Palo Alto Networks Certified Network Security Engineer (PCNSE) flashcards
160 free flashcards. Tap a card to flip it.
Application-Default Service
Flip cardThe 'application-default' service setting in a Palo Alto Networks security policy allows traffic on the standard ports associated with a specified application.
- Simplifies policy creation by mapping apps to common ports.
- Can inadvertently allow unwanted services if not carefully reviewed.
- For granular control, specify custom service objects (e.g., 'tcp/443').
Memory trick: Policy Rules: Order, Source, Dest, App, Service, Action.
Destination NAT (DNAT)
Flip cardDestination Network Address Translation (DNAT) modifies the destination IP address of an incoming packet, commonly used to expose internal services to external networks.
- Used for inbound connections.
- Translates a public IP to a private IP.
- Often paired with security policies to control access.
- Preserves the original source IP by default.
Memory trick: NAT Routes Traffic: Source for Out, Destination for In.
Interface Management Profile
Flip cardAn Interface Management Profile on a Palo Alto Networks firewall controls which services (e.g., SSH, HTTPS) are allowed to access the firewall's management plane from specific zones.
- Applied to interfaces or zones.
- Restricts management access services.
- Enhances firewall security.
Memory trick: Manage interfaces with precise profiles, keeping the firewall's brain safe.
IKE/IPsec Crypto Profiles
Flip cardConfiguration objects that define the cryptographic parameters (encryption, authentication, Diffie-Hellman group, and lifetime) for IKE Phase 1 (IKE Crypto Profile) and IKE Phase 2 (IPsec Crypto Profile) of a VPN tunnel.
- IKE Crypto Profile: Defines Phase 1 security associations (SA).
- IPsec Crypto Profile: Defines Phase 2 security associations (SA).
- Ensures secure key exchange and data encryption for VPNs.
- Must match on both ends of the VPN tunnel for successful establishment.
Memory trick: Crypto Profiles for phases of secure tunnels.
LDAP Authentication Profile
Flip cardAn LDAP Authentication Profile on a Palo Alto Networks firewall defines how the firewall connects to and authenticates users against an LDAP directory service, such as Active Directory.
- Used for user authentication against directories.
- Requires server address, base DN, bind DN, and password.
- Essential for integrating with Active Directory for GlobalProtect.
Memory trick: GlobalProtect needs a 'Look-Up Directory Access Profile' for its remote users.
Log Forwarding Profile
Flip cardA configuration object on a Palo Alto Networks firewall that specifies how logs (traffic, threat, system, etc.) are sent to external destinations such as syslog servers, SNMP managers, or Panorama.
- Defines log types to be forwarded.
- Specifies external destinations (syslog, SNMP, HTTP, email).
- Can filter logs based on severity or other criteria.
- Applied within security policies or other profiles (e.g., URL Filtering).
Memory trick: Logs in, profile out, no more doubt!
Config Log (Configuration Log)
Flip cardThe Config Log on a Palo Alto Networks firewall is an immutable log that records every configuration change, including the administrator who made the change, the timestamp, and the specific parameters that were modified, providing a critical audit trail.
- Records all configuration changes.
- Includes admin, timestamp, and exact changes.
- Immutable and essential for auditability.
Memory trick: The 'Config Log' is the firewall's permanent diary of every change.
DSCP Marking (QoS)
Flip cardA Quality of Service mechanism that modifies the Differentiated Services Code Point field in the IP header to classify and prioritize network traffic.
- Provides a standard way to classify traffic.
- Allows for end-to-end QoS across different network devices.
- Different DSCP values correspond to different per-hop behaviors (PHBs).
- Commonly used for real-time applications like VoIP and video.
Memory trick: DSCP's the stamp, for priority's champ!
NAT Policy Troubleshooting (Outbound)
Flip cardDiagnosing issues where internal hosts cannot reach external resources due to incorrect or missing Network Address Translation (NAT) configurations on the firewall.
- Initial SYN leaves firewall, but no SYN-ACK returns.
- Security policy allows traffic.
- External reachability to destination is verified.
- Commonly indicates missing or misconfigured Source NAT.
Memory trick: SYN goes out, SYN-ACK's a doubt, NAT's the key to figure it out!
Selective Decryption
Flip cardSelective decryption involves configuring decryption policies to only decrypt traffic that requires security inspection, thereby optimizing firewall performance and resource utilization.
- Use 'no-decrypt' rules for non-sensitive, high-bandwidth traffic.
