<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserID Agent version compatbility in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/1222866#M123527</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how about 11.2 Pan Os? Will it work with user id agent? One of customer recieving below error they are using 11.2:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cannot open security log for DC AS-01 - Access denied&lt;/P&gt;</description>
    <pubDate>Thu, 06 Mar 2025 09:12:54 GMT</pubDate>
    <dc:creator>KhaleelE</dc:creator>
    <dc:date>2025-03-06T09:12:54Z</dc:date>
    <item>
      <title>UserID Agent version compatbility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599029#M119144</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm currently working through the Certificate Advisory.&amp;nbsp; We currently have firewalls running 10.1.11, user-ID agent is 10.1.1-102.&amp;nbsp; &amp;nbsp;Started an upgraded firewalls&amp;nbsp; to current preferred version of 10.1.13h1.&amp;nbsp; The issue I have is I am simultaneously trying to introduce PA-1410 firewalls into Panorama for management.&amp;nbsp; PA-1410 does not support 10.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The advisory states that firewalls must be upgraded with hotfix before upgrading the UserID agent.&amp;nbsp; Per the advisory:&lt;BR /&gt;&lt;SPAN&gt;"Install the hotfix listed in&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;Table 2&lt;/STRONG&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;below on all NGFWs and Panoramas. It is important to perform this step&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;before&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;updating the agents; these two steps must be performed in sequence"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This creates a challenge, as to my knowledge,&amp;nbsp; UserID agent 10.1.x will not work on firewalls running 11.x.&amp;nbsp; 11.x is my only option for the 1410's and I need to deploy these firewalls well before the other firewalls will be finished upgrading.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What's the best way to go about this?&amp;nbsp; &amp;nbsp;Only thing I can think of is introduce the 1410's without using userID agent temporarily and use agentless server monitor instead.&amp;nbsp; &amp;nbsp;Anyone have another idea?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, the latest userID agent is listed as 11.0.1-104,&amp;nbsp; does this work with PAN-OS 11.1 and 11.2?&amp;nbsp; Documentation states it works on 11.0 and earlier.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 23:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599029#M119144</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2024-09-27T23:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent version compatbility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599215#M119173</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've shared your post with the Advisory team.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 19:11:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599215#M119173</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-10-01T19:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent version compatbility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599248#M119176</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167427"&gt;@securehops&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Simple solution that adds a bit of complexity, but why don't you just spin up another agent with 11.0.1 and only use it for the PA-1410s? I imagine that there's a reason that you aren't using agentless to begin with, so that would keep the benefits of running the agent in this instance. Either option is viable assuming that you can use the agentless setup.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 00:27:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599248#M119176</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-10-02T00:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent version compatbility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599255#M119180</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did consider setting up a new server for UserID agent as a backup option but since it's only temporary, I was thinking agentless would be the easier way to go&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I always used agentless but it kept triggering a lot of alerts and at the time, the solution from tac was to just use the UserID agent&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The also couldn't get clarity from support if the 11.0 userID agent is compatible with pan-os 11.1 and 11.2.&amp;nbsp; Release notes says it's compatible with 11.&lt;STRONG&gt;0&lt;/STRONG&gt; and earlier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 01:10:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599255#M119180</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2024-10-02T01:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent version compatbility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599519#M119210</link>
      <description>&lt;P&gt;PAN-OS is backwards compatible with userID versions, so PAN-OS 11.x can work with UserID 10.x&lt;/P&gt;
&lt;P&gt;no need for any duplication&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;reaper@fwl-be(active)&amp;gt; show system info | match sw-version
sw-version: 11.1.4-h1
reaper@fwl-be(active)&amp;gt; show system info | match model
model: PA-1420
reaper@fwl-be(active)&amp;gt; show user user-id-agent config all | match Product
Product Version: 10.1.0
Product Version: 10.1.0
reaper@fwl-be(active)&amp;gt; show user user-id-agent state all | match Status
        Status                                            : conn:idle
        Status                                            : conn:idle
reapern@fwl-be(active)&amp;gt; show user ip-user-mapping all

IP                                            Vsys                From    User                             IdleTimeout(s) MaxTimeout(s)
--------------------------------------------- ------------------- ------- -------------------------------- -------------- -------------
10.10.10.5                                  vsys1               UIA     pangurus\reaper                   6861           6861
&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 04 Oct 2024 08:05:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/599519#M119210</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-10-04T08:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent version compatbility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/600770#M119351</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since I was in a time crunch, I set up a new server temporarily.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is good to know for future, but documentation states differently.&amp;nbsp; Palo needs to do a better job on this&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 15:13:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/600770#M119351</guid>
      <dc:creator>securehops</dc:creator>
      <dc:date>2024-10-15T15:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent version compatbility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/1222866#M123527</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how about 11.2 Pan Os? Will it work with user id agent? One of customer recieving below error they are using 11.2:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cannot open security log for DC AS-01 - Access denied&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 09:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/1222866#M123527</guid>
      <dc:creator>KhaleelE</dc:creator>
      <dc:date>2025-03-06T09:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent version compatbility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/1225442#M123853</link>
      <description>&lt;P&gt;this means the AD is not configured to allow this action (either the service account for userid agent does not have sufficient privileges, or audit logging is not set up properly)&lt;/P&gt;
&lt;P&gt;this is not a compatibility issue&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 08:59:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/1225442#M123853</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-04-02T08:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Agent version compatbility</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/1238866#M125231</link>
      <description>&lt;P&gt;Hi, current preferred release version is &lt;STRONG&gt;11.0.3&lt;/STRONG&gt;. thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RMaurya013725_0-1758864291994.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69383iB42BB8D373DE745E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RMaurya013725_0-1758864291994.png" alt="RMaurya013725_0-1758864291994.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 05:25:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-agent-version-compatbility/m-p/1238866#M125231</guid>
      <dc:creator>R.Maurya013725</dc:creator>
      <dc:date>2025-09-26T05:25:07Z</dc:date>
    </item>
  </channel>
</rss>

