<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID - one user occasionally not hitting the user based policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443277#M100198</link>
    <description>&lt;P&gt;Has anyone found a solution to this issue?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Oct 2021 21:33:19 GMT</pubDate>
    <dc:creator>rlambright</dc:creator>
    <dc:date>2021-10-25T21:33:19Z</dc:date>
    <item>
      <title>User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226279#M65149</link>
      <description>&lt;P&gt;PAN-OS 8.1.2, User-ID configured with Windows AD single domain. There are security rules built, based on users/user groups. It is mostly working as intended, but specifically there's&amp;nbsp;[at least]&amp;nbsp;one user that has a different behavior - some user-based (not group) rules are occasionally missing, even through they did hit the policy a few moments ago. Same traffic, same packet fields - IPs/ports, etc., but suddenly it goes through Deny, instead of hitting the Permit policy. At the same time same rules works fine for a different user. After a moment, it may start hitting the proper rule again.&lt;/P&gt;&lt;P&gt;When checking via CLI, faulty user is registered properly- there is user-ip mapping, user-group mapping, etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If creating additional rule, based on IP only, without username used - it hits that rule if it is missing the user-based rule, so there should an issue with User-ID, but not widely seen as there are a bunch of user/group rules used and they are working fine. Issue have been noticed with one specific user, but it is no different than any other user seen around.&lt;/P&gt;&lt;P&gt;useridd.log shows such an message, where &amp;lt;domain&amp;gt; - proper domain and &amp;lt;username&amp;gt; - username for the tricky user:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Warning:&amp;nbsp; pan_user_group_user_prime_uid_lookup(pan_user_group_multi_attr.c:1306): For&amp;nbsp;&amp;lt;domain&amp;gt;\&amp;lt;username&amp;gt;&amp;nbsp;user, domain&amp;nbsp;&amp;lt;domain&amp;gt;&amp;nbsp;does not exist in group-mapping&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried resetting, clearing, refreshing, etc., but that didn't help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Don't want to overwhelm with configuration, but maybe spew some ideas where to look?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 12:33:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226279#M65149</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2018-08-08T12:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticated User-ID with GlobalProtect for Internal Network Segmentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226301#M65151</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42773"&gt;@nikoo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It might be worth watching what the user is doing for a bit and seeing if they are doing something that would cause the user-id mapping to age-out or map to an unknown user?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 15:31:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226301#M65151</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-07T15:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticated User-ID with GlobalProtect for Internal Network Segmentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226334#M65160</link>
      <description>&lt;P&gt;Are you using the agent or agentless setup?&amp;nbsp; I upgraded to version 8 not too long ago and ran into problems with the agentless setup.&amp;nbsp; My problem was that the logged in user suddenly became unknown per the palo alto.&amp;nbsp; Turns out I had two problems.&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; The default domain contorller policy for logins was only logging failure, not success.&amp;nbsp; I changed this in the default domain controllers gpo.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; I use the WMI Authentication for the User-ID Setup.&amp;nbsp; The AD account used requires special permissions to work.&amp;nbsp; My missing piece for that was that the account needed to be a member of the Remote Desktop User group on computer without local admin rights.&amp;nbsp; I can't recall the special permission needed exactly, but that was the easy way to solve it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 17:53:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226334#M65160</guid>
      <dc:creator>ToddJohnsen</dc:creator>
      <dc:date>2018-08-07T17:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticated User-ID with GlobalProtect for Internal Network Segmentation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226344#M65164</link>
      <description>&lt;P&gt;Just one question for clarification....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your detailed post you mention that if the ip address hits the rule that you added for ip only, it is allowed...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my question is ,,, when this happens, what user id is assosiated with this ip address when it is allowed via ip address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it the expected user id or blank or something else...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 18:04:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226344#M65164</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-07T18:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226858#M65307</link>
      <description>&lt;P&gt;Thank you for the advices guys, somehow missed all the notifications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I know (not working directly with the end user) - nothing specifically fancy, but there could be something unnoticed though - no one was really sitting behind his back.&amp;nbsp;But definitelly nothing major - same setup, just different time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30124"&gt;@ToddJohnsen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, it is clientless (moslty, one agent as well). User is kind of known to the Palo - it is not lost at any time, but will check through updates documents regarding requirements anyway as initial setup is pre 8.0 era. Although given this concerns only one specific user - company wide issue should be seen more often I believe.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These is expected user-id associated with the IP in the logs and user-ip mappings. User field is not blank. If looking at the logs - they are exactly the same, with the difference of rule being hit. In one case - used-id base, in another case - backup IP-only based rule. User-ID mapping is still present in the cache - at least as far as I've checked from the CLI.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 08:40:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226858#M65307</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2018-08-13T08:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226862#M65309</link>
