PAN Agent Over WAN issues.

cancel
Showing results for 
Search instead for 
Did you mean: 

PAN Agent Over WAN issues.

Not applicable

Hi PA Champions,

I have had issues with high b/w utilization from PA-FW to PAN Agent over WAN links.

As such best alternate was to install a PAN Agent in remote WAN Site DC's, along with the PAN Agent

that is already installed at the Head office.

But once I had done with installation with the PAN Agent in the WAN site, I have had issues

with PA-FW trying to reference every user, even users fromthe Head Office to the WAN DC PAN agent.

As such, a user who was earliers successfully logging on to the PAN agent in the Head Office,

now is not able to browse, and it says its blocked, and witih in the blocked page it mentions his local IP address

as the 'user name' (Source) not the correct user name.

i.e Blocked User= <IP address>

This has happend only after installing and configuring the WAN Pan Agent.

Once We remove the WAN Site pan agent configuration from the PA-FW, everything is working fine as before.

No issues.

I presume this is cause the Head Office PAN Agent is not being used by PA-FW for referencing this user.

When I checked the PAN Agent status it showed me the following.

admin@DP-PAFW01(active)> show user pan-agent statistics

Timer: interval of group membership retrieval
State: *:primary pan-agent to retrieve group membership
---------------- --------------- ----- ------- ------------------ ------ ------ -------- -------- -------- --------------- -----
Name             IP Address      Port  Vsys     State             Users  Grps   IPs      Activity Timer(s) Domain          Index
---------------- --------------- ----- ------- ------------------ ------ ------ -------- -------- -------- --------------- -----
PAN-Agent-01     10.0.2.20       7799  vsys1    connected, ok     0      0      10091    58       600      dpf             1
PAN-Agent-Ghu 10.12.111.14    7799  vsys1   *connected, ok     12660  443    59       67       600      dpf             2

Any idea on what is the best practice or best way to install and configure PAN Agent on the WAN DC's

so that the local Head office PAN agent can also be used for all head office users.

How can I make the PA-FW understand that the PAN Agent at the head office should be the

primary pan-agent to retrieve group membership and not the newly installed WAN Site PAN.

Thanks and Rgds,

Tauseef Ahmed.

1 REPLY 1

L3 Networker

Are your ip-user matchings aging out @ the PAN-Agent? I have seen that being an issue where old mappings make their way to the PAN. In other words, make sure the mappings age out on the PAN-agent! Have you disabled WMI/Netbios probing?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!