Showing results for 
Show  only  | Search instead for 
Did you mean: 


L4 Transporter

When enabling user-id where does it check against to get the information to identify  the users? I have it turned on for serveral zones and it only seems to work on the VPN user-id's.


@jdprovine you can configure the RADIUS server to forward succesfull authentication messages as syslog to a syslog receiver (both firewall and UserID Agent can do this)

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy


You can do syslog forwarding or you could use RadiUID. Syslog forwarding is probably going to be the easiest solution however. 

Ok i have got to jump in here as getting very interesting....


im puzzled by the syslog stuff. Assumimg rad auth is accepted and a tick in the box to syslog... how does this then relate to user ip mapping... or is this for group membership ?


just to add... we also use radius for non staff logins on GP. We have no user agent to assist with this. The palo seems to do this itsel when user id is enabled on interface/zone.


a user logs into radius as fred, we have a policy that allows fred through... 


am i missing something .......



The userid agent I would install on an AD domain controller could also pull information from another server that the radius information forwarded to a syslog server or the firwall can be set up to access the syslog servers information for radius - interesting.

Does the userid agent have to be on all your domain controllers or just one?



I can see all the users from my GP logins too, I think its because they are authenticated through the portal but I don't think that is same userid stuff

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!