- Policy order is crucial for decryption rules.
- Helps manage CPU load and maintain privacy for certain traffic.
Memory trick: Decrypt Smartly: Skip High-Bandwidth, Prioritize Security.
QoS Policy Rule
Flip cardA QoS Policy Rule on a Palo Alto Networks firewall classifies traffic based on defined criteria and assigns it a specific QoS class or DSCP value, which is then used by interface QoS profiles for prioritization and bandwidth management.
- Classifies traffic based on various attributes.
- Assigns a QoS class or DSCP value.
- Works in conjunction with Interface QoS Profiles.
Memory trick: The 'Quality of Service Policy Rule' is the traffic cop deciding who goes first.
GlobalProtect Satellite Gateway
Flip cardA GlobalProtect Satellite Gateway is a Palo Alto Networks firewall deployed at a remote site with a dynamic public IP address, which registers with a GlobalProtect Portal to enable site-to-site VPN connectivity with other GlobalProtect devices.
- Enables site-to-site VPN for dynamic IP branches.
- Registers with a GlobalProtect Portal.
- Part of a GlobalProtect full mesh or hub-and-spoke VPN solution.
Memory trick: The 'Satellite' finds its Portal 'home' so other branches can find it.
Security Zone
Flip cardA logical grouping of one or more interfaces on a Palo Alto Networks firewall that share common security requirements. Security policies are applied between zones to control traffic flow.
- Fundamental for firewall security policy enforcement.
- Can contain Layer 2, Layer 3, Virtual Wire, or Tap interfaces.
- Traffic between interfaces in the SAME zone is typically allowed by default (inter-zone blocking).
- Traffic between DIFFERENT zones is blocked by default, requiring security policies.
Memory trick: Zone your networks for secure protection.
HA Session Synchronization
Flip cardSession Synchronization in Palo Alto Networks HA ensures that active session states are replicated from the primary to the secondary firewall, allowing for seamless failover of existing connections.
- Crucial for maintaining TCP sessions during failover.
- Uses dedicated HA data link for replication.
- Requires specific configuration and monitoring.
Memory trick: HA Sync: Config for Rules, Session for Connections.
Management Profile
Flip cardA configuration object in Palo Alto Networks firewalls that defines which administrative services (like SSH, HTTPS, SNMP) are allowed on a specific interface and from which source IP addresses.
- Controls access TO the firewall's management plane.
- Applied to specific interfaces (e.g., Management, Ethernet interfaces).
- Includes services like SSH, HTTPS, Ping, SNMP, User-ID agent.
Memory trick: Manage Your Access Points with a Profile.
VLAN Subinterface
Flip cardA VLAN subinterface on a Palo Alto Networks firewall allows a single physical interface to be logically partitioned into multiple interfaces, each handling traffic for a specific VLAN ID and assignable to its own security zone.
- Logical partitioning of a physical interface.
- Each subinterface associated with a VLAN ID.
- Enables distinct security zones and policies per VLAN.
Memory trick: Subinterfaces are 'Split Interfaces' for distinct zones.
Active/Active HA (Palo Alto)
Flip cardA High Availability configuration where both firewalls actively process traffic concurrently, typically for load sharing and increased throughput.
- Both firewalls are active and forward traffic.
- Requires traffic distribution mechanisms (e.g., ECMP, link aggregation).
- Can be deployed in Layer 2 or Layer 3 modes.
- Provides increased throughput and redundancy.
Memory trick: Two active, for throughput's surge, a load-sharing urge!
Static IP NAT (Source)
Flip cardStatic IP NAT (Source) on a Palo Alto Networks firewall maps one or more internal source IP addresses to a consistent, specific public IP address for outbound connections, ensuring a predictable external identity.
- Maps internal IP to a single public IP.
- Used for outbound connections.
- Ensures consistent external IP for internal hosts.
Memory trick: Static IP NAT is the 'Consistent Caller ID' for your internal network.
Palo Alto Networks Virtual Router
Flip cardA Virtual Router on a Palo Alto Networks firewall is a logical routing instance that maintains its own routing table and participates in dynamic routing protocols like OSPF or BGP.
- Interfaces are assigned to a Virtual Router to participate in routing.
- Can run multiple routing protocols simultaneously.
- Default 'VR-Default' is always present.
Memory trick: Virtual Router Routes Traffic, OSPF Learns Paths.
