User-ID Agent Comparison

PAN-OS Integrated User-ID Agent (Agentless)

The Integrated User-ID Agent is built into the PAN-OS firewall and collects user-to-IP mapping information directly from directory services without requiring additional software installation.

Advantages:

Considerations:

graph TD A[Firewall with Integrated User-ID Agent] --> B[Queries Directory Services] B --> C[Retrieves User-to-IP Mappings]

Windows-Based User-ID Agent (Agent-Based)

The Windows-Based User-ID Agent is installed on a Windows server and collects user-to-IP mapping information from directory services, forwarding it to the firewall.

Advantages:

Considerations:

graph TD A[Windows Server with User-ID Agent] --> B[Collects User-to-IP Mappings] B --> C[Forwards Mappings to Firewall]

Decision Criteria

Choosing between the Integrated and Windows-Based User-ID Agents depends on various factors: