<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Redistribution Agent : Close Connection to Agent in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583057#M2956</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132284"&gt;@WillyHarivonjy&lt;/a&gt;&amp;nbsp;Did yours just start happening in the last few days? Cause Im assuming you need to update your firewalls and/or user id agent(s)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer to customer advisory:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/additional-pan-os-certificate-expirations-and-new-comprehensive/ta-p/572158" target="_blank"&gt;LIVEcommunity - Additional PAN-OS Certificate Expirations and New, Comprehensive Certificate Management Process - LIVEcommunity - 572158 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2024 15:16:09 GMT</pubDate>
    <dc:creator>Claw4609</dc:creator>
    <dc:date>2024-04-09T15:16:09Z</dc:date>
    <item>
      <title>User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/564445#M2053</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I am getting high severity alerts for user id connection agent Failure - Redistribution Agent &amp;lt;Agent Name&amp;gt; (Vsys1):Close Connection to Agent. Would appreciate if anyone can help me understand the log to check if the issue occurred&amp;nbsp;due to firewall or by someone did it manually.&amp;nbsp; If occurred on its own, then what could be the reason.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When i checked the user agent status, They are connected &amp;amp; reachable through ping as well.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;While checking the useridd.logs, i could observe below errors.&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;2023-10-27 10:02:53.327 +0700 Error:&amp;nbsp; pan_user_id_agent_send_and_recv_msgs(pan_user_id_agent.c:4126): pan_user_msgs_recv() failed&lt;BR /&gt;2023-10-27 10:02:53.327 +0700 Error:&amp;nbsp; pan_user_id_agent_uia_proc_v5(pan_user_id_uia_v5.c:1254): pan_user_id_agent_send_and_recv_msgs() failed for &amp;lt;Agent Name&amp;gt;&lt;BR /&gt;2023-10-27 10:02:53.327 +0700 Error:&amp;nbsp; pan_user_id_agent_send_and_recv_msgs(pan_user_id_agent.c:4126): pan_user_msgs_recv() failed&lt;BR /&gt;2023-10-27 10:02:53.327 +0700 Error:&amp;nbsp; pan_user_id_agent_uia_proc_v5(pan_user_id_uia_v5.c:1254): pan_user_id_agent_send_and_recv_msgs() failed for &amp;lt;Agent Name&amp;gt;&lt;BR /&gt;2023-10-27 10:02:53.327 +0700 [agent name] useridd notify dist to reconnect&lt;BR /&gt;2023-10-27 10:02:53.327 +0700 [agent name] useridd notify dist to reconnect&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;While checking the distributord.logs, i could observe below errors.&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;2023-10-27 10:02:53.327 +0700 [agent My_Agent]vsys1 useridd requests reconnection&lt;BR /&gt;2023-10-27 10:02:53.328 +0700 [agent My_Agent] reset version to 6 to reconnect&lt;BR /&gt;2023-10-27 10:02:53.328 +0700 [agent My_Agent]vsys2 useridd requests reconnection&lt;BR /&gt;2023-10-27 10:02:53.328 +0700 2023-10-27 10:02:53.328 +0700 [agent My_Agent] reset version to 6 to reconnect&lt;BR /&gt;Error:&amp;nbsp; pan_distributor_agents_proc(pan_distributor_agent.c:3246): hasn't heard from My_Agent(1) for 540798 seconds&lt;BR /&gt;2023-10-27 10:02:53.328 +0700 Error:&amp;nbsp; pan_distributor_agents_proc(pan_distributor_agent.c:3246): hasn't heard from My_Agent(2) for 540798 seconds&lt;BR /&gt;2023-10-27 10:02:58.058 +0700 2023-10-27 10:02:58.058 +0700 [agent My_Agent] DCOM_SSL_CLNT_CONFIG&lt;BR /&gt;[agent My_Agent] DCOM_SSL_CLNT_CONFIG&lt;BR /&gt;2023-10-27 10:02:58.062 +0700 2023-10-27 10:02:58.062 +0700 [agent My_Agent] no service route available. Use default.&lt;BR /&gt;[agent My_Agent] no service route available. Use default.&lt;BR /&gt;2023-10-27 10:02:58.062 +0700 2023-10-27 10:02:58.062 +0700 add new conn My_Agent to dcom, fd = 1027, addr = ssl@X.X.X.X#5007&lt;BR /&gt;add new conn My_Agent to dcom, fd = 1028, addr = ssl@X.X.X.X#5007&lt;BR /&gt;2023-10-27 10:02:58.062 +0700 conn My_Agent is not connected.&lt;BR /&gt;2023-10-27 10:02:58.062 +0700 2023-10-27 10:02:58.062 +0700 conn My_Agent is not connected.&lt;BR /&gt;add socket fd 1027(My_Agent) into epoll 2 [prev total fds: 0, jobid: 0].&lt;BR /&gt;2023-10-27 10:02:58.062 +0700 add socket fd 1028(My_Agent) into epoll 3 [prev total fds: 0, jobid: 0].