Static DNS Servers (Firewall)
Flip cardStatic DNS Servers configured on a Palo Alto Networks firewall (under Device > Setup > Services > DNS) are used by the firewall itself to resolve hostnames for updates, FQDN objects, and other internal operations.
- Used by the firewall for its own DNS queries.
- Essential for FQDN objects and dynamic updates.
- Configured under Device > Setup > Services > DNS.
Memory trick: The 'Static DNS Servers' are the firewall's own phonebook to the internet.
Virtual Wire Interface
Flip cardA Palo Alto Networks firewall interface type that operates in a transparent Layer 2 mode, allowing the firewall to be inserted into a network segment without requiring changes to the existing network topology.
- Acts as a 'bump-in-the-wire'.
- Does not have an IP address on the data plane.
- Forwards traffic based on MAC addresses.
- Enforces security policies transparently.
Memory trick: Virtual Wire's the ghost, for transparent protection the most!
Dynamic Peer VPN
Flip cardA dynamic peer VPN configuration allows one or both VPN endpoints to have a dynamic public IP address, typically using a FQDN or a 'any' peer ID for identification.
- Essential for branch offices with dynamic IPs.
- Often uses a Dynamic DNS service to update the FQDN.
- Requires specific IKE Gateway configuration for dynamic peers.
Memory trick: VPNs Connect Sites: Route for Dynamic, Policy for Static.
Dynamic IP and Port (DIPP) NAT
Flip cardA NAT type that translates multiple private IP addresses to a single public IP address by using different source port numbers for each connection, also known as Port Address Translation (PAT).
- Enables many-to-one IP address translation.
- Conserves public IP addresses.
- Commonly used for outbound internet access from internal networks.
- Each internal connection gets a unique public IP:Port combination.
Memory trick: DIPP's the key, for many to be, out to the internet, wild and free!
App-ID
Flip cardA Palo Alto Networks technology that identifies applications traversing the firewall, regardless of port, protocol, or evasive tactics.
- Enables application-based security policies.
- Uses multiple classification mechanisms (signatures, decryption, heuristics).
- Provides granular control over application usage.
- Continuously updated through content updates.
Memory trick: App-ID's eye, never lets an unauthorized byte fly!
Palo Alto Networks QoS Policy Rule
Flip cardA QoS Policy Rule on a Palo Alto Networks firewall classifies traffic based on application, user, and other criteria, and applies QoS actions such as marking DSCP values or assigning to a QoS class.
- Similar to security policies in structure and evaluation order.
- Determines which traffic gets prioritized.
- Works in conjunction with QoS Profiles applied to interfaces.
Memory trick: QoS Rules Mark, Profiles Shape, Interfaces Deliver.
Palo Alto Networks Panorama
Flip cardA centralized management system that provides a single console for managing multiple Palo Alto Networks firewalls, deploying consistent policies, and centralizing logs.
- Centralized policy management.
- Centralized logging and reporting.
- Can manage firewalls across different regions.
- Simplifies large-scale firewall deployments.
Memory trick: Panorama's the view, for firewalls old and new!
Security Zones
Flip cardSecurity Zones are logical containers for interfaces that define trust levels and are fundamental for applying security policies.
- Interfaces must belong to a zone to process traffic.
- Policies are applied between zones, not interfaces.
- Common zones include Trust (internal), Untrust (external), DMZ (demilitarized zone).
Memory trick: Zones Guard Access with Logical Boundaries.
Certificate-based Authentication for VPN
Flip cardUsing X.509 digital certificates to mutually authenticate VPN peers, providing strong identity verification and key exchange.
- Provides stronger security than Pre-shared Keys.
- Enables mutual authentication (both sides verify each other).
- Scales better for multiple VPN connections.
- Requires a Public Key Infrastructure (PKI) for certificate management.
Memory trick: Certificates are the key, for a VPN that's truly free!
Syslog Forwarding
Flip cardSyslog forwarding sends firewall logs to an external syslog server (like a SIEM) for centralized storage, analysis, and alerting.
- Standard protocol for log aggregation.
- Can use UDP (port 514) or TCP (port 6514) for transport.
- Configured via Log Forwarding Profiles.
Memory trick: Logs Go to Splunk via Syslog.
External Authentication Profiles
Flip cardPalo Alto Networks firewalls can integrate with external directory services or authentication servers to authenticate users for various services like GlobalProtect, VPNs, or administrator access.
