about agentless user-id in panos-5.0

Announcements

Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Reply
KiCheon.Lee
L4 Transporter

about agentless user-id in panos-5.0

Hello

I have a questions about agentless user-id in panos-5.0.

I know that cache time of user-ip mapping information is 45 minutes(default) on agent and cache time is 1 hour(default) on FW in PANOS-4.1.

Are these time values same in PANOS-5.0?

If it is right,

Do user ip mapping in MP run instead of agent role in PANOS-4.1? Are MP cache times 45minutes(default)?

and Do user ip mapping in DP run instead of  FW role in PANOS-4.1? Are DP cache times also 1 hour(default)?

Thanks


Accepted Solutions
kprakash
L5 Sessionator

Hi Cheon,

The same timers apply to the PANFWs running on 5.0, having the agentless service configured. Please find below the docs that explain about the timers on the PANFW ( and it applies to both the agent and the agentless services )

https://live.paloaltonetworks.com/docs/DOC-4551

I hope this helps.

BR,

Karthik RP

View solution in original post


All Replies
kprakash
L5 Sessionator

Hi Cheon,

The same timers apply to the PANFWs running on 5.0, having the agentless service configured. Please find below the docs that explain about the timers on the PANFW ( and it applies to both the agent and the agentless services )

https://live.paloaltonetworks.com/docs/DOC-4551

I hope this helps.

BR,

Karthik RP

View solution in original post

KiCheon.Lee
L4 Transporter

Thanks, kprakash.

Are there both ip-user-mapping info on DP and ip-user-mapping-mp info on MP when make user-id with user agent??

kprakash
L5 Sessionator

Hi Cheon,

Yes, we have the mappings on both the management plane and the data-plane. Hope that helps!

BR,

Karthik

zarina
L5 Sessionator

You can view the MP mappings through:

> show user ip-user-mapping-mp all

DP mappings:

>  show user ip-user-mapping all

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!