<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Errors with Data Redistribution (User-ID Agent) on Labs Environment in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-with-data-redistribution-user-id-agent-on-labs/m-p/1233724#M6085</link>
    <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am searching Palo Alto User-ID configuration and build Labs on EVE-NG use Palo Alto KVM.&lt;/P&gt;
&lt;P&gt;Now I can set up LDAP and Group Mapping , it's working.&lt;/P&gt;
&lt;P&gt;But I can not set up Data Redistribution, Connection between Firewall and User-ID Agent is &lt;STRONG&gt;No. (Connected No, log as bellow). I created Certificate and add it to Agent already.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I am using PanOS 10.2.8 and Agent 10.2.4 running Window Server 2016&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please help !&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2025-07-10 19:47:32.086 +0700 pan_dcom_epoll: start epoll thread 1 at 1752151652(epoch: 1752151652)&lt;BR /&gt;2025-07-10 19:47:35.000 +0700 close socket fd 1026(UIA-test)&lt;BR /&gt;2025-07-10 19:47:35.000 +0700 Error: pan_distributor_agent_dcom_callback(pan_distributor_agent.c:2026): agent UIA-test is reset, event:1, abort:0, reset:1&lt;BR /&gt;2025-07-10 19:47:35.001 +0700 conn UIA-test is not connected.&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 close conn UIA-test, same thread 0, b_notifying 0&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 conn UIA-test has been closed by application[event=6]&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 release conn UIA-test, notify=1&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 close socket fd 1026(UIA-test)&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 no work in epoll index 1&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 pan_dcom_epoll: quit, index = 1, now=1752151655(epoch: 1752151655)&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 [agent UIA-test] DCOM_SSL_CLNT_CONFIG&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 [secure_conn] pan_distributor_sec_conn_load_custom_server_cert()&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 [secure_conn] RSA key&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 [secure_conn] Custom client ssl certificate loaded&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 add new conn UIA-test to dcom, fd = 1026, addr = ssl@10.10.10.10#5007&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 conn UIA-test is not connected.&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 add socket fd 1026(UIA-test) into epoll 1 [prev total fds: 0, jobid: 0].&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 agent UIA-test didn't establish secure communication yet&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 pan_dcom_epoll: start epoll thread 1 at 1752151660(epoch: 1752151660)&lt;BR /&gt;2025-07-10 19:47:43.004 +0700 close socket fd 1026(UIA-test)&lt;BR /&gt;2025-07-10 19:47:43.004 +0700 Error: pan_distributor_agent_dcom_callback(pan_distributor_agent.c:2026): agent UIA-test is reset, event:1, abort:0, reset:1&lt;BR /&gt;2025-07-10 19:47:43.005 +0700 conn UIA-test is not connected.&lt;BR /&gt;2025-07-10 19:47:43.005 +0700 close conn UIA-test, same thread 0, b_notifying 0&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 conn UIA-test has been closed by application[event=6]&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 release conn UIA-test, notify=1&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 close socket fd 1026(UIA-test)&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 no work in epoll index 1&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 pan_dcom_epoll: quit, index = 1, now=1752151663(epoch: 1752151663)&lt;BR /&gt;2025-07-10 19:47:48.036 +0700 [agent UIA-test] DCOM_SSL_CLNT_CONFIG&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 [secure_conn] pan_distributor_sec_conn_load_custom_server_cert()&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 [secure_conn] RSA key&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 [secure_conn] Custom client ssl certificate loaded&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 add new conn UIA-test to dcom, fd = 1026, addr = ssl@10.10.10.10#5007&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 conn UIA-test is not connected.&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 add socket fd 1026(UIA-test) into epoll 1 [prev total fds: 0, jobid: 0].&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 agent UIA-test didn't establish secure communication yet&lt;BR /&gt;2025-07-10 19:47:48.038 +0700 pan_dcom_epoll: start epoll thread 1 at 1752151668(epoch: 1752151668)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jul 2025 11:00:10 GMT</pubDate>
    <dc:creator>HeathCheck_K</dc:creator>
    <dc:date>2025-07-10T11:00:10Z</dc:date>
    <item>
      <title>Errors with Data Redistribution (User-ID Agent) on Labs Environment</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-with-data-redistribution-user-id-agent-on-labs/m-p/1233724#M6085</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am searching Palo Alto User-ID configuration and build Labs on EVE-NG use Palo Alto KVM.&lt;/P&gt;
