Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard

A company is integrating its Palo Alto Networks firewall with Active Directory to enforce user-based security policies. After initial setup, the administrator notices that policies configured with 'Source User' criteria are not matching correctly, and traffic logs show 'unknown' for the user. The User-ID agent is confirmed to be running on the domain controller. What is the next logical step to troubleshoot why user-to-IP mappings are not being correctly acquired by the firewall?

  1. AEnsure App-ID is correctly identifying the applications in use.
  2. BConfirm that the User-ID agent is configured to monitor the correct event logs on the domain controller.
  3. CVerify that the security policy rule order is correct.
  4. DCheck the firewall's network connectivity to the User-ID agent and Active Directory.
Show answer & explanation

Correct answer: B. Confirm that the User-ID agent is configured to monitor the correct event logs on the domain controller.

Even if the User-ID agent is running, it must be configured to monitor the specific event logs (e.g., security event logs for successful logins) on the domain controller to collect user-to-IP mappings. If it's not monitoring the correct logs or the logs are not enabled, no mappings will be sent to the firewall, resulting in 'unknown' users. This is a common misconfiguration for a running agent.

Why the other options are wrong

  • A. App-ID identifies applications, not users. It's irrelevant to why user-to-IP mappings are 'unknown'.
  • C. Rule order affects policy enforcement, but not the acquisition of user-to-IP mappings themselves. 'Unknown' user indicates a mapping issue first.
  • D. While network connectivity is crucial, the stem states the agent is 'running on the domain controller', implying basic connectivity. The problem is more specific to data collection by the agent.

User-ID Agent Configuration

The User-ID agent must be properly configured to monitor specific event logs on domain controllers to collect and send user-to-IP mapping information to the Palo Alto Networks firewall.

  • Monitors Windows security event logs (4624 for successful logins).
  • Requires appropriate permissions on the domain controller.
  • Firewall polls the agent for mappings or the agent pushes them.

Memory trick: Agent's Eyes: Event Logs for User IDs.

More Security Policy Configuration questions