<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [User-ID HUB Vsys] Solved Issue User-ID Behavior in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-hub-vsys-solved-issue-user-id-behavior/m-p/1256286#M126593</link>
    <description>&lt;P&gt;This Knowledge bases describe the solutions:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CpvSCAS" target="_blank"&gt;Source user information missing from the Traffic logs in multi-... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kI2SCAU" target="_blank"&gt;IP-User mappings are not redistributing from non-hub vsys to th... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jun 2026 19:45:05 GMT</pubDate>
    <dc:creator>DanielS.Romero</dc:creator>
    <dc:date>2026-06-12T19:45:05Z</dc:date>
    <item>
      <title>[User-ID HUB Vsys] Solved Issue User-ID Behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-hub-vsys-solved-issue-user-id-behavior/m-p/1256248#M126592</link>
      <description>&lt;P&gt;Hello LiveCommunity Team!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I created this post to share my experience regarding the User-ID Hub for multi-vsys environments involving some &lt;STRONG&gt;User-ID&lt;/STRONG&gt; incomplete table for a specific vsys:&lt;BR /&gt;&lt;BR /&gt;I have an NGFW with multiple vsys, and in each vsys I have configured a unique &lt;STRONG&gt;Data Redistribution Appointing to dedicated User-ID Agents and Panorama/NGFWs&lt;/STRONG&gt;, &lt;STRONG&gt;local Agentless Server Monitoring&lt;/STRONG&gt;, and &lt;STRONG&gt;Group Mappings configuration&lt;/STRONG&gt;; however, I have the problem that some users and groups are not mapped to the other vsys, causing security, NAT, Decryption rules to not match according to the user ID information of every vsys&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;As a solution, I configure the default base &lt;STRONG&gt;vsys1&lt;/STRONG&gt; as the &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt; and centralize the &lt;STRONG&gt;User-ID&lt;/STRONG&gt; and &lt;STRONG&gt;Group Mapping&lt;/STRONG&gt; settings in the &lt;STRONG&gt;Hub.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;User-ID Hub Conclusions&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;- The &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt; "&lt;STRONG&gt;Master&lt;/STRONG&gt;" will redistribute the User-ID information "&lt;STRONG&gt;IP-to-User and Group Mapping&lt;/STRONG&gt;" to the "&lt;STRONG&gt;Slaves&lt;/STRONG&gt;" or &lt;STRONG&gt;non-hub&lt;/STRONG&gt; &lt;STRONG&gt;vsys&amp;nbsp;&lt;/STRONG&gt;but the&amp;nbsp;"&lt;STRONG&gt;Slaves&lt;/STRONG&gt;" or &lt;STRONG&gt;non-hub&lt;/STRONG&gt; vsys doesn't will share natively their User-ID information to the &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt; or to others "&lt;STRONG&gt;Slaves&lt;/STRONG&gt;" &lt;STRONG&gt;non-hub&lt;/STRONG&gt; &lt;STRONG&gt;vsys&lt;/STRONG&gt;.&amp;nbsp;&lt;SPAN&gt;This mechanism simplifies User-ID source configuration by allowing you to consolidate User-ID sources on a single virtual system the&amp;nbsp;&lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt; "&lt;STRONG&gt;Master&lt;/STRONG&gt;" vsys.&amp;nbsp;The purpose is to ensure all virtual systems have &lt;STRONG&gt;consistent IP-user&lt;/STRONG&gt; mappings from a central vsys.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Workaround for Non-Hub to Hub Redistribution:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;If there is a requirement for IP-user mappings learned by a &lt;STRONG&gt;non-hub&lt;/STRONG&gt; virtual system to be available on the &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt;, a workaround involves configuring the &lt;STRONG&gt;non-hub&lt;/STRONG&gt; virtual system to act as a client to &lt;STRONG&gt;Panorama&lt;/STRONG&gt; or &lt;STRONG&gt;another&lt;/STRONG&gt; &lt;STRONG&gt;NGFW&lt;/STRONG&gt;. In this scenario, &lt;STRONG&gt;Panorama&lt;/STRONG&gt;&amp;nbsp;or the other&amp;nbsp;&lt;STRONG&gt;NGFW&lt;/STRONG&gt; would then learn the IP-user mappings and Group Mapping from the &lt;STRONG&gt;non-hub&lt;/STRONG&gt; virtual system and subsequently redistribute them to the &lt;STRONG&gt;Hub&lt;/STRONG&gt; virtual system. The redistribution path would be:&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="nsc-break-all nsc-inline-block nsc-px-[0.3125em] nsc-py-[0.125em] nsc-bg-[--gen-ui-markdown-code-bg-color] nsc-text-[0.85em] nsc-leading-[1.35em] nsc-font-mono nsc-rounded" data-xid="codespan"&gt;non-hub vsys &amp;gt; Panorama/Other NGFW &amp;gt; hub vsys&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;- If custom &lt;STRONG&gt;Service Routes&lt;/STRONG&gt; are not configured per &lt;STRONG&gt;vsys&lt;/STRONG&gt; on each &lt;STRONG&gt;vsys&lt;/STRONG&gt;, they will all use the &lt;STRONG&gt;Global Service Route&lt;/STRONG&gt; to route their messages to external services such as (&lt;STRONG&gt;DNS, EDL, LDAP, SAML, UIA, etc&lt;/STRONG&gt;.). Therefore, in this scenario, use a single central &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt; with a &lt;STRONG&gt;Central User-ID&lt;/STRONG&gt; configuration to the same sources on it, for example (&lt;STRONG&gt;UIA, User-ID Agentless, Data Redistribution, Group Mapping&lt;/STRONG&gt;), since all this user ID information will be shared with the "&lt;STRONG&gt;Slave&lt;/STRONG&gt;" or &lt;STRONG&gt;non-hub vsys.