Alto MS Series User Manual Page 79

  • Download
  • Add to my manuals
  • Print
  • Page
    / 108
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 78
Getting Started Guide 75
Configure User Identification Enable User Identification
Step 2 Define the servers the firewall should
monitor to collect IP address to user
mapping information. You can define
entries for up to 100 Microsoft Active
Directory, Microsoft Exchange, or Novell
eDirectory servers on your network.
Keep in mind that in order to collect all of
the required mappings, you must connect
to all servers that your users log in to so
that the firewall can monitor the security
log files on all servers that contain logon
events.
1. Select
Device > User Identification > User Mapping.
2. In the
Server Monitor section of the screen, click Add.
3. Enter a
Name and Network Address for the server. The
network address can be a FQDN or an IP address.
4. Select the
Type of server.
5. Make sure the
Enabled check box is selected and then click OK
6. (Optional) To enable the firewall to automatically discover
domain controllers on your network using DNS lookups, click
Discover.
Note The auto-discovery feature is for domain controllers only;
you must manually add any Exchange servers or eDirectory
servers you want to monitor.
7. (Optional) To tune the frequency at which the firewall polls
configured servers for mapping information, in the
Palo Alto
Networks User ID Agent Setup
section of the screen, click the
Edit icon and then select the
Server Monitor tab. Modify
the value in the
Server Log Monitor Frequency (sec) field.
Best Practice:
You should increase the value in the
Server Log Monitor
Frequency (sec)
field to 5 seconds in environments with older
DCs or high-latency links.
8. Click
OK to save the changes.
Step 3 Set the domain credentials for the account
the firewall will use to access Windows
resources. This is required for monitoring
Exchange servers and domain controllers
as well as for WMI probing.
1. Click the Edit icon in the
Palo Alto Networks User ID Agent
Setup
section of the screen.
2. On the
WMI Authentication tab, enter the User Name and
Password for the account that will be used to probe the clients
and monitor servers. Enter the user name using the
domain\username syntax.
Map IP Addresses to Users Using the PAN-OS Integrated User-ID Agent (Continued)
Page view 78
1 2 ... 74 75 76 77 78 79 80 81 82 83 84 ... 107 108

Comments to this Manuals

No comments