<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Questioning about agentless user-id. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/220049#M63496</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Keep in mind, the firewall does not monitor every group in the domain, only those it is configured to.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;... if you restrict the monitored groups with an ldap filter or specify them one by one in the group mapping settings &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 01 Jul 2018 18:20:20 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-07-01T18:20:20Z</dc:date>
    <item>
      <title>Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/48545#M35740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I have questions about user-id functions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. How much user-id be supported by agent-less user-id? I guess that 64K user-id and 640 user-group would be supported on all of PAN model. right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. When using user-id collector, How much user-id and user-group be supported by agent-less user-id for receiving all of user-id and user-group from other FWs? 64K user-id and 640 user-group be supported?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. How many domain and DC be supported on user-id collector environment? Only 20 DC and 8 Different Domains be supported?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. When Using User-ID Collector would support so many user-id, user-group Is it makes a problem of performance for MGMT of FWs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. I know that command "show user ip-user-mappling all" would show mapping user for DataPlane and "show user ip-user-mapping-mp all" would show mapping user for Management Plane? What's different for both of command? When should I check for user-mapping for MP or DP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Roh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 05:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/48545#M35740</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-19T05:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/48546#M35741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;1. How much user-id be supported by agent-less user-id? I guess that 64K user-id and 640 user-group would be supported on all of PAN model. right?&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG&gt;Right&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;2. When using user-id collector, How much user-id and user-group be supported by agent-less user-id for receiving all of user-id and user-group from other FWs? 64K user-id and 640 user-group be supported?&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;STRONG&gt;Right&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;3. How many domain and DC be supported on user-id collector environment? Only 20 DC and 8 Different Domains be supported?&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-style: inherit; font-family: inherit; text-decoration: underline;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-style: inherit; font-family: inherit; text-decoration: underline;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;Approximate Numbers:&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-style: inherit; font-family: inherit; text-decoration: underline;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;Agentless: &lt;/STRONG&gt;&lt;/SPAN&gt;Small/Medium-sized Deployments and&amp;nbsp; LAB Environments&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Monitoring up to 20 Domain controllers and/or Exchange servers. &lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN style="font-style: inherit; font-family: inherit; text-decoration: underline;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;User-ID Agent&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt; :&lt;/STRONG&gt; Large Deployments&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Monitoring up 100 Domain controllers and/or Exchange servers&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;4. When Using User-ID Collector would support so many user-id, user-group Is it makes a problem of performance for MGMT of FWs?&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG&gt;Using the User-ID feature to its max capacity would increase the MP CPU but should not affect the Managment Access to the FW.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;5. I know that command "show user ip-user-mapping all" would show mapping user for DataPlane and "show user ip-user-mapping-mp all" would show mapping user for Management Plane? What's different for both of the command? When should I check for user-mapping for MP or DP?&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;STRONG&gt;DP reads User ID info from MP ,so while debugging User-ID related issues start with MP related command&amp;nbsp; (&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;show user &lt;/SPAN&gt;ip-user-mapping-mp all).&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 09:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/48546#M35741</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-08-19T09:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/48547#M35742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nadir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great Answer!! Thanks a lot.&lt;/P&gt;&lt;P&gt;Have a good day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Roh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 09:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/48547#M35742</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-19T09:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/48548#M35743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks you for your information and I have some questions as following:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/thread/12764"&gt;Number of user-ip-mappings supported and user-id agentless buffer question&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Pisek B.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Mar 2015 08:00:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/48548#M35743</guid>
      <dc:creator>PisekBootta</dc:creator>
      <dc:date>2015-03-13T08:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/219506#M63384</link>
      <description>&lt;P&gt;Hi Ameya,&lt;BR /&gt;&lt;BR /&gt;In case of the a single Domian forest.let say we are going with agent based user-id deployment. there is a constraint of the number of user group that the Palo Alto FW's can parse right. I am assuming 640 user groups for 7.0 version and 10k for 8.0 version. what if we have user group count over 10k scenarios how can you do the user group mapping in such cases.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:27:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/219506#M63384</guid>
      <dc:creator>Sanssj</dc:creator>
      <dc:date>2018-06-27T15:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/219510#M63386</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91991"&gt;@Sanssj&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You have over 10k different user groups being services by a single firewall?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:40:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/219510#M63386</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-27T15:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/219516#M63389</link>
      <description>&lt;P&gt;Keep in mind, the firewall does not monitor every group in the domain, only those it is configured to.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2018 16:29:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/219516#M63389</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-06-27T16:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/220049#M63496</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Keep in mind, the firewall does not monitor every group in the domain, only those it is configured to.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;... if you restrict the monitored groups with an ldap filter or specify them one by one in the group mapping settings &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jul 2018 18:20:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/220049#M63496</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-01T18:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/220063#M63503</link>
      <description>&lt;P&gt;Yeah we do have a single AD forest. which has over 13k user groups. we are finding a optimum way to query the necessary groups instead of each and evry group. include list is not a feasible solution at this point. I am exploring ways to see how to achieve this.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jul 2018 22:02:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/220063#M63503</guid>
      <dc:creator>Sanssj</dc:creator>
      <dc:date>2018-07-01T22:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Questioning about agentless user-id.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/220064#M63504</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91991"&gt;@Sanssj&lt;/a&gt;&lt;/P&gt;&lt;P&gt;In this case you need a good naming concept for AD groups, so you could specify a simple LDAP filter to import the required groups ... or a little more complex LDAP filter. But this is probably the only way&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jul 2018 23:15:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questioning-about-agentless-user-id/m-p/220064#M63504</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-01T23:15:50Z</dc:date>
    </item>
  </channel>
</rss>