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;- &lt;SPAN&gt;Consolidate your User-ID sources and migrate them from &lt;STRONG&gt;non-hub&lt;/STRONG&gt; &lt;STRONG&gt;vsys&lt;/STRONG&gt; to the designated &lt;STRONG&gt;User-ID hub virtual system&lt;/STRONG&gt;, removing unnecessary, dupplicated or outdated sources from other &lt;STRONG&gt;non-hub virtual systems.&amp;nbsp;&lt;/STRONG&gt;This setup ensures that if a &lt;STRONG&gt;non-hub&lt;/STRONG&gt; virtual system needs to identify a user for policy enforcement or logging and doesn't find the mapping locally, it will query the &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt; for the necessary information&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;- &lt;SPAN&gt;&lt;STRONG&gt;IP address and Port-to-username&lt;/STRONG&gt; mapping information learned from &lt;STRONG&gt;Terminal Server Agents (TSA)&lt;/STRONG&gt; is not shared between the &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt; and the &lt;STRONG&gt;non-hub virtual systems&lt;/STRONG&gt;&lt;/SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Possible workaround for Central Hub TSA Redistribution (Needs to be tested):&amp;nbsp;&lt;/STRONG&gt;A&lt;SPAN&gt;&amp;nbsp;workaround involves configuring the &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt; virtual system to act as a server to &lt;STRONG&gt;Panorama&lt;/STRONG&gt; or &lt;STRONG&gt;another&lt;/STRONG&gt; &lt;STRONG&gt;NGFW.&lt;/STRONG&gt; In this scenario, &lt;STRONG&gt;Panorama&lt;/STRONG&gt;&amp;nbsp;or the other&amp;nbsp;&lt;STRONG&gt;NGFW&lt;/STRONG&gt; would then learn the &lt;STRONG&gt;IP-user-and-Port mappings&lt;/STRONG&gt; and &lt;STRONG&gt;Group Mapping&lt;/STRONG&gt; from the &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt;&amp;nbsp;virtual system and subsequently redistribute them to the &lt;STRONG&gt;non-hub&lt;/STRONG&gt; virtual system. The redistribution path would be:&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="nsc-break-all nsc-inline-block nsc-px-[0.3125em] nsc-py-[0.125em] nsc-bg-[--gen-ui-markdown-code-bg-color] nsc-text-[0.85em] nsc-leading-[1.35em] nsc-font-mono nsc-rounded" data-xid="codespan"&gt;central hub vsys &amp;gt; Panorama/Other NGFW &amp;gt; non-hub vsys&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;- The current vsys &lt;STRONG&gt;User-ID information&lt;/STRONG&gt; &lt;STRONG&gt;cache&lt;/STRONG&gt; will remain active on every &lt;STRONG&gt;Hub&lt;/STRONG&gt; and &lt;STRONG&gt;non-hub vsys&lt;/STRONG&gt; until there's a new user Logon process that maps the user on the &lt;STRONG&gt;User-ID Hub vsys&lt;/STRONG&gt;. If you change to a central User-ID hub the User-ID configurations (UIA, Agentless, Group Mapping) needs to wait the caché timeout from every non-hub vsys to expire to start learning User-ID information from the central User-ID Hub. If you needs a faster convergence between the &lt;STRONG&gt;User-ID Hub&lt;/STRONG&gt; and &lt;STRONG&gt;non-hub vsys&lt;/STRONG&gt;, make a clear for the user-id information on the specific vsys CLI so the User-ID Hub information then can be distributed to the other vsys.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;- Cheat Sheet CLI vsys User-ID information:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="1014"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="30px"&gt;&lt;STRONG&gt;PAN-OS CLI Command&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="30px"&gt;&lt;STRONG&gt;Function Description / Use Case&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="84px"&gt;&lt;STRONG&gt;show system info | match vsys&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="84px"&gt;Displays basic system properties filtered by the 'vsys' keyword. Crucial for verifying whether the Multi-VSYS capability is enabled on the device and checking the total number of configured virtual systems.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="84px"&gt;&lt;STRONG&gt;show session meter&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="84px"&gt;Displays the maximum concurrent session capacity supported by the current physical hardware or VM model alongside real-time consumption metrics. Helps engineers verify if the firewall is nearing its operational limit.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="84px"&gt;&lt;STRONG&gt;set system setting target-vsys vsys1&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="84px"&gt;Switches the operational context of the current CLI session to a specific virtual system (in this case, 'vsys1'). It allows execution of verification and troubleshooting commands scoped entirely to that target VSYS.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="57px"&gt;&lt;STRONG&gt;show user user-id-agent statistics&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="57px"&gt;Provides comprehensive statistical metrics regarding connections with external User-ID agents. Displays messaging counters, connection health status, and continuous log event parsing rates.