<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID for large scale deployment in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-large-scale-deployment/m-p/411805#M92766</link>
    <description>&lt;P&gt;do you have DC's at each of these sites...&amp;nbsp; &amp;nbsp;there are various figures flying around but you need to consider what is at each location.&amp;nbsp; if you have a palo at each location then use local agent to local DC. we have 8 DC's for 8 k user base and we just went for 1 server agent at each of our 2 major sites on dedicated windoze boxes and never had any issues.&amp;nbsp; we do have 200 remote small sites but they all stream back to our major sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;perhaps an overview of your setup would help....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this kinda keeps the busy end away from the palo's and the DC's&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Jun 2021 15:48:17 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2021-06-08T15:48:17Z</dc:date>
    <item>
      <title>User-ID for large scale deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-large-scale-deployment/m-p/411683#M92753</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have planned to implement user based policy in PA and we have roughly around 5k users across different locations with multiple controller as we have two options,&lt;/P&gt;&lt;P&gt;1. Dedicated windows based user-id agent&lt;/P&gt;&lt;P&gt;2. Palo alto Integrated user-id agent&lt;/P&gt;&lt;P&gt;among these two which one is best for production with 5K+ users&amp;nbsp; and what is best practice for deploying the same&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Siva&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 06:54:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-large-scale-deployment/m-p/411683#M92753</guid>
      <dc:creator>nkmehta</dc:creator>
      <dc:date>2021-06-08T06:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for large scale deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-large-scale-deployment/m-p/411805#M92766</link>
      <description>&lt;P&gt;do you have DC's at each of these sites...&amp;nbsp; &amp;nbsp;there are various figures flying around but you need to consider what is at each location.&amp;nbsp; if you have a palo at each location then use local agent to local DC. we have 8 DC's for 8 k user base and we just went for 1 server agent at each of our 2 major sites on dedicated windoze boxes and never had any issues.&amp;nbsp; we do have 200 remote small sites but they all stream back to our major sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;perhaps an overview of your setup would help....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this kinda keeps the busy end away from the palo's and the DC's&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 15:48:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-large-scale-deployment/m-p/411805#M92766</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-06-08T15:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for large scale deployment</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-large-scale-deployment/m-p/411979#M92783</link>
      <description>&lt;P&gt;To not have much load on the firewalls the Dedicated windows based user-id agent is better than the integrated one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you can use user redistribution so that the firewalls that are not infront of the users will get this data from the other edge firewalls if they can't directly connect to the windows agent. You can read this if interested:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/ip-and-user-tag-mappings-redistribution-for-dag-dug/m-p/393030#M90970" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/ip-and-user-tag-mappings-redistribution-for-dag-dug/m-p/393030#M90970&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 07:10:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-large-scale-deployment/m-p/411979#M92783</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-06-09T07:10:58Z</dc:date>
    </item>
  </channel>
</rss>

