<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID limitations for distribution in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-limitations-for-distribution/m-p/474523#M103377</link>
    <description>&lt;P&gt;Hi folks !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would like your advice on a specific issue about user-id limitations :&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of our customer is using one central firewall to redistribute user-id mapping to more than 100 devices, and has issues about user-id process crashing on the central fw.&lt;/P&gt;&lt;P&gt;As far as i understood limitations on user-id redistribution, there is a limit of 100 redistribution points &lt;STRONG&gt;beneath each firewall, &lt;/STRONG&gt;which is not the case, as this central fw is retrieving infos from 2 user-id agents only. It just spreads these infos to more than one hundred devices. Each remote device only has like 3 layers beneath it.&lt;/P&gt;&lt;P&gt;So, is this normal behavior, or is there a trick here to make it work ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Subsidiary question, the windows user-id agent sometimes generates more than 150gb of traffic in a day (1gb maximum in normal times), if anyone has an idea &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Mar 2022 06:42:11 GMT</pubDate>
    <dc:creator>ssavariau</dc:creator>
    <dc:date>2022-03-21T06:42:11Z</dc:date>
    <item>
      <title>User-ID limitations for distribution</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-limitations-for-distribution/m-p/474523#M103377</link>
      <description>&lt;P&gt;Hi folks !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would like your advice on a specific issue about user-id limitations :&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of our customer is using one central firewall to redistribute user-id mapping to more than 100 devices, and has issues about user-id process crashing on the central fw.&lt;/P&gt;&lt;P&gt;As far as i understood limitations on user-id redistribution, there is a limit of 100 redistribution points &lt;STRONG&gt;beneath each firewall, &lt;/STRONG&gt;which is not the case, as this central fw is retrieving infos from 2 user-id agents only. It just spreads these infos to more than one hundred devices. Each remote device only has like 3 layers beneath it.&lt;/P&gt;&lt;P&gt;So, is this normal behavior, or is there a trick here to make it work ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Subsidiary question, the windows user-id agent sometimes generates more than 150gb of traffic in a day (1gb maximum in normal times), if anyone has an idea &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 06:42:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-limitations-for-distribution/m-p/474523#M103377</guid>
      <dc:creator>ssavariau</dc:creator>
      <dc:date>2022-03-21T06:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID limitations for distribution</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-limitations-for-distribution/m-p/475445#M103462</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/201291"&gt;@ssavariau&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What hardware are you running and what PAN-OS version ?&lt;/P&gt;
&lt;P&gt;Have you checked the firewall logs for a root cause of the UID crashing ? Are there any core-files that can be analyzed ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 24 Mar 2022 09:05:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-limitations-for-distribution/m-p/475445#M103462</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-03-24T09:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID limitations for distribution</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-limitations-for-distribution/m-p/475466#M103467</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;&lt;P&gt;Firewalls are a 3220 for the hub, and 220s for spoke, running on PAN-OS 9.0.0&lt;/P&gt;&lt;P&gt;On the hub, distributord process was shown as running, but we still had to run CLI command&amp;nbsp;"debug software restart process distributord" to make it functional again. At the time of this crash, an investigation was done, and that was the immediate solution found to correct it.&lt;/P&gt;&lt;P&gt;If we cannot spread user-id mapping to more than 100 devices from only one, we'll need to take a more hierarchical approach i think ?&lt;/P&gt;&lt;P&gt;Thx for your time !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 09:35:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-limitations-for-distribution/m-p/475466#M103467</guid>
      <dc:creator>ssavariau</dc:creator>
      <dc:date>2022-03-24T09:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID limitations for distribution</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-limitations-for-distribution/m-p/475676#M103482</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/201291"&gt;@ssavariau&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;9.0 just went end of life at the beginning of this month, so you'll need to get these to 9.1 or higher sooner rather than later. If you choose to open a chase on the issue, they'll tell you to upgrade before continuing to troubleshoot I'm sure so be aware of that. If you upgrade to a supported release and run into the issue again, then you can open a TAC case and have them identify root cause on why the process locked up, it could easily be some bug in the process you're running into.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 00:49:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-limitations-for-distribution/m-p/475676#M103482</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-03-25T00:49:50Z</dc:date>
    </item>
  </channel>
</rss>

