<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WMI access denied in System Logs but Device &amp;gt; User Identification shows connected on all DC's in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wmi-access-denied-in-system-logs-but-device-gt-user/m-p/461243#M102148</link>
    <description>&lt;P&gt;show user ip-user-mapping all showed valid user to IP mappings.&lt;/P&gt;&lt;P&gt;show user server-monitor statistics showed 4 DC's in the connected state, but if you kept running that command over and over you'd see a random DC go to not connected, then access denied, then connected again.&amp;nbsp; The windows program WBEMTEST with the same service account credentials we use against the DC's launched with no issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We changed them from WinRM-HTTP to WMI and committed, and no issues since.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's no problem with it on WMI, that's ok to have it set to that method if it works right?&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jan 2022 21:02:45 GMT</pubDate>
    <dc:creator>ksauer507</dc:creator>
    <dc:date>2022-01-26T21:02:45Z</dc:date>
    <item>
      <title>WMI access denied in System Logs but Device &gt; User Identification shows connected on all DC's</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wmi-access-denied-in-system-logs-but-device-gt-user/m-p/461220#M102143</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've seen on my Palo Alto 3220 system logs dashboard applet a ton of Access Denied messages regarding our domain controllers.&amp;nbsp; However if I go over to Device &amp;gt; User Identification, all 4 of our DC's there are listed as connected in green.&amp;nbsp; All 4 are Microsoft Active Directory, WinRM-HTTP.&amp;nbsp; If they are green and connected there, why am I seeing errors in the system logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;01/26 14:29:58 Server monitor &lt;EM&gt;dcname&lt;/EM&gt;(vsys1) is connected&lt;/P&gt;&lt;P&gt;01/26 14:29:58 Server monitor &lt;EM&gt;dcname&lt;/EM&gt;(vsys1): connection failed, HTTP code 500, s:Receiverw:InternalErrorThe WS-Management service cannot process the request. The WMI service returned an 'access denied' error. 200The WS-Management service cannot process the request. The WMI service returned an 'access denied' error. H&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 19:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wmi-access-denied-in-system-logs-but-device-gt-user/m-p/461220#M102143</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2022-01-26T19:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: WMI access denied in System Logs but Device &gt; User Identification shows connected on all DC's</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wmi-access-denied-in-system-logs-but-device-gt-user/m-p/461243#M102148</link>
      <description>&lt;P&gt;show user ip-user-mapping all showed valid user to IP mappings.&lt;/P&gt;&lt;P&gt;show user server-monitor statistics showed 4 DC's in the connected state, but if you kept running that command over and over you'd see a random DC go to not connected, then access denied, then connected again.&amp;nbsp; The windows program WBEMTEST with the same service account credentials we use against the DC's launched with no issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We changed them from WinRM-HTTP to WMI and committed, and no issues since.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's no problem with it on WMI, that's ok to have it set to that method if it works right?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 21:02:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wmi-access-denied-in-system-logs-but-device-gt-user/m-p/461243#M102148</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2022-01-26T21:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: WMI access denied in System Logs but Device &gt; User Identification shows connected on all DC's</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wmi-access-denied-in-system-logs-but-device-gt-user/m-p/462004#M102215</link>
      <description>&lt;P&gt;Maybe check the article below and also you may double check the DC config itself as only WBEMTEST may not be enough, also check for network flapping or bottleneck issues or firewall CPU/Memory issues as the integrated WMI agent is causing cpu/memory issues to the firewall. Also the trust between the 4 DC could be in some cases not configured correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clk0CAC" target="_blank" rel="noopener"&gt;Agentless User-ID 'access denied' Error in Server Monitor - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also check for known issues for your firewall version or addresses issues for the versions after your version. Example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-release-information/known-issues.html" target="_blank" rel="noopener"&gt;Known Issues (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-addressed-issues.html" target="_blank" rel="noopener"&gt;PAN-OS 9.1 Addressed Issues (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jan 2022 08:49:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wmi-access-denied-in-system-logs-but-device-gt-user/m-p/462004#M102215</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-01-30T08:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: WMI access denied in System Logs but Device &gt; User Identification shows connected on all DC's</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wmi-access-denied-in-system-logs-but-device-gt-user/m-p/509575#M106084</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;gt;&amp;gt; mp useridd.log 2022-07-22 05:53:28.324 +0400 Error: pan_user_id_win_wmic_log_query(pan_user_id_win.c:1603): log query for server1.local failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;mp useridd.log 2022-07-22 05:53:28 2022-07-22 05:53:28.324 +0400 Error: pan_user_id_win_get_error_status(pan_user_id_win.c:1288): WMIC message from server server1.local: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;We checked this issue further and found the reason as a recent patch release from Microsoft&amp;nbsp;&lt;A href="https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c" target="_blank" rel="noopener nofollow noreferrer" data-aura-rendered-by="60:37417;a"&gt;KB5004442&lt;/A&gt;&amp;nbsp;which impacts the WMI transport service used from the FW side.&lt;BR /&gt;We checked the same with the Server Team and could correlate the patch installation and the mapping failure timestamps.&lt;BR /&gt;A detailed description of the issue along with the resolution is provided in the articles below:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkkfCAA&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener nofollow noreferrer" data-aura-rendered-by="60:37417;a"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkkfCAA&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 08:49:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wmi-access-denied-in-system-logs-but-device-gt-user/m-p/509575#M106084</guid>
      <dc:creator>nislam</dc:creator>
      <dc:date>2022-07-22T08:49:28Z</dc:date>
    </item>
  </channel>
</rss>

