<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: adding more than one UIA agent on firewall? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/216055#M62599</link>
    <description>&lt;P&gt;Thanks man...i got it now...&lt;/P&gt;</description>
    <pubDate>Thu, 31 May 2018 07:37:52 GMT</pubDate>
    <dc:creator>kchopra01</dc:creator>
    <dc:date>2018-05-31T07:37:52Z</dc:date>
    <item>
      <title>adding more than one UIA agent on firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/215915#M62575</link>
      <description>&lt;P&gt;Hi Techies,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a small doubt whether I can add more than one UIA server in my firewall in the sense that they should behave kind of active passive .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Requirement is something like that I want to secure user id functionality on firewall so that if one of my UIA gets down , then firewall should contact other UIA server for that....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if we have any solution for it ...&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 13:40:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/215915#M62575</guid>
      <dc:creator>kchopra01</dc:creator>
      <dc:date>2018-05-30T13:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: adding more than one UIA agent on firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/215926#M62577</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes you can have the PAN monitor more than one user-id agent. I have two just to keep things simple and redundant,&amp;nbsp;I have a small environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/configure-the-windows-based-user-id-agent-for-user-mapping" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/configure-the-windows-based-user-id-agent-for-user-mapping&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 14:22:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/215926#M62577</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-30T14:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: adding more than one UIA agent on firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/215928#M62579</link>
      <description>&lt;P&gt;oh thats great if you are using it already !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I have one doubt , whether panos reads those both servers in sequence ( kind of active -passive style) or it monitors both simulatenously ?&lt;/P&gt;&lt;P&gt;Also, if it monitors both at the same time then isn't it it creates problem&amp;nbsp; ? because it is reading logs from both UIA, so whose result it will give to firewall ?? UIA1 or 2 ?&lt;/P&gt;&lt;P&gt;sorry if it sounds silly but i need clarity before implementing..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 14:34:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/215928#M62579</guid>
      <dc:creator>kchopra01</dc:creator>
      <dc:date>2018-05-30T14:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: adding more than one UIA agent on firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/215931#M62581</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Your concerns are very valid. It monitors and ingests the information from both agents at the same time on an interval. I belevie it uses timestamps from the windows event logs to resolve conflicts, i.e. one IP has two names.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/User-ID-Agent-Setup-Tips/ta-p/54755" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/User-ID-Agent-Setup-Tips/ta-p/54755&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 14:43:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/215931#M62581</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-30T14:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: adding more than one UIA agent on firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/216038#M62593</link>
      <description>&lt;P&gt;Hey thanks man for the solution....&lt;/P&gt;&lt;P&gt;So , i just need to add just one more UIA under device&amp;gt;user identification&amp;gt; user id agent and thats it right ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In that way , I would be seein two servers connected ( green) and my firewall will talk to two servers at the same time and if there is any conflict, it would read windows event logs.....to cross verif and send results&amp;nbsp; ...right ?&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 06:26:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/216038#M62593</guid>
      <dc:creator>kchopra01</dc:creator>
      <dc:date>2018-05-31T06:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: adding more than one UIA agent on firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/216051#M62597</link>
      <description>&lt;P&gt;The UIA reads the windows event logs continuously to provide the most current User-IP mappings to the firewall. The firewall then talks to both UIAs and always uses the most current timestamp for an IP. So lets assume the following:&lt;/P&gt;&lt;P&gt;UIA1: domain\johndoe 20180531-06:10:34 10.10.10.10&lt;/P&gt;&lt;P&gt;UIA2: domain\johndoe 20180531-07:23:26 10.10.10.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case the firewall would have received the mapping first from UIA1. As soon as the new mapping is present on UIA2 the firewall updates it's user-ip-mapping table with the new event from UIA2.&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 07:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/216051#M62597</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-31T07:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: adding more than one UIA agent on firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/216055#M62599</link>
      <description>&lt;P&gt;Thanks man...i got it now...&lt;/P&gt;</description>
      <pubDate>Thu, 31 May 2018 07:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-more-than-one-uia-agent-on-firewall/m-p/216055#M62599</guid>
      <dc:creator>kchopra01</dc:creator>
      <dc:date>2018-05-31T07:37:52Z</dc:date>
    </item>
  </channel>
</rss>

