<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID Agent or Agentless User-ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9422#M6907</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;What is the difference between User-ID Agent and Agentless User-ID?&amp;nbsp; Why would I use one over the other?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Jan 2014 02:12:10 GMT</pubDate>
    <dc:creator>bmodi</dc:creator>
    <dc:date>2014-01-29T02:12:10Z</dc:date>
    <item>
      <title>User-ID Agent or Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9422#M6907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;What is the difference between User-ID Agent and Agentless User-ID?&amp;nbsp; Why would I use one over the other?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 02:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9422#M6907</guid>
      <dc:creator>bmodi</dc:creator>
      <dc:date>2014-01-29T02:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent or Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9423#M6908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;similar discussion&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/23631#23631"&gt;https://live.paloaltonetworks.com/message/23631#23631&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 02:36:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9423#M6908</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2014-01-29T02:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent or Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9424#M6909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding few more related discussions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/13129"&gt;User-ID Best Practices document?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3120"&gt;User Identification Tech Note PAN-OS 4.1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/34659"&gt;best practice User-ID strategy?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/24137"&gt;UserID&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6172"&gt;Installation and Provisioning of the User Agent&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 03:01:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9424#M6909</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-29T03:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent or Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9425#M6910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One would user UserID agent - if you have a distributed DC set up - across multiple WAN locations. That way you can run the UseriD Agent on each DC at the remote location and keep their chatter local. &lt;/P&gt;&lt;P&gt;Then only send the filtered (specific IP to user mappings) across the WAN to a head end firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If however, you'd like to keep everything under one administrator groups's control (sometimes server folks and network folks have trouble sharing info.), then it may be easier to simply run the UserID agentless on the firewall. That way, only the access to AD via the LDAP admin account will be needed to have the firewall talk to the DCs. This would be preferred i&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;n cases where the DCs and firewall are all local and there is no WAN link to cross.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jul 2014 07:45:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9425#M6910</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2014-07-26T07:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent or Agentless User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9426#M6911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The basic difference between agent and agentless is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User-id agent installs on a windows computer and collects the user to ip mappings for forwarding to the firewall&lt;/LI&gt;&lt;LI&gt;Agentless user-id runs on the firewall and queries the windows servers to retrieve the user to ip mapping information&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User-id agent can install multiple ways&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Install directly on the domain controller for each one and collect local data&lt;/LI&gt;&lt;LI&gt;Install on one computer and query data from multiple domain controllers from this location&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;General considerations:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;each domain controller in your AD domain has local only copies of the login mappings you need so all must participate in user-id in some way&lt;/LI&gt;&lt;LI&gt;If you have a lot of processing on the firewall and a lot of domain controllers then agentless user-id may not be practical&lt;/LI&gt;&lt;LI&gt;If your AD computers are spread around multiple WAN links the traffic generated by agentless user-id may be problematic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the best source for the gory details is the User-id Best practices documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6591"&gt;User-ID Best Practices - PAN-OS 5.0, 6.0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jul 2014 12:02:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-or-agentless-user-id/m-p/9426#M6911</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-07-26T12:02:50Z</dc:date>
    </item>
  </channel>
</rss>

