;P&gt;I would go with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thats why I was asking about inter branch comms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also.... seems pretty daft adding a windows&amp;nbsp;agent to each branch because if the branch PA fails then your users are stuffed anyway...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Mar 2018 13:31:24 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-03-16T13:31:24Z</dc:date>
    <item>
      <title>No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/205839#M60414</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My network topology is like I have HQ with PA-7050 firewall and 3 domain controllers in HQ. I have 22 branches with local domain controller in each branch and firewall is PA-3050.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I want to deploy user-ID agent, In my scenario what is the best way to deploy user-ID agents. I am thinking below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Deploy one user-ID agent (with backup) in each branch on member server and monitor the local domain controller (branch DC)&lt;/P&gt;&lt;P&gt;- Deploy one user-ID agent (with backup) in HQ on member server and monitor the HQ domain controllers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- How can I share the user-ID information between branch and HQ firewalls? Should I integrate all firewalls to all user-ID agents?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 07:40:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/205839#M60414</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-16T07:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/205895#M60423</link>
      <description>&lt;P&gt;let me just ask....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does branch 1 need to know about users at branch 2, etc...&amp;nbsp;&amp;nbsp;&amp;nbsp; or does HQ just need to know about all other branches. (users)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 12:27:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/205895#M60423</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-16T12:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/205920#M60436</link>
      <description>&lt;P&gt;-you can have all the branch firewalls set up with clientless user-id to the local AD, and have each firewall function as a UserID agent to the HQ location&lt;/P&gt;
&lt;P&gt;-you can also install a User-ID agent on each location and then connect each local firewall to the local User-ID agent, and have the HQ firewall connect to all the User-ID agents&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;unless it's likely your users will make connections to other branches I wouldn't share user-id between branches, only with HQ&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 13:21:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/205920#M60436</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-16T13:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/205923#M60438</link>
      <description>&lt;P&gt;I would go with &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thats why I was asking about inter branch comms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also.... seems pretty daft adding a windows&amp;nbsp;agent to each branch because if the branch PA fails then your users are stuffed anyway...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 13:31:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/205923#M60438</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-16T13:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206006#M60478</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have multiple remote locations and two datacenters. I have one agent in each data center and each PAN connectes to them for user-id. My agents are set to only look at exchange data since its updated very frequently and everyone runs Outlook clients. Works out really well. The agentless didnt work for us as we were running into a lot of wmi contention and alerts, we have the PAN's send out alerts for anything High and Critical hence the wmi alerts. Once we moved to the agents the alerts stopped and things are working properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 16:32:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206006#M60478</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-16T16:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206116#M60506</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you have agents only in HQ and all firewalls (sites + HQ) using those agents?&lt;/P&gt;&lt;P&gt;In this case, how about bandwidth usage from each site firewall to user-ID agent in HQ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 08:11:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206116#M60506</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-17T08:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206117#M60507</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;thanks. Approach 1 I believe is best as it will avoid the overhead of maintaining member servers and user-id agents in all branches.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about&amp;nbsp;if I use the user-ID agent only in HQ to monitor all DC servers (local in HQ + DC in branches). In this case,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- How can I calculate the bandwidth requirement on WAN link for user-ID agent to each branch DC monitor? Each branch has different number of users like 300, 50 or maximum 1100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2- Is it possible that branch firewall can learn the user-IP mapping from HQ firewall or user-ID agent in HQ for their local subnets only?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 08:25:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206117#M60507</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-17T08:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206147#M60511</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If every byte of bandwidth matters then I don't recomment using a central windows user-id agent server, as with this method the whole security log from every DC will be transfered from the branche DC to the user-id agent server.&lt;/P&gt;&lt;P&gt;As far as I know there is no general calculation of the required bandwidth, as it really depends on the user behaviour. But to get your required bandwidth, you can do the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Windows User-ID agent: Check the size of the security log on the DCs and devide that by the time the log contains entries&lt;/LI&gt;&lt;LI&gt;Agentless User-ID: export the logs with the IDs 4768, 4769, 4770, 4624, check the size of these and divide this numbet by the time you have logs&lt;/LI&gt;&lt;LI&gt;Windows Log Forwarding: the same as with Agentless User-ID Agent&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Of course with every transfer over the network there is also a (very) small percentage of overhead, but this probably does not matter that much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So in case you want/need all the User-ID data from all locations in all locations I would use one of the following methods:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Agentless Setup: Configure your 7050 to query all the DCs&lt;/LI&gt;&lt;LI&gt;Windows User-ID Agent: configure the agent to query the main DCs directly and configure all the branch DCs to forward the required logs to this User-ID Agent server (as described here:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/deploy-user-id-for-numerous-mapping-information-sources" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/deploy-user-id-for-numerous-mapping-information-sources&lt;/A&gt;)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;My personal preference in your situation would be the agentless setup because of the lower complexity - there are less components/features involved, which means less possible situations where problems can happen.&lt;/P&gt;&lt;P&gt;But both of these methods will work and also in both cases you can configure the branch firewalls to fetch the User-ID data either from your 7050 or the windows user-id agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To your second question: this is kind of possible. In the zone configuration where you have to enable the user identification, you could configure the subnets that the firewall should use for user-id. But this is a second step I think, the firewall will still get all User-ID data from the HQ and then simply not use the ones that are not part of a configured subnet. Or if you go the way with configure every branch firewall to connect to the branch DCs, it is possible to configure the agentless user agent to only gather the user-ip mappings from the local subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 13:17:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206147#M60511</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-17T13:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206352#M60562</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;While I have not measured the actual bandwidth, its pretty small and not noticeable on our network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:05:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/206352#M60562</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-19T15:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: No of User ID agents for HQ and sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/207421#M60802</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 11:58:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-of-user-id-agents-for-hq-and-sites/m-p/207421#M60802</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-26T11:58:40Z</dc:date>
    </item>
  </channel>
</rss>

