Traps Endpoint Installation

Reply
L1 Bithead

Traps Endpoint Installation

Hi , I'm new to Palo Alto Traps Endpoint platform. I have a question regarding Traps Installation for On-Site Standalone deployment

- Do we need to configure Active Directory in our environment before installing Traps ? Is Active Directory mandatory for Traps ESM and Agents installation?

Any help would be much appreciated. Thanks

Tags (4)
L7 Applicator

Re: Traps Endpoint Installation

@m.hassan96,

ESM will handle things perfectly fine without Active Directory. 

Re: Traps Endpoint Installation

 

Hello @m.hassan96,

 

Active Directory is not a requirement for Traps deployment, and Traps will work fine without it.

Active Directory can be integrated with Traps to authenticate ESM Administrators, and to use Active Directory objects, and also it will make it easier for big environments to push the certificates through a GPO if SSL is being used.

But still it is not a requirement.

L1 Bithead

Re: Traps Endpoint Installation

@BPry , @AbdulRahman_Safwat  Thanks for your replies. So I just need to Configure ESM , install Trap Agents on Workload VMs and specify IP of ESM server and thats it. Agents will be able to pull updates and security policies from ESM server on that IP address, no furthur configuration or authentication is required. Is that right? Kindly correct me if I'm wrong 

L7 Applicator

Re: Traps Endpoint Installation

@m.hassan96 ,

Correct. When you install the ESM you'll ideally specify a certificate signed by a trusted CA so that the Client and the server can securely determine whether or not they trust each other; the Server itself will need to be allowed access to the outside to pull the updates, but the agents themselves will pull the updates from the ESM on port 2125 (by default). 

L1 Bithead

Re: Traps Endpoint Installation

@BPry Thanks that helped a lot. Just to make things more clear, What If we don't use any kind of certificates? I'm assuming Communication between Agents and ESM server would still happen but it would be less secure (no encryption). Is that right? 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!