<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserID mapping flags user unknown with single digit timeout secs in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-mapping-flags-user-unknown-with-single-digit-timeout-secs/m-p/1224060#M5694</link>
    <description>&lt;P&gt;If you are using agentless User id, you can change the timeout value from the user ID setting in the firewall.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Mar 2025 03:58:44 GMT</pubDate>
    <dc:creator>Edsnow</dc:creator>
    <dc:date>2025-03-18T03:58:44Z</dc:date>
    <item>
      <title>UserID mapping flags user unknown with single digit timeout secs</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-mapping-flags-user-unknown-with-single-digit-timeout-secs/m-p/1223942#M5690</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using Agentless UserID mapping. Since past 2 weeks, random users are dropped out of ip-user-mapping and unable to browse internet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I run "show user ip-user-mapping all" on CLI:&lt;/P&gt;
&lt;P&gt;I get 90% of connected AD users mapped to IP addresses but rest of the 10% users are logged as below -&lt;/P&gt;
&lt;P&gt;IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|&amp;nbsp; Vsys | From | User&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| IdleTimeout(s) | MaxTimeout(s)&lt;/P&gt;
&lt;P&gt;192.168.2.27&amp;nbsp; |&amp;nbsp; vsys1 |&amp;nbsp; AD&amp;nbsp; |&amp;nbsp; &amp;nbsp;unknown&amp;nbsp; unknown&amp;nbsp; &amp;nbsp;|&amp;nbsp; 1&amp;nbsp; &amp;nbsp;|&amp;nbsp; 4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I verified that the subnet is included, clocks are synced with correct NTP, LDAP &amp;amp; Kerberos server works fine. Server-Monitor are "Connected" and below when run "show user server-monitor state all" -&lt;/P&gt;
&lt;P&gt;UDP Syslog Listener Service is disabled&lt;BR /&gt;SSL Syslog Listener Service is disabled&lt;/P&gt;
&lt;P&gt;Server: &amp;lt;server1.domain.com&amp;gt; (vsys: vsys1) (job 4132013)&lt;BR /&gt;Host: 192.168.0.31&lt;BR /&gt;num of log query made : 15272&lt;BR /&gt;num of log query failed : 144&lt;BR /&gt;num of log read : 478509&lt;BR /&gt;last record timestamp : 1742182760&lt;BR /&gt;last record time : 20250317033920.0-000&lt;/P&gt;
&lt;P&gt;Server: &amp;lt;server2.domain.com&amp;gt;(vsys: vsys1) (job 4132059)&lt;BR /&gt;Host: 192.168.0.41&lt;BR /&gt;num of log query made : 28536&lt;BR /&gt;num of log query failed : 144&lt;BR /&gt;num of log read : 0&lt;BR /&gt;last record timestamp : 0&lt;BR /&gt;last record time :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see the successful User Logon events (event ID 4624) on the AD server for that specific IP address and device. Since they can access local resources and file server I don't think AD has any issues authenticating the users. Should I be looking for any specific flag that could cause the delay?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The VPN/GloalProtect connects these same users seamlessly but it is disrupting the business tasks on corporate network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any response or tip is highly appreciated, since Level-2/3 Support Engineer is also unable to help me on this one.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 03:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-mapping-flags-user-unknown-with-single-digit-timeout-secs/m-p/1223942#M5690</guid>
      <dc:creator>rshetye</dc:creator>
      <dc:date>2025-03-17T03:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: UserID mapping flags user unknown with single digit timeout secs</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-mapping-flags-user-unknown-with-single-digit-timeout-secs/m-p/1224060#M5694</link>
      <description>&lt;P&gt;If you are using agentless User id, you can change the timeout value from the user ID setting in the firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 03:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-mapping-flags-user-unknown-with-single-digit-timeout-secs/m-p/1224060#M5694</guid>
      <dc:creator>Edsnow</dc:creator>
      <dc:date>2025-03-18T03:58:44Z</dc:date>
    </item>
  </channel>
</rss>