&lt;BR /&gt;2023-10-27 10:02:58.062 +0700 agent My_Agent didn't establish secure communication yet&lt;BR /&gt;2023-10-27 10:02:58.062 +0700 agent My_Agent didn't establish secure communication yet&lt;BR /&gt;2023-10-27 10:02:58.062 +0700 2023-10-27 10:02:58.062 +0700 pan_dcom_epoll: start epoll thread 3 at 1698375778(epoch: 1698375778)&lt;BR /&gt;pan_dcom_epoll: start epoll thread 2 at 1698375778(epoch: 1698375778)&lt;BR /&gt;2023-10-27 10:02:58.083 +0700 [agent My_Agent] DCOM_SSL_CLNT_PRE_CONN&lt;BR /&gt;2023-10-27 10:02:58.085 +0700 [agent My_Agent] DCOM_SSL_CLNT_PRE_CONN&lt;BR /&gt;2023-10-27 10:02:59.660 +0700 Error:&amp;nbsp; pan_dcom_ssl_connect(pan_dcom_ssl.c:331): conn My_Agent: SSL_connect return -1&lt;BR /&gt;2023-10-27 10:02:59.660 +0700 Error:&amp;nbsp; pan_dcom_ssl_connect(pan_dcom_ssl.c:332): SSL :error:00000000:lib(0):func(0):reason(0)&lt;BR /&gt;2023-10-27 10:02:59.660 +0700 Error:&amp;nbsp; pan_dcom_app_notify_callback(pan_dcom_sock.c:450): conn My_Agent failed in ssl notify&lt;BR /&gt;2023-10-27 10:02:59.660 +0700 conn My_Agent is not connected yet, err = 0&lt;BR /&gt;2023-10-27 10:02:59.660 +0700 close socket fd 1027(My_Agent)&lt;BR /&gt;2023-10-27 10:02:59.660 +0700 close conn My_Agent, same thread 0, b_notifying 0&lt;BR /&gt;2023-10-27 10:02:59.660 +0700 conn My_Agent has been closed by application[event=6]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;System Logs:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;2023/10/27 10:04:16 high&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; userid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; connect 0&amp;nbsp; Redistribution Agent My_Agent(vsys2):&amp;nbsp; details: close connection to agent&lt;BR /&gt;2023/10/27 10:04:16 high&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; userid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; connect 0&amp;nbsp; Redistribution Agent My_Agent(vsys1):&amp;nbsp; details: close connection to agent&lt;BR /&gt;2023/10/27 10:04:11 info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; userid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disconn 0&amp;nbsp; User-ID-Agent My_Agent disconnected: IP X.X.X.X, port 5007 vsys2&lt;BR /&gt;2023/10/27 10:04:11 info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; userid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disconn 0&amp;nbsp; User-ID-Agent My_Agent disconnected: IP X.X.X.X, port 5007 vsys1&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 04:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/564445#M2053</guid>
      <dc:creator>tanmay_lemoriya</dc:creator>
      <dc:date>2023-11-06T04:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/564842#M2066</link>
      <description>&lt;P&gt;Hi &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/318141"&gt;@tanmay.lemoriya&lt;/a&gt;&lt;/SPAN&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please follow the steps in this &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000Cr9GCAS&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;KB&lt;/A&gt; to troubleshoot.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 17:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/564842#M2066</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-11-08T17:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/573435#M2465</link>
      <description>did t get resolved if so how ?</description>
      <pubDate>Thu, 18 Jan 2024 05:56:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/573435#M2465</guid>
      <dc:creator>Rahul.Balan</dc:creator>
      <dc:date>2024-01-18T05:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/573436#M2466</link>
      <description>&lt;P&gt;did t get resolved if so how ?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 05:56:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/573436#M2466</guid>
      <dc:creator>Rahul.Balan</dc:creator>
      <dc:date>2024-01-18T05:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/573438#M2467</link>
      <description>&lt;P&gt;The issue is still there &amp;amp; not resolved.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 06:16:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/573438#M2467</guid>
      <dc:creator>tanmay_lemoriya</dc:creator>
      <dc:date>2024-01-18T06:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583053#M2955</link>
      <description>&lt;P&gt;Hi, did you get to resolve this issue? I have the same behavior on my side try some steps but still having the issue.&lt;/P&gt;
&lt;P&gt;Seems to be related to the certificate but not sure.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 14:55:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583053#M2955</guid>
      <dc:creator>WillyHarivonjy</dc:creator>
