PCNSE · Question #749
A customer wants to deploy User-ID on a Palo Alto Networks NGFW with multiple vsys. One of the vsys will support a GlobalProtect portal and gateway. The customer uses Windows Active Directory for auth
The correct answer is B. Deploy the GlobalProtect vsys as a User-ID data hub. When a multi-vsys firewall has one vsys running GlobalProtect, that vsys receives the most accurate IP-to-username mappings directly from VPN authentication. Designating it as a User-ID data redistribution hub (data hub) allows all other vsys to pull those mappings centrally with
Question
A customer wants to deploy User-ID on a Palo Alto Networks NGFW with multiple vsys. One of the vsys will support a GlobalProtect portal and gateway. The customer uses Windows Active Directory for authentication. What is the most operationally efficient way to redistribute the most accurate IP addresses to username mappings?
Options
- ADeploy a PAN-OS integrated User-ID agent on each vsys
- BDeploy the GlobalProtect vsys as a User-ID data hub
- CDeploy a M-200 as a User-ID collector
- DDeploy Windows User-ID agents on each domain controller
How the community answered
(44 responses)- A5% (2)
- B73% (32)
- C7% (3)
- D16% (7)
Explanation
When a multi-vsys firewall has one vsys running GlobalProtect, that vsys receives the most accurate IP-to-username mappings directly from VPN authentication. Designating it as a User-ID data redistribution hub (data hub) allows all other vsys to pull those mappings centrally without deploying separate agents on every vsys. Option A is less efficient because it requires configuring an agent per vsys independently. Option C (M-200) is a management appliance, not a User-ID collector. Option D (Windows agents on domain controllers) collects AD login events but is less accurate than GlobalProtect mappings and doesn't solve the multi-vsys redistribution problem as cleanly as a data hub.
Topics
Community Discussion
No community discussion yet for this question.