I have been using the agentless user-id but it seems to be overloading my firewalls so I am moving to a separate agent. I am trying to decide whether I need one or two though and need to understand what happens when an agent restarts. When it loses the agent, does the firewall drop all its user mappings? When the agent comes back does it drip-feed new mappings or does it clear the existing mappings on the firewall from that source? In other words, if my server were to reboot, would the firewalls carry on and pick up where they left off (accepting I would miss that any events while the agent were down) or would I lose all my user mapopings either when it went down or when it came back? Most of my user mappings are from SYSLOG so are not re-generated. Once they are gone, that's it.
... View more