Configure Passive identity agent primary and secondary agent deployments

Configure primary and secondary passive identity agents to provide redundancy and avoid a single point of failure in user identity monitoring.

To provide redundancy and to avoid a single point of failure, you can configure primary and secondary passive identity agents in any of the ways shown in this topic.

You can install a passive identity agent on the AD domain controller, directory server, or on any client connected to the domain you wish to monitor.

Procedure


Step 1

For a single AD domain controller with primary and secondary agents deployment:

The following figure shows how to set up primary and secondary passive identity agents on one AD domain controller. If the primary agent fails, the secondary takes over.

The advantage of using primary and secondary passive identity agents is that if the primary agent does not communicate with the Cloud-Delivered Firewall Management Center for any reason, the secondary takes over. You can use other types of deployments (in other words, primary/secondary agents monitoring one AD domain or multiple domains

  1. Create a Microsoft AD realm that has one directory for the domain controller.

  2. Install the passive identity agent software on any two network machines connected to the domain controller.

    Configure each passive identity agent individually to communicate with the Cloud-Delivered Firewall Management Center on which you configure the passive identity agent source.

    See Install the passive identity agent software.

  3. Create the identity source.

Step 2

For multiple AD domain controllers with primary and secondary agents deployment.

An example of primary and secondary agents installed on different AD domain controllers, all sending user IP information to the firewall manager

The preceding figure shows how to configure primary and secondary agents to monitor three AD domain controllers. If the primary agent fails, the secondary agent takes over.

  1. Create a Microsoft AD realm that has one directory for the domain controller.

  2. Install the passive identity agent software on any machine connected to the domain controller.

    Configure each passive identity agent individually to communicate with the Cloud-Delivered Firewall Management Center on which you configure the passive identity agent source.

    See Install the passive identity agent software.

  3. Create the identity source.