- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-25-2011 11:22 PM
Hi PA Champions,
I have had issues with high b/w utilization from PA-FW to PAN Agent over WAN links.
As such best alternate was to install a PAN Agent in remote WAN Site DC's, along with the PAN Agent
that is already installed at the Head office.
But once I had done with installation with the PAN Agent in the WAN site, I have had issues
with PA-FW trying to reference every user, even users fromthe Head Office to the WAN DC PAN agent.
As such, a user who was earliers successfully logging on to the PAN agent in the Head Office,
now is not able to browse, and it says its blocked, and witih in the blocked page it mentions his local IP address
as the 'user name' (Source) not the correct user name.
i.e Blocked User= <IP address>
This has happend only after installing and configuring the WAN Pan Agent.
Once We remove the WAN Site pan agent configuration from the PA-FW, everything is working fine as before.
No issues.
I presume this is cause the Head Office PAN Agent is not being used by PA-FW for referencing this user.
When I checked the PAN Agent status it showed me the following.
admin@DP-PAFW01(active)> show user pan-agent statistics
Timer: interval of group membership retrieval
State: *:primary pan-agent to retrieve group membership
---------------- --------------- ----- ------- ------------------ ------ ------ -------- -------- -------- --------------- -----
Name IP Address Port Vsys State Users Grps IPs Activity Timer(s) Domain Index
---------------- --------------- ----- ------- ------------------ ------ ------ -------- -------- -------- --------------- -----
PAN-Agent-01 10.0.2.20 7799 vsys1 connected, ok 0 0 10091 58 600 dpf 1
PAN-Agent-Ghu 10.12.111.14 7799 vsys1 *connected, ok 12660 443 59 67 600 dpf 2
Any idea on what is the best practice or best way to install and configure PAN Agent on the WAN DC's
so that the local Head office PAN agent can also be used for all head office users.
How can I make the PA-FW understand that the PAN Agent at the head office should be the
primary pan-agent to retrieve group membership and not the newly installed WAN Site PAN.
Thanks and Rgds,
Tauseef Ahmed.
03-29-2011 04:49 AM
Are your ip-user matchings aging out @ the PAN-Agent? I have seen that being an issue where old mappings make their way to the PAN. In other words, make sure the mappings age out on the PAN-agent! Have you disabled WMI/Netbios probing?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!