<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Server Monitoring of User-ID agent set-up shows Authentication failed /Connection refused error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-of-user-id-agent-set-up-shows-authentication/m-p/536889#M110273</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216045"&gt;@Sujanya&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That error is too general and requires additional debugging.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd make sure the clock is synced under the same NTP server everywhere.&lt;/P&gt;
&lt;P&gt;Also enable debug logging:&lt;/P&gt;
&lt;P&gt;debug user-id on debug&lt;BR /&gt;debug user-id set userid servermonitor&lt;/P&gt;
&lt;P&gt;Also capture krb5 and http traffic at the time of the issue&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) kerberos traffic is between fw and kdc server on port 88.&lt;/SPAN&gt;&lt;BR style="color: #172b4d; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Oxygen, Ubuntu, 'Fira Sans', 'Droid Sans', 'Helvetica Neue', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;2) http traffic is between fw and server monitor server on port 5985.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You might want to grab all this info + a tech support file and send it over to TAC for analysis.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2023 10:01:01 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2023-03-29T10:01:01Z</dc:date>
    <item>
      <title>Server Monitoring of User-ID agent set-up shows Authentication failed /Connection refused error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-of-user-id-agent-set-up-shows-authentication/m-p/536244#M110181</link>
      <description>&lt;P&gt;We have over 80+ firewalls in our environment, all of them of version 10.1.6.-h6 , we are using Kerberos profile in the user-id agent set-up and every server monitor status seems connected. Except for the firewall which is with PAN-OS version 10.2.3.-h4, even after using the same parameters.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;getting below error:&lt;/P&gt;
&lt;P&gt;Server monitor HOSTNAMEDP(vsys1): connection failed, HTTP code 401, (null)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly suggest us on above condition.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 11:19:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-of-user-id-agent-set-up-shows-authentication/m-p/536244#M110181</guid>
      <dc:creator>Sujanya</dc:creator>
      <dc:date>2023-03-24T11:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Server Monitoring of User-ID agent set-up shows Authentication failed /Connection refused error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-of-user-id-agent-set-up-shows-authentication/m-p/536889#M110273</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216045"&gt;@Sujanya&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That error is too general and requires additional debugging.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd make sure the clock is synced under the same NTP server everywhere.&lt;/P&gt;
&lt;P&gt;Also enable debug logging:&lt;/P&gt;
&lt;P&gt;debug user-id on debug&lt;BR /&gt;debug user-id set userid servermonitor&lt;/P&gt;
&lt;P&gt;Also capture krb5 and http traffic at the time of the issue&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) kerberos traffic is between fw and kdc server on port 88.&lt;/SPAN&gt;&lt;BR style="color: #172b4d; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Oxygen, Ubuntu, 'Fira Sans', 'Droid Sans', 'Helvetica Neue', sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;2) http traffic is between fw and server monitor server on port 5985.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You might want to grab all this info + a tech support file and send it over to TAC for analysis.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 10:01:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/server-monitoring-of-user-id-agent-set-up-shows-authentication/m-p/536889#M110273</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-03-29T10:01:01Z</dc:date>
    </item>
  </channel>
</rss>

