A healthcare organization needs to design a User-ID deployment for its Active Directory environment. The requirement is to map IP addresses to usernames for all users, including those connecting via VPN, Wi-Fi, and wired connections, to enable user-based security policies. The solution must ensure high availability and minimize latency. Which combination of User-ID agents and deployment methods would best meet these requirements?
- AA single User-ID agent deployed directly on the Palo Alto Networks firewall.
- BA dedicated hardware appliance for User-ID, integrated with RADIUS servers.
- COne Windows-based User-ID agent deployed centrally.
- DMultiple Windows-based User-ID agents deployed in a distributed manner, along with a GlobalProtect User-ID agent.
Show answer & explanationAnswer & explanation
Correct answer: D. Multiple Windows-based User-ID agents deployed in a distributed manner, along with a GlobalProtect User-ID agent.
To ensure high availability, minimize latency, and cover all user types (wired, Wi-Fi, VPN), a distributed deployment of multiple Windows-based User-ID agents (for wired/Wi-Fi and AD monitoring) combined with the GlobalProtect User-ID agent (for VPN users) is the best approach. Multiple agents provide redundancy and can be placed closer to domain controllers for lower latency.
Why the other options are wrong
- A. Deploying the User-ID agent directly on the firewall is not scalable for large environments and consumes firewall resources, potentially impacting performance.
- B. There is no dedicated hardware appliance for User-ID. While RADIUS can be used for authentication, the User-ID agent is still needed for IP-to-user mapping from various sources.
- C. A single central Windows-based agent introduces a single point of failure and could lead to latency issues for geographically dispersed users.
User-ID Deployment Best Practices
User-ID deployment best practices emphasize distributed agents for high availability, low latency, and comprehensive IP-to-user mapping across various access methods (wired, wireless, VPN).
- Use multiple User-ID agents for redundancy.
- Distribute agents close to Domain Controllers.
- Leverage GlobalProtect for VPN user mapping.
- Monitor various sources: event logs, Syslog, RADIUS, XFF.
Memory trick: User-ID needs 'MANY' 'SOURCES' to 'MAP' everyone for 'HA'.