&lt;P&gt;Now I can set up LDAP and Group Mapping , it's working.&lt;/P&gt;
&lt;P&gt;But I can not set up Data Redistribution, Connection between Firewall and User-ID Agent is &lt;STRONG&gt;No. (Connected No, log as bellow). I created Certificate and add it to Agent already.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I am using PanOS 10.2.8 and Agent 10.2.4 running Window Server 2016&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please help !&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2025-07-10 19:47:32.086 +0700 pan_dcom_epoll: start epoll thread 1 at 1752151652(epoch: 1752151652)&lt;BR /&gt;2025-07-10 19:47:35.000 +0700 close socket fd 1026(UIA-test)&lt;BR /&gt;2025-07-10 19:47:35.000 +0700 Error: pan_distributor_agent_dcom_callback(pan_distributor_agent.c:2026): agent UIA-test is reset, event:1, abort:0, reset:1&lt;BR /&gt;2025-07-10 19:47:35.001 +0700 conn UIA-test is not connected.&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 close conn UIA-test, same thread 0, b_notifying 0&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 conn UIA-test has been closed by application[event=6]&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 release conn UIA-test, notify=1&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 close socket fd 1026(UIA-test)&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 no work in epoll index 1&lt;BR /&gt;2025-07-10 19:47:35.002 +0700 pan_dcom_epoll: quit, index = 1, now=1752151655(epoch: 1752151655)&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 [agent UIA-test] DCOM_SSL_CLNT_CONFIG&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 [secure_conn] pan_distributor_sec_conn_load_custom_server_cert()&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 [secure_conn] RSA key&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 [secure_conn] Custom client ssl certificate loaded&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 add new conn UIA-test to dcom, fd = 1026, addr = ssl@10.10.10.10#5007&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 conn UIA-test is not connected.&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 add socket fd 1026(UIA-test) into epoll 1 [prev total fds: 0, jobid: 0].&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 agent UIA-test didn't establish secure communication yet&lt;BR /&gt;2025-07-10 19:47:40.031 +0700 pan_dcom_epoll: start epoll thread 1 at 1752151660(epoch: 1752151660)&lt;BR /&gt;2025-07-10 19:47:43.004 +0700 close socket fd 1026(UIA-test)&lt;BR /&gt;2025-07-10 19:47:43.004 +0700 Error: pan_distributor_agent_dcom_callback(pan_distributor_agent.c:2026): agent UIA-test is reset, event:1, abort:0, reset:1&lt;BR /&gt;2025-07-10 19:47:43.005 +0700 conn UIA-test is not connected.&lt;BR /&gt;2025-07-10 19:47:43.005 +0700 close conn UIA-test, same thread 0, b_notifying 0&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 conn UIA-test has been closed by application[event=6]&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 release conn UIA-test, notify=1&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 close socket fd 1026(UIA-test)&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 no work in epoll index 1&lt;BR /&gt;2025-07-10 19:47:43.008 +0700 pan_dcom_epoll: quit, index = 1, now=1752151663(epoch: 1752151663)&lt;BR /&gt;2025-07-10 19:47:48.036 +0700 [agent UIA-test] DCOM_SSL_CLNT_CONFIG&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 [secure_conn] pan_distributor_sec_conn_load_custom_server_cert()&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 [secure_conn] RSA key&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 [secure_conn] Custom client ssl certificate loaded&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 add new conn UIA-test to dcom, fd = 1026, addr = ssl@10.10.10.10#5007&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 conn UIA-test is not connected.&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 add socket fd 1026(UIA-test) into epoll 1 [prev total fds: 0, jobid: 0].&lt;BR /&gt;2025-07-10 19:47:48.037 +0700 agent UIA-test didn't establish secure communication yet&lt;BR /&gt;2025-07-10 19:47:48.038 +0700 pan_dcom_epoll: start epoll thread 1 at 1752151668(epoch: 1752151668)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 11:00:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-with-data-redistribution-user-id-agent-on-labs/m-p/1233724#M6085</guid>
      <dc:creator>HeathCheck_K</dc:creator>
      <dc:date>2025-07-10T11:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Errors with Data Redistribution (User-ID Agent) on Labs Environment</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-with-data-redistribution-user-id-agent-on-labs/m-p/1235713#M6180</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please verify the firewall settings on the Domain Controller(as I understand it is Windows Server 2016).&lt;/P&gt;
&lt;P&gt;You need to allow TCP 5007 port for this.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 11:42:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/errors-with-data-redistribution-user-id-agent-on-labs/m-p/1235713#M6180</guid>
      <dc:creator>Parsek</dc:creator>
      <dc:date>2025-08-08T11:42:27Z</dc:date>
    </item>
  </channel>
</rss>

