<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to set up Active Directory user ID? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12813#M9390</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the PAN Agent is required to see UserID's in the logs and to be able to set policy by UserID.&amp;nbsp; Make sure to install the correct PAN Agent as there are a couple now with the latest versions (one for LDAP and one for AD).&amp;nbsp; You can also use the Terminal Services Agent in conjunction with the PAN Agent to get UserID mappings on a Citrix or Terminal server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most customers install a single agent on a Windows member server that is configured to talk to their Domain Controllers.&amp;nbsp; The firewall is configured to communicate with the Agent.&amp;nbsp; Some customers choose to install multiple Agents directly on the Domain controllers and the firewall is configured to communicate with all of them.&amp;nbsp; Both approaches or a combination will work - it just comes down to what is best for your environment.&amp;nbsp; The Agent does need to run continuously for best results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Jun 2010 16:01:40 GMT</pubDate>
    <dc:creator>kbrazil</dc:creator>
    <dc:date>2010-06-18T16:01:40Z</dc:date>
    <item>
      <title>How to set up Active Directory user ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12812#M9389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new the Palo Alto networks firewall device (model PA-500).&amp;nbsp; I have it deployed in my environment but am just letting it pass all traffic right now; I want to get a handle on the traffic before I start limiting things.&amp;nbsp; In any case, I would like to have the PA-500 identify AD users and groups for our domain.&amp;nbsp; I've tried to research this and saw a bit about a user ID agent, but I'm not quite understanding if this is necessary or not.&amp;nbsp; So my questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Can the PA-500 communicate directly with my domain controllers and therefore eliminate the need for a user ID agent?&lt;/P&gt;&lt;P&gt;- If the user ID agent is needed, do I just need to install this on one computer (i.e. one of my DCs) or is this needed on each client PC? This agent has to run continuously for user ID to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know these are basic questions, but most of the material I've seen on this is really about installing the user ID agent and not about in what situations it is needed.&amp;nbsp; Thank you in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jun 2010 15:22:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12812#M9389</guid>
      <dc:creator>synapse</dc:creator>
      <dc:date>2010-06-18T15:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up Active Directory user ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12813#M9390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the PAN Agent is required to see UserID's in the logs and to be able to set policy by UserID.&amp;nbsp; Make sure to install the correct PAN Agent as there are a couple now with the latest versions (one for LDAP and one for AD).&amp;nbsp; You can also use the Terminal Services Agent in conjunction with the PAN Agent to get UserID mappings on a Citrix or Terminal server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most customers install a single agent on a Windows member server that is configured to talk to their Domain Controllers.&amp;nbsp; The firewall is configured to communicate with the Agent.&amp;nbsp; Some customers choose to install multiple Agents directly on the Domain controllers and the firewall is configured to communicate with all of them.&amp;nbsp; Both approaches or a combination will work - it just comes down to what is best for your environment.&amp;nbsp; The Agent does need to run continuously for best results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jun 2010 16:01:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12813#M9390</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-06-18T16:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up Active Directory user ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12814#M9391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the advice, Kelly.&amp;nbsp; I'm actually surprised that the firewall device does not communicate directly with AD.&amp;nbsp; Doesn't this design just introduce a point of failure?&amp;nbsp; If my policies are based around usernames, but the agent stops responding (service down, server is shut down, etc.) will my policies fail open or closed?&amp;nbsp; I guess I will probably deploy multiple agents to minimize this possibility.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jun 2010 20:30:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12814#M9391</guid>
      <dc:creator>synapse</dc:creator>
      <dc:date>2010-06-18T20:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up Active Directory user ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12815#M9392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using multiple Agents is best practice for high availability for UserID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The use of agents helps to offload the userid to IP mapping from the control plane of the firewall.&amp;nbsp; In this way the agent processes the mapping information into a table which is sent to the firewall.&amp;nbsp; This both minimizes the work the firewall needs to do and also can reduce the amount of traffic the firewall is sending and receiving.&amp;nbsp; Another issue, especially for AD integration, is that an Agent running on a Windows member server allows the use of native Windows API's to access the user to IP mapping information.&amp;nbsp; This makes integration much more seamless since the authentication needed to query this data is provided by the service account configured on the Domain, which is a naive Windows function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jun 2010 23:42:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12815#M9392</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-06-18T23:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up Active Directory user ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12816#M9393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How does one install multiple agents on the SAME controller?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2011 18:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12816#M9393</guid>
      <dc:creator>swishewk</dc:creator>
      <dc:date>2011-06-20T18:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to set up Active Directory user ID?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12817#M9394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With "multiple agents"&amp;nbsp; it was meant that they are installed on different boxes. &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt; So that when one box dies the other can take over...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2011 18:58:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-set-up-active-directory-user-id/m-p/12817#M9394</guid>
      <dc:creator>michael_schumak</dc:creator>
      <dc:date>2011-06-20T18:58:55Z</dc:date>
    </item>
  </channel>
</rss>

