Dell PowerConnect W Clearpass 100 Software Palo Alto Networks User-ID Services - Page 12

Enable Zone Based User Identification, Configuring User-ID Agent Software, Zones, Trust

Page 12 highlights

Enable Zone Based User Identification An additional step is required to enable the User Identification process on the Palo Alto Networks firewall is based on the configuration of the Zones that any interesting traffic with pass through. In our test environment all traffic is passing between the Trust and UnTrust zones so it is these zones whose configuration will need modification. From the Network > Zones menu option, select each Zone in question and ensure the Enable User Identification option shown below is checked. Once you have edited each relevant Zone in your deployment, the summary table should look similar to this with the User Identification feature clearly enabled on each Zone. At this point the configuration of the Palo Alto Networks firewall is complete. For the changes to take affect you must ensure the Commit button is clicked to save the changes. Configuring User-ID Agent Software It is assumed that the Palo Alto Networks User-ID Agent software is already installed on the Windows host discussed in the previous sections. It is a basic windows installer so no additional coverage of the install process will be included here. 12| Palo Alto Networks User-ID Services Amigopod |Technical Note

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20

12
| Palo Alto Networks User-ID Services
Amigopod
|Technical Note
Enable Zone Based User Identification
An additional step is required to enable the User Identification process on the Palo Alto
Networks firewall is based on the configuration of the
Zones
that any interesting traffic
with pass through.
In our test environment all traffic is passing between the
Trust
and
UnTrust
zones so it is
these zones whose configuration will need modification.
From the
Network > Zones
menu option, select each Zone in question and ensure the
Enable
User Identification
option shown below is checked.
Once you have edited each relevant
Zone
in your deployment, the summary table should
look similar to this with the
User Identification
feature clearly enabled on each
Zone.
At this point the configuration of the Palo Alto Networks firewall is complete. For the
changes to take affect you must ensure the Commit button is clicked to save the changes.
Configuring User-ID Agent Software
It is assumed that the Palo Alto Networks User-ID Agent software is already installed on
the Windows host discussed in the previous sections. It is a basic windows installer so no
additional coverage of the install process will be included here.