This tutorial highlights the benefits of using User-ID redistribution and the step-by-step configurations to share user to IP mappings between multiple firewalls and also Panorama.
Does the collector name need to be unique? Or can the same name be pushed to multiple firewalls in the use case of multiple firewalls in a panorama deployment?
In 7.1 one of the limitations was the use of Panorama as a redistribution point : live.paloaltonetworks.com/t5/Configuration-Articles/PAN-OS-7-1-User-ID-enhancements/ta-p/74609
Thanks for the response Kim. So, instead of using Panorama as a redistribution point, could I use a 7.1 firewall as that collection and distribution point?
Thanks again. I am looking at doing this with a master hub for redistribution, but was not ready to move to 8.0 yet. I had not had a chance to view the document before my question. In the document, it does look like I might have a potential issue with redistributing groups and will have to figure out what an LDAP Proxy is, but it gets me to step 1 of User-ID. Again, thank you and the PAN Team for making these videos and replying with answers to help.