02-13-2018 12:38 PM - edited 02-21-2020 07:20 AM
I'm in process of learning and implementing the user agent solution for AD dealing with Firepower Identity management.
Reading in the directions, the user agent can handle 5 Domain Controllers. My environment has no less than 8 DC's. Will I have to spin up 2 separate servers? Or can I install multiple agents on 1 OS instance?
Thanks,
02-14-2018 07:34 AM - edited 02-14-2018 07:35 AM
There's no need to spin up any new servers. The agent is pretty lightweight.
Just run an instance on on DC #1 with the local plus 4 remote DCs being polled = 5 DCs.
Then a second instance on DC #6 with the local plus the other two remote DCs = 3 DCs.
02-14-2018 07:47 AM
So, you are just recommending installing directly on the DC's?
I was going through the documentation and read this .... "For security reasons, we recommend you install the user agent on a domain computer and not on the Active Directory server computer."
Considering we are in the security business, I was going to spin up a couple of VM's. I'll look into what those risks might be and perhaps these risks can be acceptable.
Thank you very much for your input as I will be looking at all the options.
02-14-2018 07:55 AM
I've always installed them either on a DC (80% of the time or more) or other existing server. I have never asked a customer to spin a whole server just to run this one little program.
I'm not sure what the rationale for saying a program that queries the server event log for user logon/logoff events and stores them in a small database ads security risk when installed on the DC it queries.
02-14-2018 08:03 AM
02-15-2018 06:43 AM
How would we or do we implement HA with the agents?
Currently we do have HA for the FMC's, and if we decide to go the route of installing the agent on each DC, then I think we are covered. However, in the event we have to stand up VM's with agents installed on them, what's the best path to take to implement HA with those agents?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide