To map usernames to IP addresses, User-ID agents monitor
various sources, such as directory servers. The agents send the
user mappings to firewalls, Log Collectors, or Panorama and each
of these appliances can then serve as
forward the mappings to other firewalls, Log Collectors, or Panorama.
For a firewall (
or Panorama (
) to collect user mappings,
you must configure its connections to the User-ID agents or redistribution
To configure Dedicated Log Collectors to connect to User-ID
agents or redistribution points, define User-ID
Agent Settings. You cannot configure local Log Collectors
to connect to User-ID agents or redistribution points.
you can configure a Log Collector or Panorama to redistribute user mappings,
these devices cannot map IP addresses to usernames. Only Windows-based
User-ID agents and PAN-OS integrated User-ID agents can perform
The complete procedure to configure user mapping
requires additional tasks besides
configuring connections to User-ID agents.