- Supports LDAP, RADIUS, TACACS+, SAML, Kerberos.
- Configured under Device > Authentication Profile.
- Used to centralize user management and authentication.
Memory trick: GlobalProtect Connects with LDAP for AD Users.
SSL Forward Proxy Decryption
Flip cardSSL Forward Proxy Decryption on a Palo Alto Networks firewall intercepts and decrypts outbound HTTPS traffic from internal users to external websites, allowing for security inspection and policy enforcement.
- Inspects outbound HTTPS traffic.
- Requires a trusted root CA certificate on client machines.
- Supports selective decryption/exclusion policies.
Memory trick: Forward Proxy is the 'Outbound Traffic Inspector' with an exclusion VIP list.
SSL Forward Proxy Decryption with Decryption Policy
Flip cardSSL Forward Proxy decrypts outbound encrypted traffic from internal users to external destinations by acting as a man-in-the-middle. A Decryption Policy defines the rules for which traffic to decrypt, block, or exclude from decryption.
- Used for outbound encrypted traffic from internal clients to external servers.
- Requires a Decryption Policy to specify traffic for decryption or exclusion.
- A 'No Decrypt' rule can bypass decryption for specific destinations/sources.
- Requires a Forward Trust Certificate and a Forward Untrust Certificate.
Memory trick: Forward your proxy, then policy the bypass.
QoS Profile
Flip cardA configuration object that defines how traffic is classified, marked, and prioritized based on application, service, or zone to ensure critical applications receive the necessary bandwidth and low latency.
- Classifies traffic using App-ID, Service, or Zone.
- Marks traffic using DSCP or 802.1p.
- Prioritizes traffic into queues for bandwidth management.
- Applied to interfaces where QoS is enabled.
Memory trick: Quality Service for Important Packets.
Layer 3 Interface
Flip cardA network interface configured with an IP address, enabling it to participate in routing and forward traffic between different subnets.
- Has an IP address and subnet mask.
- Can be assigned to a security zone.
- Participates in routing protocols.
- Essential for inter-VLAN routing and connecting to the internet.
Memory trick: Route like a King, with Layer 3's ring!
HA Interface (Control Link)
Flip cardThe HA Interface, or Control Link (HA1), in a Palo Alto Networks firewall HA pair is a dedicated link used for heartbeat messages, configuration synchronization, and most importantly, session state synchronization between the active and passive devices.
- Dedicated link between HA peers.
- Carries heartbeat, config sync, and session sync.
- Essential for active/passive failover.
Memory trick: The 'Heartbeat and Sync Interface' keeps the HA pair beating together.
Palo Alto Networks Subinterface
Flip cardA subinterface is a logical interface associated with a physical interface, configured with a VLAN tag and an IP address to handle traffic for a specific VLAN.
- Enables a single physical port to route multiple VLANs.
- Each subinterface belongs to a security zone.
- Used for 'router-on-a-stick' scenarios on the firewall.
Memory trick: Interfaces: L3 for Route, VWire for Bridge, Sub for VLANs.
Panorama Device Groups
Flip cardDevice Groups in Panorama are logical groupings of managed firewalls that allow for centralized management and targeted deployment of shared policies and objects.
- Used for security policies, NAT policies, objects, and decryption policies.
- Firewalls can belong to multiple device groups.
- Policies are merged from parent to child device groups and then to firewalls.
Memory trick: Panorama Manages with Templates for Device, Groups for Policy.
Application Object (App-ID)
Flip cardAn Application Object, powered by App-ID, represents a specific application recognized by the Palo Alto Networks firewall, allowing security policies to be based on actual application identity rather than just ports and protocols.
- Identifies applications regardless of port.
- Provides granular control over traffic.
- Used in security policy rules to permit or deny applications.
Memory trick: The 'Application Object' is the magnifying glass for specific traffic types.
User-ID Agent Function
Flip cardA software component that gathers user-to-IP address mappings from various sources, primarily Active Directory domain controller event logs, for use by the Palo Alto Networks firewall.
- Monitors Windows security event logs (Event ID 4624 for successful logons).
- Can also use Syslog, Exchange, Terminal Services, and client probes.
- Pushes collected mappings to the Palo Alto Networks firewall.
- Requires appropriate permissions on domain controllers.
Memory trick: Log on, log in, logs are key, for User-ID to truly see!
Active/Passive HA
Flip cardA High Availability configuration where one firewall is active and processes all traffic, while the other is passive and acts as a standby.
