<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID: User-IP mapping is 'unknown' for some AD users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/530772#M109507</link>
    <description>&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
    <pubDate>Sat, 11 Feb 2023 07:44:41 GMT</pubDate>
    <dc:creator>DellaHale</dc:creator>
    <dc:date>2023-02-11T07:44:41Z</dc:date>
    <item>
      <title>User-ID: User-IP mapping is 'unknown' for some AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528158#M109063</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are facing issue with Agentbased User-ID agent 10.1.0-21 and the PanOS version 10.0.1&lt;/P&gt;
&lt;P&gt;User-IP-Mapping shows unknown for some of the users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt;show user ip-user-mapping ip x.x.x.x&lt;/P&gt;
&lt;P&gt;IP address: x.x.x.x (vsys1)&lt;BR /&gt;User: unknown&lt;BR /&gt;From: Unknown&lt;BR /&gt;Idle Timeout: 0s&lt;BR /&gt;Max. TTL: 3s&lt;BR /&gt;HIP Query: Disabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt;tail follow yes mp-log useridd.log&lt;/P&gt;
&lt;P&gt;2023-01-18 15:36:43.369 +0100 Error: pan_vsys_getaddrinfo(pan_dnsproxyd_sysd_api.c:1722): [DNS_API] getaddrinfo() failed 1, Unknown error!&lt;BR /&gt;2023-01-18 15:36:43.369 +0100 Error: pan_user_id_agent_resolve_ip(pan_user_id_agent.c:1948): pan_vsys_getaddrinfo failed for host=lb_domaincontroler1.abcd.com&lt;BR /&gt;2023-01-18 15:36:43.369 +0100 Error: pan_user_id_win_wmic_log_query(pan_user_id_win.c:1613): failed to resolve ip for lb_domaincontroler1.abcd.com&lt;BR /&gt;2023-01-18 15:36:45.557 +0100 Error: pan_vsys_getaddrinfo(pan_dnsproxyd_sysd_api.c:1722): [DNS_API] getaddrinfo() failed 1, Unknown error!&lt;BR /&gt;2023-01-18 15:36:45.557 +0100 Error: pan_user_id_agent_resolve_ip(pan_user_id_agent.c:1948): pan_vsys_getaddrinfo failed for host=lb_domaincontroler1.abcd.com&lt;BR /&gt;2023-01-18 15:36:45.557 +0100 Error: pan_user_id_win_wmic_log_query(pan_user_id_win.c:1613): failed to resolve ip for lb_domaincontroler1.abcd.com&lt;BR /&gt;2023-01-18 15:36:46.159 +0100 Error: pan_user_id_win_wmic_log_query(pan_user_id_win.c:1669): log query for ABCD-AD1 failed: NTSTATUS: NT code 0x80041003 - NT code 0x80041003&lt;BR /&gt;2023-01-18 15:36:46.159 +0100 Error: pan_user_id_win_get_error_status(pan_user_id_win.c:1340): WMIC message from server ABCD-AD1: NTSTATUS: NT code 0x80041003 - NT code 0x80041003&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Executed all the commands in the documents, cleared cache and refreshed User-ID-Agent and Group Mapping.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/cli-cheat-sheets/cli-cheat-sheet-user-id" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-cli-quick-start/cli-cheat-sheets/cli-cheat-sheet-user-id&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR1CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClR1CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone help me in this to fix it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 10:16:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528158#M109063</guid>
      <dc:creator>Pankaj_Dhobe</dc:creator>
      <dc:date>2023-01-23T10:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID: User-IP mapping is 'unknown' for some AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528163#M109066</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218618"&gt;@Pankaj_Dhobe&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;From the provided logs it looks like your firewall is not able to resolve the FQDN that you use for the user-ip-mapping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2023-01-18 15:36:45.557 +0100 Error: pan_user_id_win_wmic_log_query(pan_user_id_win.c:1613): &lt;STRONG&gt;failed to resolve ip for lb_domaincontroler1.abcd.com&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because of this your FW is not able to reach the User-ID agent that is running on this host. In nut shell your FW is not able to communicate with the server where User-ID agent is running.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So at first step you should verify firewall can resolve the FQDN (or just use IP address) and then verify connectivity between FW and user-id agent.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 11:02:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528163#M109066</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-01-23T11:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID: User-IP mapping is 'unknown' for some AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528164#M109067</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218618"&gt;@Pankaj_Dhobe&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is your cache timeout set to?&amp;nbsp; I have noticed with some customers that they authenticate only in the morning.