Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignHard

A healthcare organization needs to design a User-ID deployment for its Active Directory environment. The requirement is to map IP addresses to usernames for all users, including those connecting via VPN, Wi-Fi, and wired connections, to enable user-based security policies. The solution must ensure high availability and minimize latency. Which combination of User-ID agents and deployment methods would best meet these requirements?

  1. AA single User-ID agent deployed directly on the Palo Alto Networks firewall.
  2. BA dedicated hardware appliance for User-ID, integrated with RADIUS servers.
  3. COne Windows-based User-ID agent deployed centrally.
  4. DMultiple Windows-based User-ID agents deployed in a distributed manner, along with a GlobalProtect User-ID agent.
Show answer & explanation

Correct answer: D. Multiple Windows-based User-ID agents deployed in a distributed manner, along with a GlobalProtect User-ID agent.

To ensure high availability, minimize latency, and cover all user types (wired, Wi-Fi, VPN), a distributed deployment of multiple Windows-based User-ID agents (for wired/Wi-Fi and AD monitoring) combined with the GlobalProtect User-ID agent (for VPN users) is the best approach. Multiple agents provide redundancy and can be placed closer to domain controllers for lower latency.

Why the other options are wrong

  • A. Deploying the User-ID agent directly on the firewall is not scalable for large environments and consumes firewall resources, potentially impacting performance.
  • B. There is no dedicated hardware appliance for User-ID. While RADIUS can be used for authentication, the User-ID agent is still needed for IP-to-user mapping from various sources.
  • C. A single central Windows-based agent introduces a single point of failure and could lead to latency issues for geographically dispersed users.

User-ID Deployment Best Practices

User-ID deployment best practices emphasize distributed agents for high availability, low latency, and comprehensive IP-to-user mapping across various access methods (wired, wireless, VPN).

  • Use multiple User-ID agents for redundancy.
  • Distribute agents close to Domain Controllers.
  • Leverage GlobalProtect for VPN user mapping.
  • Monitor various sources: event logs, Syslog, RADIUS, XFF.

Memory trick: User-ID needs 'MANY' 'SOURCES' to 'MAP' everyone for 'HA'.

More Plan and Design questions