<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Maximum number of UserID Agents for 4.1.x ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8508#M6283</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whats the maximum number of UserID agents that can be configured to talk to the firewall ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ie. Will the firewall complain if we have 200+ userID agents configured to talk to it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know each agent can monitor a maximum of 100 domain controllers.. but how many agents can the firewall monitor?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Mar 2012 05:35:46 GMT</pubDate>
    <dc:creator>ucteam</dc:creator>
    <dc:date>2012-03-20T05:35:46Z</dc:date>
    <item>
      <title>Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8508#M6283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whats the maximum number of UserID agents that can be configured to talk to the firewall ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ie. Will the firewall complain if we have 200+ userID agents configured to talk to it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know each agent can monitor a maximum of 100 domain controllers.. but how many agents can the firewall monitor?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 05:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8508#M6283</guid>
      <dc:creator>ucteam</dc:creator>
      <dc:date>2012-03-20T05:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8509#M6284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been unable to find a hard coded limit. I don't believe we restrict you to a certain number of agents connected to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, keep in mind that only one agent per domain actually connects to the firewall at a time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words, having multiple user-id agents connected to 1 firewall for 1 domain will only provide redunancy in case one of the agents goes down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this doesn't quite answer what you're looking for, please let me know the environment you're going to be deploying and I can look for more specific information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Jason Seals &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Mar 2012 00:10:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8509#M6284</guid>
      <dc:creator>jseals</dc:creator>
      <dc:date>2012-03-24T00:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8510#M6285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of course I find the number right after posting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"• Each UIA can connect to up to 100 Domain Controllers&lt;/P&gt;&lt;P&gt;• Each firewall can support up to 100 UIA’s&lt;/P&gt;&lt;P&gt;• Limit of 100 entries each in the Allow and Ignore list on the UIA"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In summary, it looks like we can have 100 agents connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason Seals&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 4.1, the agent can connect to 100 Domain Controllers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Mar 2012 00:21:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8510#M6285</guid>
      <dc:creator>jseals</dc:creator>
      <dc:date>2012-03-24T00:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8511#M6286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;My understanding is that the firewall will not read from more that one UIA at a time. One is Primary other is secondary, how would adding all the other agents help with user Identification?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 18:08:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8511#M6286</guid>
      <dc:creator>pperrotta</dc:creator>
      <dc:date>2012-03-26T18:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8512#M6287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;Hi...If you have different domains with different AD forests (or without trust), you can use 1 agent per domain.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;Also, you can have 2+ agents per domain as needed.&amp;nbsp; Let's say you have 1 main location and 4 remote sites, each site has some DCs, and where WAN bandwidth is low.&amp;nbsp;&amp;nbsp; You can deploy 1 agent per site to monitor its local DCs without crossing the WAN.&amp;nbsp;&amp;nbsp; The PA firewall can talk to all 5 agents to gather UserIDs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif; "&gt;Thanks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 20:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8512#M6287</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-03-26T20:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8513#M6288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok in my situation I have 30 remote DC's with slower WAN links, I currently use 2 Pan agents to poll all 30, it works fairly well but I would say 20% of users get portaled on a regular basis. So if I install agents on all my DC's the PA could digest info from all of them? Is that recomeneded? I seem to get diffrent answers on this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 21:07:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8513#M6288</guid>
      <dc:creator>pperrotta</dc:creator>
      <dc:date>2012-03-26T21:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8514#M6289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In general, deploying the agent near the DCs is to decrease the WAN bandwidth consumption by the agent.&amp;nbsp; If the consumed WAN bandwidth by the 2 agents polling your 30 DCs is not a problem for you, then I suggest leaving the 2 agents where they are. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;20% of users get portaled - I assume you mean Captive Portal and 20% is prompted for authentication.&amp;nbsp; If so, you should extend the 'User Identification Timeout'.&amp;nbsp; If you're running version 4.1 agent, you can add your exchange server(s) to the list and have the agents monitor the exchange server(s) as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 22:48:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8514#M6289</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-03-26T22:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8515#M6290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys ,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have a question , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN Firewall have any limit with users from Ldap ? &lt;/P&gt;&lt;P&gt;PA 200&amp;nbsp; support the same numbers of users than PA 2050 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thiago Lima.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2012 12:45:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8515#M6290</guid>
      <dc:creator>Thiago</dc:creator>
      <dc:date>2012-03-27T12:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8516#M6291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Yes, there are upper limits to every system based on system resources.&amp;nbsp; Can you be more specific on your questions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2012 19:19:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8516#M6291</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-03-28T19:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8517#M6292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color:#000000;font-family:Tahoma, 'Sans Serif', Arial;font-size:11px;text-align:-webkit-auto"&gt;I've heard the following may be documented on the Palo Alto internal KB:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Tahoma, 'Sans Serif', Arial;font-size:11px;text-align:-webkit-auto"&gt;Platform Capacity&lt;/P&gt;&lt;P style="color:#000000;font-family:Tahoma, 'Sans Serif', Arial;font-size:11px;text-align:-webkit-auto"&gt;Maximum number of pan-agents per vsys: 100&lt;/P&gt;&lt;P style="color:#000000;font-family:Tahoma, 'Sans Serif', Arial;font-size:11px;text-align:-webkit-auto"&gt;Maximum number of pan-agents per platform: 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color:#000000;font-family:Tahoma, 'Sans Serif', Arial;font-size:11px;text-align:-webkit-auto"&gt;BUT I also revieved a reply to direct email recently stating that:&lt;/P&gt;&lt;P style="color:#000000;font-family:Tahoma, 'Sans Serif', Arial;font-size:11px;text-align:-webkit-auto"&gt;Thats it's 255 for user agent.&lt;/P&gt;&lt;P style="color:#000000;font-family:Tahoma, 'Sans Serif', Arial;font-size:11px;text-align:-webkit-auto"&gt;Terminal server agents are 255 except in the 5000 series where they can go up to 1000&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Apr 2012 10:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8517#M6292</guid>
      <dc:creator>ucteam</dc:creator>
      <dc:date>2012-04-01T10:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum number of UserID Agents for 4.1.x ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8518#M6293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And yes.. correct.. the reason for deploying many UserID agents (i.e locally installed at each remote site with domain controller) is to reduce the network/ bandwidth utilisation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whilst in theory the concept of having 2 central agents monitoring 100 domain controllers seems like a good solution.. unfortunately it doesnt account for common windows applications / active directory issues whereby sometimes users or computer accounts will begin authenticating 1000s of times (seemingly unnescarily) in the matter of a few seconds due to either poorly written applications or general issues with the windows operating system itself..&amp;nbsp; These excessive amount of successful authentication events which then have to be dragged across the network by the centrally located UserID agent can have a negative impact on the network if there is limited avaialble bandwidth on the WAN links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also PaloAltos UserID agent limitation that it can only monitor a maximum of 100 domain controllers each is a bit of a pain..&amp;nbsp; &lt;/P&gt;&lt;P&gt;Given that we have over 130 domain controllers it would require a minimum of 4 UserID agents centrally installed to monitor all domain controllers (with redundancy). So either dedicating 4 new servers to this purpose or deploying to 4 existing random servers seems messy when compared to been able to package up and just push out the agent to all existing domain controllers with a identical config file for each.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Apr 2012 13:01:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/maximum-number-of-userid-agents-for-4-1-x/m-p/8518#M6293</guid>
      <dc:creator>ucteam</dc:creator>
      <dc:date>2012-04-01T13:01:22Z</dc:date>
    </item>
  </channel>
</rss>