&amp;nbsp; They would have User-ID mappings in the morning, but not during the day.&amp;nbsp; I increased the cache timeout to 10 hours so they would have the mappings all day (work day).&amp;nbsp; Here is a doc where you can determine if it is a cache timeout issue -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001Uu5CAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000001Uu5CAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 11:04:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528164#M109067</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-23T11:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID: User-IP mapping is 'unknown' for some AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528166#M109068</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Out of the 281 users, 58 are showing unknown. So connectivity is there as other users are authenticating successfully.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt;show user ip-user-mapping all option count&lt;/P&gt;
&lt;P&gt;Total: 281 users&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show user ip-user-mapping all option count type UNKNOWN&lt;/P&gt;
&lt;P&gt;Total: 58 users&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 12:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528166#M109068</guid>
      <dc:creator>Pankaj_Dhobe</dc:creator>
      <dc:date>2023-01-23T12:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID: User-IP mapping is 'unknown' for some AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528172#M109069</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218618"&gt;@Pankaj_Dhobe&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;In that case I am not sure that the logs you have share are relevant to your problem. I would still suggest to verify your firewall have stable connection to the user-id agent server and DNS resolution is working as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Back to your problem&lt;/P&gt;
&lt;P&gt;- get one of the IP addresses, that are currently unknown on the firewall&lt;/P&gt;
&lt;P&gt;- go to the user-id agent GUI and check its log if it has it in its logs&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1674481184150.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47334iC9B7EDB7CD3A8BB8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1674481184150.png" alt="Astardzhiev_0-1674481184150.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Go to Monitoring and search for that IP. Do you see it there?&lt;/P&gt;
&lt;P&gt;Go to Logs, do you see any "failed" logs? Note logs here will start populate from the moment you navigate to the log tab (you wouldn't see old logs here). If there are any error, you may want to set the log level to debug&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_1-1674481390254.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47335iB7AC6CD0451152FC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_1-1674481390254.png" alt="Astardzhiev_1-1674481390254.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In additional note:&lt;/P&gt;
&lt;P&gt;- Have you noticed any pattern in the unknown and know addresses? Does unknown IP share the same subnet(s)? Do you see successful user-ip-mapping for IP from the same subnet from which you see unknown?&lt;/P&gt;
&lt;P&gt;- Is your user-id agent configured with any inclusion/exclusion? User Identification -&amp;gt; Discovery&lt;/P&gt;
&lt;P&gt;- Is your firewall zone configured with any inclusion/exclusion? Network -&amp;gt; Zones -&amp;gt; User Identification ACL)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just noticed the odd firewall version that your are running. Note that 10.0 is officially out of support, but more importantly 10.0.1 is the very first maintenance release for 10.0, which naturally could be full of bugs.&lt;/P&gt;
&lt;P&gt;I don't like start looking for bugs before you have eliminated any other possible reason, but at the same time running such early OS version (when there is so many bug fixes released) is like you want your firewall to crash &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 13:54:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/528172#M109069</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-01-23T13:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID: User-IP mapping is 'unknown' for some AD users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/530772#M109507</link>
      <description>&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2023 07:44:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-ip-mapping-is-unknown-for-some-ad-users/m-p/530772#M109507</guid>
      <dc:creator>DellaHale</dc:creator>
      <dc:date>2023-02-11T07:44:41Z</dc:date>
    </item>
  </channel>
</rss>

