Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Arrow up icon
GO TO TOP
Mastering Palo Alto Networks

You're reading from   Mastering Palo Alto Networks The complete journey to firewall mastery from setup to advanced security

Arrow left icon
Product type Paperback
Published in May 2025
Publisher Packt
ISBN-13 9781836644811
Length 646 pages
Edition 3rd Edition
Concepts
Arrow right icon
Author (1):
Arrow left icon
Tom Piens aka  'reaper' Tom Piens aka 'reaper'
Author Profile Icon Tom Piens aka 'reaper'
Tom Piens aka 'reaper'
Arrow right icon
View More author details
Toc

Table of Contents (19) Chapters Close

Preface 1. Understanding the Core Technologies FREE CHAPTER 2. Setting up a New Device 3. Building Strong Policies 4. Taking Control of Sessions 5. Services and Operational Modes 6. Identifying Users and Controlling Access 7. Managing Firewalls Through Panorama 8. Managing Firewalls Through Strata Cloud Manager 9. Upgrading Firewalls and Panorama 10. Logging and Reporting 11. Virtual Private Networks (VPNs) 12. Advanced Protection 13. Troubleshooting Common Session Issues 14. A Deep Dive Into Troubleshooting 15. Cloud-Based Firewall Deployment 16. Other Books You May Enjoy 17. Index
Appendix

User-ID basics

In this section, we will learn how to set up the basics needed to identify users by preparing AD and configuring the agent/agentless configuration to collect user-to-IP mappings.

One universal truth is that for User-ID to work, the interface that receives connections from the users that need to be identified needs to have User-ID enabled in its zone. Navigate to Network | Zones and click Enable User Identification in the appropriate zone, as you can see in the following screenshot:

Figure 6.1: User-ID in a zone

Figure 6.1: User-ID in a zone

This setting needs to be active in local zones, or remote zones (such as VPNs) that receive user sessions, but should not be enabled for untrusted zones such as internet uplinks. For each source IP in a User-ID-enabled zone, the firewall will try to create a record for user-to-IP mapping. If User-ID is enabled in an outside-facing zone, the available table space may get flooded with empty (random internet background noise) user-to-IP mappings...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at AU $24.99/month. Cancel anytime