<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID in FIPS-CC in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-in-fips-cc/m-p/1264309#M127006</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1367185885"&gt;@G.Williamson789500&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There might be a mismatch or incompatibility in the secure communication settings between the firewall in FIPS-CC mode and DC-A which could be why youre not seeing any connection attempts. I would run a packet capture, Even if number of attempts is reported at 0, it's possible that very early SSL negotiation attempts are failing before a full connection attempt is logged. Also, If you enter "less mp-log distributord.log" , do you see any related ssl/tls errors?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2026 00:59:08 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2026-09-15T00:59:08Z</dc:date>
    <item>
      <title>User-ID in FIPS-CC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-in-fips-cc/m-p/1264216#M126996</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am having an issue setting up user-id when the firewall is in FIPS-CC mode. Here is the following issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL dir="ltr"&gt;
&lt;LI&gt;PA-3440, PAN-OS 11.2.10-h7, FIPS-CC mode enabled&lt;/LI&gt;
&lt;LI&gt;Windows User-ID Agent v11.0.3-134 (identical version on both hosts)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;BR /&gt;I have two Windows-based User-ID Agents configured under &lt;STRONG&gt;Device &amp;gt; Data Redistribution &amp;gt; Agents&lt;/STRONG&gt;, pointing to two domain controllers (DC-A and DC-B) with identical config (same port 5007, same vsys, both enabled). DC-B connects fine. DC-A has never connected, and it looks like the firewall isn't even attempting a connection to it.&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;Key diagnostic finding:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV tabindex="0" role="group" aria-label="Code"&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;PRE&gt;&lt;CODE&gt;&amp;gt; show user user-id-agent statistics
Name    Host     Port  Vsys    State       Ver
DC-B    ...      5007  vsys1   conn:idle   5

&amp;gt; show redistribution agent statistics
Name    Host     Port  Vsys    State           Ver
DC-A    ...      5007  vsys1   not-conn:idle   6&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P dir="ltr"&gt;DC-B is registering under the legacy &lt;STRONG&gt;User-ID Agent (protocol v5)&lt;/STRONG&gt; handler and connects successfully. DC-A is registering under the newer &lt;STRONG&gt;Redistribution Agent (protocol v6)&lt;/STRONG&gt; handler, and &lt;CODE&gt;show redistribution agent state DC-A&lt;/CODE&gt; shows &lt;STRONG&gt;&lt;CODE&gt;num of connection tried: 0&lt;/CODE&gt;&lt;/STRONG&gt; — zero attempts, ever.&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;STRONG&gt;Already ruled out:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL dir="ltr"&gt;
&lt;LI&gt;Network path — clean ping to DC-A, 0% loss, tested both default and sourced from mgmt interface&lt;/LI&gt;
&lt;LI&gt;Agent software version — confirmed identical on both DCs&lt;/LI&gt;
&lt;LI&gt;Config/commit — DC-A entry exists, enabled, commits without error; also tried full delete + clean re-add, no change&lt;/LI&gt;
&lt;LI&gt;Collector Settings (Device &amp;gt; Data Redistribution &amp;gt; Collector Settings) — unconfigured on both, ruled out as a factor&lt;/LI&gt;
&lt;LI&gt;Unrelated LDAPS/group-mapping connections to both DCs (port 636) are working fine, so it's not a broader connectivity/cert issue to that DC&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Has anyone run into this issue and any suggestions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 19:56:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-in-fips-cc/m-p/1264216#M126996</guid>
      <dc:creator>G.Williamson789500</dc:creator>
      <dc:date>2026-09-11T19:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID in FIPS-CC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-in-fips-cc/m-p/1264309#M127006</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1367185885"&gt;@G.Williamson789500&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There might be a mismatch or incompatibility in the secure communication settings between the firewall in FIPS-CC mode and DC-A which could be why youre not seeing any connection attempts. I would run a packet capture, Even if number of attempts is reported at 0, it's possible that very early SSL negotiation attempts are failing before a full connection attempt is logged. Also, If you enter "less mp-log distributord.log" , do you see any related ssl/tls errors?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 00:59:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-in-fips-cc/m-p/1264309#M127006</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-09-15T00:59:08Z</dc:date>
    </item>
  </channel>
</rss>

