Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A company is implementing User-ID on their Palo Alto Networks firewall to provide user-based security policies. After configuring the User-ID agent to monitor their Active Directory domain controllers, the administrator notices that user-to-IP mappings are not being populated on the firewall. Which of the following is a common reason for this issue?
- AThe security policy allowing traffic from the User-ID agent to the firewall is missing.
- BThe firewall's management interface is not in the 'trusted' zone.
- CThe User-ID agent is not configured to monitor security event logs on the domain controllers.
- DThe firewall is not configured with a default route.
Show answer & explanationAnswer & explanation
Correct answer: C. The User-ID agent is not configured to monitor security event logs on the domain controllers.
The User-ID agent primarily collects user-to-IP mappings by monitoring security event logs (specifically successful logon events) on domain controllers. If this monitoring is not configured, mappings will not be populated.
Why the other options are wrong
- A. While a security policy is needed for communication, the question implies communication issues between the agent and DC, not directly agent to firewall for mapping collection itself. The core issue is the collection mechanism.
- B. The management interface's zone is not directly related to the User-ID agent's ability to collect mappings from DCs, though connectivity is required.
- D. A missing default route would affect general network connectivity, not specifically the User-ID agent's ability to collect mappings from domain controllers.
User-ID Agent Function
A software component that gathers user-to-IP address mappings from various sources, primarily Active Directory domain controller event logs, for use by the Palo Alto Networks firewall.
- Monitors Windows security event logs (Event ID 4624 for successful logons).
- Can also use Syslog, Exchange, Terminal Services, and client probes.
- Pushes collected mappings to the Palo Alto Networks firewall.
- Requires appropriate permissions on domain controllers.
Memory trick: Log on, log in, logs are key, for User-ID to truly see!