      <dc:date>2024-04-09T14:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583057#M2956</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132284"&gt;@WillyHarivonjy&lt;/a&gt;&amp;nbsp;Did yours just start happening in the last few days? Cause Im assuming you need to update your firewalls and/or user id agent(s)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer to customer advisory:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/additional-pan-os-certificate-expirations-and-new-comprehensive/ta-p/572158" target="_blank"&gt;LIVEcommunity - Additional PAN-OS Certificate Expirations and New, Comprehensive Certificate Management Process - LIVEcommunity - 572158 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:16:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583057#M2956</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-04-09T15:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583058#M2957</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;This is a new deployment, I have the same software version on all my managed firewalls. And I only have the issue on 4 clusters out of 45 clusters. I think I'm not impacted by this article.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:26:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583058#M2957</guid>
      <dc:creator>WillyHarivonjy</dc:creator>
      <dc:date>2024-04-09T15:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583059#M2958</link>
      <description>&lt;P&gt;What PAN-OS version are you using? And are you using the built-in user-id agent or are you using the Windows user-id agent? If the Windows user-id agent, what version are you using?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583059#M2958</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-04-09T15:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583070#M2960</link>
      <description>&lt;P&gt;Ok, my&lt;/P&gt;
&lt;P&gt;- Panorama is on PanOS 10.2.8,&lt;/P&gt;
&lt;P&gt;- all managed devices are on PanOS version 10.1.11-h4 (this is affected by the certificate advisory) but they have the last dynamic updates that replace the certificate with the one that expires on November 2024 as per this article&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/additional-pan-os-certificate-expirations-and-new-comprehensive/ta-p/572158" target="_blank"&gt;https://live.paloaltonetworks.com/t5/customer-advisories/additional-pan-os-certificate-expirations-and-new-comprehensive/ta-p/572158&lt;/A&gt;&lt;BR /&gt;- all managed firewalls are rebooted as per the recommendation on the certificate advisory, we expect to upgrade all firewalls to the target version that fixes the certificate expiration permanently before Nov 2024&lt;/P&gt;
&lt;P&gt;- All managed firewall redistribute their user-id mapping to the Panorama and then the Panorama acts as a redistribution collector and shares all collected user-id to other firewalls.&lt;/P&gt;
&lt;P&gt;-&amp;nbsp; So basically, each firewall acts as a user-id agent for the Panorama, and the Panorama also acts as a user-id agent for some sites as it collects all user-ip mapping for several sites&lt;/P&gt;
&lt;P&gt;- The issue is some sites can connect to the Panorama as redistribution agents but some of them are not, on the logs the issue is related to SSL communication :&lt;/P&gt;
&lt;P&gt;2024-04-09 16:26:15.820 +0200 Error: pan_dcom_ssl_read(pan_dcom_ssl.c:399): conn firewall01: SSSL_read() read a closure alert, nread 0 err 6&lt;/P&gt;
&lt;P&gt;2024-04-09 16:26:15.820 +0200 Error: pan_dcom_ssl_write(pan_dcom_ssl.c:450): conn firewall01: ssl return 6, disconnect it&lt;BR /&gt;2024-04-09 16:26:15.820 +0200 Error: pan_dcom_sock_xmit(pan_dcom_sock.c:1423): failed to send message on firewall01, len = 2, err -1&lt;BR /&gt;2024-04-09 16:26:15.820 +0200 Error: pan_dcom_ssl_write(pan_dcom_ssl.c:449): SSL :error:1409F07F:SSL routines:ssl3_write_pending:bad write retry&lt;BR /&gt;2024-04-09 16:26:15.820 +0200 Error: pan_dcom_ssl_write(pan_dcom_ssl.c:450): conn firewall01: ssl return 1, disconnect it&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:51:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/583070#M2960</guid>
      <dc:creator>WillyHarivonjy</dc:creator>
      <dc:date>2024-04-09T15:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Redistribution Agent : Close Connection to Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/1243711#M6510</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;Did this get solved? If so, how?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 12:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-redistribution-agent-close-connection-to-agent/m-p/1243711#M6510</guid>
      <dc:creator>J.Makhoul</dc:creator>
      <dc:date>2025-12-11T12:40:32Z</dc:date>
    </item>
  </channel>
</rss>

