Palo Alto Networks Knowledgebase: How to Install the Palo Alto Networks User-ID Agent
How to Install the Palo Alto Networks User-ID Agent
Created On 09/25/18 17:36 PM - Last Updated 07/18/19 20:11 PM
Before installing User-ID, run through the following checklist:
Determine the machine the user-agent will be installed on.
Windows XP, Windows 7, Windows 8 or Windows Server 2003/2008/2012.
Network connectivity to the DCs and to the management port of the firewall.
Be a member of the domain.
Determine which user account can be used by the user-agent to query the domain. This account needs the user right to read the security logs on the domain controllers. The domain admins group has this right, but a new group can be created in AD that has this right added to basic user rights.
Determine which domain (with corresponding domain controllers) the user-agent will be querying. One user-agent is required for each domain and can handle a maximum of 512k users in a domain. From PAN-OS 8.1 we support half a million machine mappings as well. When the limit is reached, the least recently used entry is removed (LRU cache).
Installing and Configuring the User-ID Agent
Select a PC in the domain to install the user-agent software.
Configure the user-agent server to run under a different account than the local system, which is selected by default. This user account must have access to read security logs and netbios probing of other machines. To get to the service: admin tools > service > pan agent > log on > switch from local user to this account, then select the user that will be used for this service.
Restart PAN agent service.
Start user-agent GUI, Start > Programs > Palo Alto Networks > User Identification Agent in the top right corner, then click Configure.
Fill in the following information:
Domain name - FQDN of the domain, for example, acme.com.
Port number of your choosing - any port number not currently used on this machine. Make sure the local machine does not have any firewall that is blocking inbound connections to that port.
Domain controllers ip address - add all the DCs in the domain. Users can be authenticated with any DC in the domain, so you can enter up to 10 IP addresses.
Allow list - subnets that contain users to track.
Ignore list - IP address of the terminal server, any other machines that could potentially have multiple users logged in simultaneously.
If netbios is not allowed on the network, disable netbios probing. For more accurate IP to user mapping support, disable netbios probing.
You can monitor the agent status window in the top left corner, which should display no errors. Other messages:
Please start the PAN agent service first.
Reading domain name\enterprise admins membership.
To confirm that the server running the user-agent is listening on the port configured in Step 8, run the following command on the PC:
netstat -an | find "xxxx"
Configuring the firewall to communicate with the User-ID Agent
Log into the Palo Alto Networks firewall and go to Device > User Identification.
Configure Name, Host (IP address) and Port of the User-ID Agent.
Enable user identification on each zone to be monitored. On the Network > Zone page, edit the appropriate zones. In the bottom left corner of the Zone properties page, check the box to Enable user identification.
Commit the changes.
To confirm connectivity, run this command via CLI of APN firewall: show pan-agent statistics which should return state connected, ok.
To view currently logged in users, run: debug dataplane show user all
To make sure everything is working, create a new security rule. You should be able to select users or groups.