- Provides redundancy and fault tolerance.
- Only one firewall is actively passing traffic at any given time.
- The passive firewall synchronizes configuration and session state.
- Failover occurs if the active firewall becomes unavailable.
Memory trick: One works hard, the other guards, ready for the changing cards!
User-ID for Policy Enforcement
Flip cardUser-ID allows Palo Alto Networks firewalls to enforce security policies based on user identity rather than just IP addresses, by mapping IP addresses to usernames.
- Policies applied based on user identity.
- Requires User-ID agent or other mapping methods.
- Enables granular access control.
Memory trick: Source User: User-ID Groups Target People, Not Just IPs.
HA Control Link Configuration
Flip cardThe HA control link is a dedicated physical link between two HA firewalls used for heartbeat, state synchronization, and HA communication. It must be assigned to a zone to be functional.
- Crucial for HA heartbeat and state exchange.
- Typically a direct, dedicated physical link.
- Requires a zone assignment (e.g., Layer 3) to be active, even without an IP on the interface.
Memory trick: HA Heartbeat needs a 'zone' to feel alive, even without an IP address.
Palo Alto Networks HA2 Link
Flip cardThe HA2 link is a dedicated physical connection between two Palo Alto Networks firewalls in an HA pair, used for data-plane synchronization, including session, ARP, and NAT table synchronization.
- Dedicated for data-plane synchronization.
- Must be configured as a Layer 3 interface.
- Requires dedicated IP addresses on both HA peers.
Memory trick: HA1 for Heartbeats, HA2 for Session Sync.
Palo Alto Networks Decryption Policy Order
Flip cardPalo Alto Networks decryption policies are evaluated from top to bottom. More specific 'no-decrypt' rules must be placed above broader 'decrypt' rules to ensure exceptions are correctly handled before general decryption applies.
- Policies evaluated top-down.
- Specific exceptions must be higher in the rulebase.
- Incorrect order can lead to unintended decryption or non-decryption.
Memory trick: Decryption Order: Specific Exclusions FIRST, then General Decrypt.
Palo Alto Networks 'incomplete' Application
Flip cardThe 'incomplete' application in Palo Alto Networks traffic logs signifies that the firewall observed the initial packets of a session but the session did not fully establish (e.g., TCP handshake did not complete), preventing App-ID from identifying the actual application.
- Indicates an unestablished session.
- Often points to routing, server availability, or network path issues.
- App-ID cannot function without a complete session setup.
Memory trick: Incomplete: Handshake Not Done, App-ID Can't Run.
Decryption Logs
Flip cardDecryption logs in Palo Alto Networks firewalls provide detailed information about SSL/TLS decryption events, including successful decryption, decryption failures, and bypassed sessions.
- Crucial for monitoring the health and effectiveness of decryption policies.
- Helps identify applications or websites that cause decryption errors.
- Records reasons for decryption failures (e.g., unsupported cipher, certificate issues).
- Shows sessions explicitly excluded from decryption.
Memory trick: For decryption issues, the decryption log is your best clue.
FQDN Address Object
Flip cardAn FQDN Address Object in Palo Alto Networks firewalls resolves a Fully Qualified Domain Name to its corresponding IP address(es) dynamically for use in security policies.
- Uses DNS resolution to determine IP addresses.
- Automatically updates when DNS records change.
- Essential for controlling access to cloud services or hosts with dynamic IP addresses.
Memory trick: FQDN Address Objects are the best for dynamic cloud connections.
User-ID Server Monitoring
Flip cardUser-ID Server Monitoring involves configuring the Palo Alto Networks firewall or a User-ID agent to query Active Directory domain controllers (using WMI/WinRM) for security event logs to gather user-to-IP address mappings.
- Leverages existing Active Directory infrastructure.
- Does not require client-side agents.
- Provides real-time user-to-IP mapping for policy enforcement.
Memory trick: User-ID maps users like a GPS, and Server Monitoring is the best road map for AD.
Security Policy Rule Order
Flip cardPalo Alto Networks firewalls process security policy rules sequentially from top to bottom, applying the first rule that matches the traffic.
- Rules are evaluated in numerical order, from top to bottom.
- The first matching rule's action (Allow, Deny, Drop) is applied.
- More specific rules should generally be placed above more general rules to avoid unintended blocks or permits.
Memory trick: Top-down processing means the first match wins the traffic's fate.
