<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic user-id not mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping/m-p/453625#M101622</link>
    <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;I'm facing an issue with user-id agentless.&lt;/P&gt;
&lt;P&gt;i did the following configurations&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Create LDAP Server Profile&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;LDAP/Group Mappings configured on FW&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;User-ID Group Mapping Settings.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;server monotoring is connected&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Include network set&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;User ID on the source Zone enabled&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;account service on AD with the differents rights : events log reader, user domain, server operators, Users of the com modele distributed.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;When i verify the user mapping with this command : show user ip-user-mapping all,&amp;nbsp; only the Ip address is displayed but the user and From tab are empty&lt;SPAN style="font-family: inherit;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Can anybody tell why the mapping isn't working ? How to resolve this issue ? help&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Dec 2021 12:39:27 GMT</pubDate>
    <dc:creator>Marcellin</dc:creator>
    <dc:date>2021-12-16T12:39:27Z</dc:date>
    <item>
      <title>user-id not mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping/m-p/453625#M101622</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;I'm facing an issue with user-id agentless.&lt;/P&gt;
&lt;P&gt;i did the following configurations&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Create LDAP Server Profile&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;LDAP/Group Mappings configured on FW&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;User-ID Group Mapping Settings.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;server monotoring is connected&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Include network set&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;User ID on the source Zone enabled&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;account service on AD with the differents rights : events log reader, user domain, server operators, Users of the com modele distributed.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;When i verify the user mapping with this command : show user ip-user-mapping all,&amp;nbsp; only the Ip address is displayed but the user and From tab are empty&lt;SPAN style="font-family: inherit;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Can anybody tell why the mapping isn't working ? How to resolve this issue ? help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 12:39:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping/m-p/453625#M101622</guid>
      <dc:creator>Marcellin</dc:creator>
      <dc:date>2021-12-16T12:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: user-id not mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping/m-p/458463#M101907</link>
      <description>&lt;P&gt;Hi there, it's been a while, did you get this resolved?&lt;BR /&gt;&lt;BR /&gt;If so, what was your solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If not, can you test your server profile by running the commands in the below resource (step 2)?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/test-the-configuration/test-the-authentication-configuration.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/use-the-cli/test-the-configuration/test-the-authentication-configuration.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;You should get a successful authentication if the authentication and server profiles are working.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Also, under device &amp;gt; user identification &amp;gt; user mapping, what do you see under the "status" column for "server monitoring"? It should show a green "Connected".&lt;BR /&gt;&lt;BR /&gt;Lastly, in your authentication profile, what do you see in the "Advanced" tab &amp;gt; Allow list?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jan 2022 22:41:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping/m-p/458463#M101907</guid>
      <dc:creator>Gustavo_Aristi</dc:creator>
      <dc:date>2022-01-12T22:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: user-id not mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping/m-p/458513#M101912</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/126811"&gt;@Gustavo_Aristi&lt;/a&gt;&amp;nbsp; has provided you some great info, I will add that WMI protocol is used for IP address to user mapping not LDAP, so if you are not using the Palo Alto agent see below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/kcSArticleDetail?id=kA10g000000ClGG" target="_blank" rel="noopener"&gt;How to Configure Agentless User-ID - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/user-identification/device-user-identification-user-mapping/user-id-agent-setup/user-id-agent-setup-wmi-authentication.html" target="_blank" rel="noopener"&gt;Server Monitor Account (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLs2CAG" target="_blank" rel="noopener"&gt;How To Verify WMI Remote Connectivity using WBEMTEST (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsrCAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsrCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CltXCAS" target="_blank"&gt;Agentless User-ID Error failed to parse security log buf - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sometimes the agent is better as to not cause CPU load and in some cases the server team may not allow non Microsoft devices to connect to the AD server:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent/configure-the-windows-based-user-id-agent-for-user-mapping.html" target="_blank" rel="noopener"&gt;Configure the Windows-Based User-ID Agent for User Mapping (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also when you get this done you could be interested in redistributing this info to other firewalls:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-ip-and-user-tag-mappings-redistribution-for/m-p/393030#M90970" target="_blank" rel="noopener"&gt;LIVEcommunity - Knowledge sharing: IP and user TAG Mappings redistribution for DAG / DUG - LIVEcommunity - 393030 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 08:22:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-not-mapping/m-p/458513#M101912</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-01-13T08:22:09Z</dc:date>
    </item>
  </channel>
</rss>

