Hi, we've had some issues using the User-ID agent on the PAN, but I think it's due to us having multiple domains. We had the same issues you were having , where we'd get a user-IP mapping 50% of the time. We tried tuning it, but couldn't imrpove it very much. After working with our sales engineer and PAN support, it looks like Captive Portal is the way to go for 100% user-IP mapping, but that can be a little aggressive for the user community. We're looking into the other reccomendation which was having a server in each domain with a software agent that connects to the domain controllers and then reports back to the PAN. We're told this should get us much better results, and son't require us to put an agent on an actual DC.
... View more