IKE Phase 1 Diffie-Hellman Group
Flip cardThe Diffie-Hellman (DH) group specified in the IKE Crypto Profile determines the strength of the key exchange used to establish the IKE SA (Phase 1) during VPN tunnel negotiation, and must match between VPN peers.
- Critical for IKE Phase 1 key exchange.
- Must match on both VPN peers.
- Higher group numbers generally offer stronger security.
Memory trick: Phase 1: IKE Crypto Profile needs DH Group Match.
Panorama Reporting
Flip cardPanorama provides robust reporting capabilities, including custom reports that can be filtered and scheduled for automated delivery, enabling comprehensive security visibility and compliance.
- Custom reports allow granular data selection.
- Scheduled reports automate delivery.
- Essential for auditing and operational visibility.
Memory trick: Custom Reports are built to spec, then Scheduled Email delivers them right on time.
Traffic Log Rule Column
Flip cardThe 'Rule' column in Palo Alto Networks traffic logs explicitly displays the name of the security policy rule that was matched and applied to a specific network session.
- Directly identifies the matched security policy rule.
- Crucial for troubleshooting policy-related issues.
- Available for both allowed and denied sessions.
Memory trick: When traffic is denied, the 'Rule' column in logs points fingers.
Palo Alto Networks Log Types
Flip cardPalo Alto Networks firewalls generate various log types to record different events, each serving a specific monitoring and auditing purpose.
- Logs are crucial for troubleshooting and security auditing.
- Each log type captures distinct event categories.
- System logs track firewall operational events and administrative access.
Memory trick: Logs are like specialized diaries, each for a different story.
GlobalProtect HIP
Flip cardHost Information Profile (HIP) is a GlobalProtect feature that collects host security state information, such as OS, patch level, antivirus status, and firewall status, from the connected endpoint.
- Collects endpoint security posture details.
- Used to enforce access based on compliance.
- HIP objects and profiles are configured on the firewall.
Memory trick: HIP checks if your host is 'HIP' enough for the network party.
Least Privilege Security Policy
Flip cardA security principle that dictates that a user, program, or process should be given only the minimum privileges necessary to perform its function, often implemented with specific allow rules followed by a general deny rule.
- Grant only necessary access.
- Minimize attack surface.
- Often implemented with specific 'allow' rules and broad 'deny' rules.
Memory trick: IoT rules: Specific Source, Specific Dest, Specific App, Specific IP, then DENY ALL.
Panorama Templates
Flip cardPanorama Templates are used to manage device-specific configurations (e.g., network settings, device settings, syslog servers) across multiple firewalls, ensuring consistency and simplified management.
- Manage device-level settings.
- Applied to firewalls directly or via Template Stacks.
- Override local firewall settings if configured.
Memory trick: Templates are like blueprints for device settings; Device Groups are where the blueprints are applied.
Application Override
Flip cardAn Application Override is used to force the firewall to identify specific traffic flows as a particular application, bypassing the standard App-ID engine for those flows.
- Useful for custom or internal applications not recognized by App-ID.
- Ensures consistent application identification.
- Takes precedence over standard App-ID signatures.
Memory trick: When App-ID gets confused, check the 'Override' button.
Decryption Policy Order
Flip cardDecryption policies are evaluated in order from top to bottom. To create exceptions (e.g., no-decrypt for specific sites), those exception rules must be placed higher in the policy list than the general decrypt rules.
- Decryption policies follow top-down evaluation.
- 'No-decrypt' rules take precedence over 'decrypt' rules.
- Used to manage SSL/TLS decryption for inspection or exclusion.
Memory trick: Exceptions 'no-decrypt' always go first, like VIPs skipping the security line.
Windows-based User-ID Agent
Flip cardA software agent installed on a Windows server that integrates with Active Directory to collect user login events and map IP addresses to usernames for User-ID functionality.
- Queries Active Directory domain controllers.
- Provides user-to-IP mappings.
- Essential for traditional Windows domain user identification.
Memory trick: User-ID Agents: 'W' for Windows, 'T' for Terminal, 'S' for Syslog, 'G' for Global.
Panorama Device Groups & Templates
Flip cardPanorama's Device Groups manage shared security policies and objects, while Templates manage shared network and device configurations, enabling centralized management with flexible local overrides.
- Device Groups for policies and objects.
- Templates for network and device settings.
- Allow for hierarchical, flexible configuration management.
Memory trick: Panorama: Device Groups for Policies, Templates for Settings.