<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID-Agent wrong mapping with specific IPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wrong-mapping-with-specific-ips/m-p/510077#M106166</link>
    <description>&lt;P&gt;Hello!&lt;BR /&gt;Thanks for your replies. &lt;BR /&gt;I rebooted the firewall-cluster but the wrong mapping appeared again.&lt;BR /&gt;Then I used these commands, that solved the problem.&lt;BR /&gt;First find the user-id with the show command, then clear the entries for this id:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show user user-ids match-user username&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;clear user-policy-cache uid xx&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;clear uid-cache uid xx&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;clear uid-map-cache uid xx&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jul 2022 19:25:18 GMT</pubDate>
    <dc:creator>ChrisCon2355</dc:creator>
    <dc:date>2022-07-27T19:25:18Z</dc:date>
    <item>
      <title>User-ID-Agent wrong mapping with specific IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wrong-mapping-with-specific-ips/m-p/509815#M106123</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;since a few days we see strange things with User-ID-agent.&lt;BR /&gt;For some specific IP-addresses there are shown wrong users. This users even are not in the internal AD, they are just external VPN users invited from Azure. But they are mapped to internal ip addresses. Even if they are not online over VPN.&lt;BR /&gt;When looking into Monitor - User-ID in the column "user provided by source" there is the correct user. But in the column "user" the wrong user is shown. And this is also what we see in the CLI. We've cleaned the user-cache, installed now User-ID-Agent on the domain controllers (but of course, there the correct users are shown).&lt;BR /&gt;Running Pan-OS 10.1.6-h3 on the firewalls.&lt;BR /&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 17:07:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wrong-mapping-with-specific-ips/m-p/509815#M106123</guid>
      <dc:creator>ChrisCon2355</dc:creator>
      <dc:date>2022-07-25T17:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID-Agent wrong mapping with specific IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wrong-mapping-with-specific-ips/m-p/509844#M106125</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/219283"&gt;@ChrisCon2355&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Do these users utilize any services on these internal IPs that would cause them to authenticate to the host in question? If the service is using standard Windows Auth, that might help explain why these users are showing on internal resources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the User is differentiating from the User Provided by Source, have you verified the attributes that you have configured in regards to the source? Is it possible that whatever is triggering these authentication events is using a different directory attribute that you aren't expecting, causing them to match when they shouldn't? Maybe some relayed authentication events is using the same sAMAccountName or userPrincipalName or whatever you have the Primary Username attribute setup to?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 21:16:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wrong-mapping-with-specific-ips/m-p/509844#M106125</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-07-25T21:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID-Agent wrong mapping with specific IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wrong-mapping-with-specific-ips/m-p/510077#M106166</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;Thanks for your replies. &lt;BR /&gt;I rebooted the firewall-cluster but the wrong mapping appeared again.&lt;BR /&gt;Then I used these commands, that solved the problem.&lt;BR /&gt;First find the user-id with the show command, then clear the entries for this id:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show user user-ids match-user username&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;clear user-policy-cache uid xx&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;clear uid-cache uid xx&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;clear uid-map-cache uid xx&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 19:25:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-wrong-mapping-with-specific-ips/m-p/510077#M106166</guid>
      <dc:creator>ChrisCon2355</dc:creator>
      <dc:date>2022-07-27T19:25:18Z</dc:date>
    </item>
  </channel>
</rss>