      <description>&lt;P&gt;quick question,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when you created the rule for "IP" below the "user group" one, did you create a new rule from scratch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it may be best to clone the user rule and just edit the source ip and user fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, (clutching at straws here). I would create a couple of cloned rules before the IP one to eliminate group membership issues...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. source user&amp;nbsp;= domain\username&lt;/P&gt;&lt;P&gt;2. source user = username&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this may show some interesting results..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or.. it may not...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just to see if the user matches to one of these...&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 09:21:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226862#M65309</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-13T09:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226881#M65311</link>
      <description>&lt;P&gt;Cloned the rule, yep. Left everything the same, but removed source user statement.&lt;/P&gt;&lt;P&gt;Will try poking around, yep.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 13:21:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/226881#M65311</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2018-08-13T13:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/426513#M94505</link>
      <description>&lt;P&gt;I'm also facing issue like this.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;User id not fetching&amp;nbsp; in traffic logs. we created user base rule on that basis mapped ip address shows user id for same rule .but some time user is not authenticated from that user base policy rule and it is moving from next any any rule. if it is moving from any any rule that time it is not showing user-id mapping.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 12:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/426513#M94505</guid>
      <dc:creator>SurajN</dc:creator>
      <dc:date>2021-08-12T12:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443277#M100198</link>
      <description>&lt;P&gt;Has anyone found a solution to this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 21:33:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443277#M100198</guid>
      <dc:creator>rlambright</dc:creator>
      <dc:date>2021-10-25T21:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443288#M100200</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/122969"&gt;@rlambright&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;What issue are you actually running into, can you describe your particular problem? Usually when users report an issue like this what you're running into is the user-id mapping aging out because you aren't seeing any authentication events in a timely manner so your user based entries won't match traffic anymore.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 23:03:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443288#M100200</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-10-25T23:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443433#M100218</link>
      <description>&lt;P&gt;yeah, basically the same issue as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42773"&gt;@nikoo&lt;/a&gt; described above.&amp;nbsp; We have about 10 users (out of 300+) that&amp;nbsp; randomly get denied internet access for 5 to 15 minutes because none of policies catch them and they get the default policy.&amp;nbsp; The useridd.log says that the user doesn't belong to any AD groups during these times.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 12:51:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443433#M100218</guid>
      <dc:creator>rlambright</dc:creator>
      <dc:date>2021-10-26T12:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443435#M100219</link>
      <description>&lt;P&gt;check the User-IP mapping to see if it is againg-out correctly, if not check your User-ID Sources and change the time-out accordingly if needed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 12:59:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443435#M100219</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2021-10-26T12:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - one user occasionally not hitting the user based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443703#M100249</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/122969"&gt;@rlambright&lt;/a&gt;, at my specific case it was noted as a bug and fix was provided. General issue was with mixing UPN and SAM type of usernames in the policies. PAN-153614, fixed in 9.1.8 &amp;amp; 10.0.5.&lt;/P&gt;&lt;DIV&gt;"Fixed an issue where user-based policies did not correctly match if the same user was included in both a policy with the username in NetBIOS format and another policy with the username in FQDN format."&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;If you are running any of these versions or above - it should be a different case there.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Workaround from my case (use it at your own risk, given we don't know if it is the same issue):&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"&amp;gt; Remove User Domain override configuration from the Group-Mapping configuration.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; Configure one specific user-attribute in all the security policies"&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 27 Oct 2021 06:40:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-one-user-occasionally-not-hitting-the-user-based-policy/m-p/443703#M100249</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2021-10-27T06:40:12Z</dc:date>
    </item>
  </channel>
</rss>

