<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ID Agent Questions (Windows &amp;amp; Intergrated) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-questions-windows-amp-intergrated/m-p/226601#M65226</link>
    <description>&lt;P&gt;Thanks MickBall!&amp;nbsp; We are replacing our ASA in our main datacenter this month &amp;amp; I am trying to gauge how straight forward our User ID implementation will be.&amp;nbsp; The company I work for has 7000 employees most of which are not directly connected to the data center.&amp;nbsp; We use the traditional MPLS cloud setup with all internet traffic traversing our main data center at over 60 sites.&amp;nbsp; Even our remote users working from home traverse the data center.&amp;nbsp; We also have a robust wireless environment with multiple Aruba controllers &amp;amp; there is a high frequency of IP changes on the end points.&amp;nbsp; It's good to know there are advanced probing features &amp;amp; that the PA can be setup as a sylog listener incase the size &amp;amp; structure of our user base challenges User ID technology in our situation.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Aug 2018 13:12:06 GMT</pubDate>
    <dc:creator>MarioMarquez</dc:creator>
    <dc:date>2018-08-09T13:12:06Z</dc:date>
    <item>
      <title>User ID Agent Questions (Windows &amp; Intergrated)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-questions-windows-amp-intergrated/m-p/226541#M65215</link>
      <description>&lt;P&gt;I am taking online trainging &amp;amp;&amp;nbsp;I would be super&amp;nbsp;thankful if someone with solid PA experience could answer&amp;nbsp;some questions &amp;amp; provide any helpful&amp;nbsp;feedback.&amp;nbsp; I have a list of true or false questions &amp;amp; I just want to make sure my brain is processing all this information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The Windows agent gets installed on the domain server(s) only NOT all of the endpoints them selves?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;In most cases the Windows based agent running on the domain server sends username &amp;amp; IP data to the firewall&amp;nbsp;effectively&amp;nbsp;without enabling WMI&amp;nbsp;Client Probing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;For&amp;nbsp;environments where users are constantly switching from wired to wireless connections &amp;amp; IP's change frequently on the end points, the Windows agent works pretty well without the need for the wireless controller (or other log collectors) to send syslogs to the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;For a large environment with 7000 users (2000 local/5000 remotely connecting via MPLS to PA in data center) the Windows based agent is the best way to go?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The Windows agent works well for remote users connecting to network via&amp;nbsp;Anyconnect SSL&amp;nbsp;client without the need to send syslogs to the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 04:10:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-questions-windows-amp-intergrated/m-p/226541#M65215</guid>
      <dc:creator>MarioMarquez</dc:creator>
      <dc:date>2018-08-09T04:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Agent Questions (Windows &amp; Intergrated)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-questions-windows-amp-intergrated/m-p/226595#M65225</link>
      <description>&lt;P&gt;ok in brief... perhaps a more tech answer will follow.. please observe end note...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The Windows agent gets installed on the domain server(s) only NOT all of the endpoints them selves?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;True,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;In most cases the Windows based agent running on the domain server sends username &amp;amp; IP data to the firewall&amp;nbsp;effectively&amp;nbsp;without enabling WMI&amp;nbsp;Client Probing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;True,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;For&amp;nbsp;environments where users are constantly switching from wired to wireless connections &amp;amp; IP's change frequently on the end points, the Windows agent works pretty well without the need for the wireless controller (or other log collectors) to send syslogs to the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;True,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;For a large environment with 7000 users (2000 local/5000 remotely connecting via MPLS to PA in data center) the Windows based agent is the best way to go?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;True but extra true if servers are more local to users than the PA's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True or False&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The Windows agent works well for remote users connecting to network via&amp;nbsp;Anyconnect SSL&amp;nbsp;client without the need to send syslogs to the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;True.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my answers are based on my setup/relationship between AD,users and devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thay are only true as all users and devices authenticate against AD on several occasions throughout the day.&lt;/P&gt;&lt;P&gt;I also have a timeout set to 24 hours...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for other setups the answers may be more of a maybe or false depending on how much activity goes on between the user and AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if your users are all domain members and do lots of email and file sharing, drive connecting etc then the windows security log will be frequently updated with user-ip info and this is the needy fulfilment of the log collecter agent thingy to work efficiently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would elaborate further but need to attend my dental appointment where no doubt i will have half my face removed for a large fee...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 11:40:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-questions-windows-amp-intergrated/m-p/226595#M65225</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-09T11:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Agent Questions (Windows &amp; Intergrated)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-questions-windows-amp-intergrated/m-p/226601#M65226</link>
      <description>&lt;P&gt;Thanks MickBall!&amp;nbsp; We are replacing our ASA in our main datacenter this month &amp;amp; I am trying to gauge how straight forward our User ID implementation will be.&amp;nbsp; The company I work for has 7000 employees most of which are not directly connected to the data center.&amp;nbsp; We use the traditional MPLS cloud setup with all internet traffic traversing our main data center at over 60 sites.&amp;nbsp; Even our remote users working from home traverse the data center.&amp;nbsp; We also have a robust wireless environment with multiple Aruba controllers &amp;amp; there is a high frequency of IP changes on the end points.&amp;nbsp; It's good to know there are advanced probing features &amp;amp; that the PA can be setup as a sylog listener incase the size &amp;amp; structure of our user base challenges User ID technology in our situation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 13:12:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-questions-windows-amp-intergrated/m-p/226601#M65226</guid>
      <dc:creator>MarioMarquez</dc:creator>
      <dc:date>2018-08-09T13:12:06Z</dc:date>
    </item>
  </channel>
</rss>