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="84px"&gt;&lt;STRONG&gt;show user user-ids all&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="84px"&gt;Displays the complete database of active user identities learned by the firewall. Helpful for confirming that specific user strings are known to the plane and available for security policy matching.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="84px"&gt;&lt;STRONG&gt;show user ip-user-mapping all&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="84px"&gt;Displays the firewall's active IP-to-User mapping table. It provides granular visibility into the source IP address, assigned username, discovery method (Agent, AD, Syslog, etc.), remaining Time-to-Live (TTL), and domain.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="84px"&gt;&lt;STRONG&gt;show user group list&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="84px"&gt;Lists all directory groups that have been successfully retrieved and parsed by the firewall from configured directory sources (such as Active Directory or LDAP servers). Helps verify proper group synchronization.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="84px"&gt;&lt;STRONG&gt;show user group-mapping state all&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="84px"&gt;Shows the health and operational status of all configured Group Mapping profiles. Verifies whether active LDAP/AD communication channels are running normally and timestamps the most recent directory synchronization.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="84px"&gt;&lt;STRONG&gt;show user group-mapping statistics&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="84px"&gt;Provides performance statistics concerning the group mapping process, including total numbers of synchronized groups, user-per-group distributions, and corresponding sub-process memory footprints.&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="314.802px" height="84px"&gt;&lt;STRONG&gt;set system setting target-vsys none&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="698.531px" height="84px"&gt;Reverts the current CLI operational context back to the global default non-vsys mode. Clears the specific VSYS scope so the engineer can run system-wide visibility commands that span across the entire hardware appliance.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your time, and I hope this information is helpful in your daily cybersecurity work. I would greatly appreciate your support by liking or accepting this as a useful post; it would help me a lot in becoming a CyberElite!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Daniel Romero&lt;BR /&gt;Senior Network/Security Engineer&lt;BR /&gt;PANW Partner&lt;BR /&gt;&lt;BR /&gt;&lt;A id="hoverCardLink" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/NGFW/pd-p/NGFW" target="_blank"&gt;NGFW&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A id="hoverCardLink_1" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/GlobalProtect/pd-p/GlobalProtect" aria-controls="hoverCardLink_2-tooltip-element" aria-describedby="hoverCardLink_2-tooltip-element" target="_blank"&gt;GlobalProtect&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A id="hoverCardLink_3" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/User-ID/pd-p/User-ID" target="_blank"&gt;User-ID&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A id="hoverCardLink_5" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/Prisma+Access/pd-p/Prisma_Access" target="_blank"&gt;Prisma Access&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A id="hoverCardLink_7" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/Panorama/pd-p/Panorama" target="_blank"&gt;Panorama&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A id="hoverCardLink_9" class="lia-link-navigation lia-product-hover-card-link lia-product-mention lia-tooltip-trigger" href="https://live.paloaltonetworks.com/t5/c-twzvq79624/Strata+Cloud+Manager/pd-p/Strata_Cloud_Manager" aria-controls="hoverCardLink_10-tooltip-element" aria-describedby="hoverCardLink_10-tooltip-element" target="_blank"&gt;Strata Cloud Manager&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2026 16:36:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-hub-vsys-solved-issue-user-id-behavior/m-p/1256248#M126592</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2026-06-12T16:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: [User-ID HUB Vsys] Solved Issue User-ID Behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-hub-vsys-solved-issue-user-id-behavior/m-p/1256286#M126593</link>
      <description>&lt;P&gt;This Knowledge bases describe the solutions:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CpvSCAS" target="_blank"&gt;Source user information missing from the Traffic logs in multi-... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kI2SCAU" target="_blank"&gt;IP-User mappings are not redistributing from non-hub vsys to th... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2026 19:45:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-hub-vsys-solved-issue-user-id-behavior/m-p/1256286#M126593</guid>
      <dc:creator>DanielS.Romero</dc:creator>
      <dc:date>2026-06-12T19:45:05Z</dc:date>
    </item>
  </channel>
</rss>

