<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows User-ID Agent Disconnect After Failover in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/windows-user-id-agent-disconnect-after-failover/m-p/530156#M879</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I have a customer who had an issue with the WMI using agentless User-ID due to Microsoft security update.&lt;/P&gt;
&lt;P&gt;We decided to move to Windows User-ID Agent installed on a domain member Windows Server 2016.&lt;/P&gt;
&lt;P&gt;PAN OS 10.2.2 and installed agent version 10.2.1-101.&lt;/P&gt;
&lt;P&gt;In the Data Redistribution i can see the agent is connected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Customer found that if failover occurs, the agent is disconnected.&lt;/P&gt;
&lt;P&gt;I was able to reproduce this in a lab running the same configuration on VMware.&lt;/P&gt;
&lt;P&gt;I tried to upgrade to 10.2.3-hf2 but still the same behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i run the command "show user user-id-agent config all" on any gateway while secondary is active, i get the following output:&lt;BR /&gt;Server error : op command for client useridd timed out as client is not available&lt;BR /&gt;When the primary is active, i will get this error only when i run the command on the secondary (passive) gateway. The primary (active) will output the configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i run the command "show user user-id-agent state all" on the secondary when its passive i get the output:&lt;/P&gt;
&lt;P&gt;Cannot get config from agent winsrv_user-id_agent: Error: Failed to connect to 10.10.100.30(10.10.100.30):5007&lt;BR /&gt;No User-ID Agent agents in vsys vsys1&lt;/P&gt;
&lt;P&gt;This makes sense as it is passive and should not be able to connect. But when the secondary is active, i get only:&lt;/P&gt;
&lt;P&gt;No User-ID Agent agents in vsys vsys1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone has any idea regarding this behavior?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Feb 2023 17:24:42 GMT</pubDate>
    <dc:creator>ademo-user25</dc:creator>
    <dc:date>2023-02-07T17:24:42Z</dc:date>
    <item>
      <title>Windows User-ID Agent Disconnect After Failover</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/windows-user-id-agent-disconnect-after-failover/m-p/530156#M879</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I have a customer who had an issue with the WMI using agentless User-ID due to Microsoft security update.&lt;/P&gt;
&lt;P&gt;We decided to move to Windows User-ID Agent installed on a domain member Windows Server 2016.&lt;/P&gt;
&lt;P&gt;PAN OS 10.2.2 and installed agent version 10.2.1-101.&lt;/P&gt;
&lt;P&gt;In the Data Redistribution i can see the agent is connected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Customer found that if failover occurs, the agent is disconnected.&lt;/P&gt;
&lt;P&gt;I was able to reproduce this in a lab running the same configuration on VMware.&lt;/P&gt;
&lt;P&gt;I tried to upgrade to 10.2.3-hf2 but still the same behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i run the command "show user user-id-agent config all" on any gateway while secondary is active, i get the following output:&lt;BR /&gt;Server error : op command for client useridd timed out as client is not available&lt;BR /&gt;When the primary is active, i will get this error only when i run the command on the secondary (passive) gateway. The primary (active) will output the configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If i run the command "show user user-id-agent state all" on the secondary when its passive i get the output:&lt;/P&gt;
&lt;P&gt;Cannot get config from agent winsrv_user-id_agent: Error: Failed to connect to 10.10.100.30(10.10.100.30):5007&lt;BR /&gt;No User-ID Agent agents in vsys vsys1&lt;/P&gt;
&lt;P&gt;This makes sense as it is passive and should not be able to connect. But when the secondary is active, i get only:&lt;/P&gt;
&lt;P&gt;No User-ID Agent agents in vsys vsys1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone has any idea regarding this behavior?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 17:24:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/windows-user-id-agent-disconnect-after-failover/m-p/530156#M879</guid>
      <dc:creator>ademo-user25</dc:creator>
      <dc:date>2023-02-07T17:24:42Z</dc:date>
    </item>
  </channel>
</rss>

