<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues getting  ip-user mapping with probing error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issues-getting-ip-user-mapping-with-probing-error/m-p/21076#M15381</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The agent settings are set to default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Part of the log also shows below. So, should we be probing ips like that? &lt;/P&gt;&lt;P&gt;Using only AD method and could it be a problem with an inability to read the security log?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.45.81, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.17.21, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.58.111, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.96.188, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.96.224, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.110.78, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.51.184, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Mar 2013 18:01:13 GMT</pubDate>
    <dc:creator>vinesh</dc:creator>
    <dc:date>2013-03-01T18:01:13Z</dc:date>
    <item>
      <title>Issues getting  ip-user mapping with probing error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-getting-ip-user-mapping-with-probing-error/m-p/21074#M15379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got UI agent 4.1.6 configured on PanOS 4.1.9.&lt;/P&gt;&lt;P&gt;We have around 3000 users and in agent we see only around 700 user-mapping count.&lt;/P&gt;&lt;P&gt;in the logs we get the below error for a lot of IPs and i guess that's why we dont get all users. I've tried to disable WMI but still doesnt work.&lt;/P&gt;&lt;P&gt;Have anyone experienced a similar iissue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2/22/13 08:17:29:688[ Info&amp;nbsp; 856]: IP 10.76.15.140 is already in the probing queue&lt;/P&gt;&lt;P&gt;02/22/13 08:17:29:688[ Info&amp;nbsp; 856]: IP 10.76.45.123 is already in the probing queue&lt;/P&gt;&lt;P&gt;02/22/13 08:17:29:688[ Info&amp;nbsp; 856]: IP 10.76.15.205 is already in the probing queue&lt;/P&gt;&lt;P&gt;02/22/13 08:17:29:688[ Info&amp;nbsp; 856]: IP 10.76.15.196 is already in the probing queue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 17:04:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-getting-ip-user-mapping-with-probing-error/m-p/21074#M15379</guid>
      <dc:creator>vinesh</dc:creator>
      <dc:date>2013-03-01T17:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting  ip-user mapping with probing error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-getting-ip-user-mapping-with-probing-error/m-p/21075#M15380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have not seen it, but I am curious what your probing interval currently is set at.&lt;/P&gt;&lt;P&gt;At the same point in time, I am not sure I understand why disabling this would attempt to resolve this issue. &lt;/P&gt;&lt;P&gt;&lt;EM&gt;Remember that active probing is for anyone that is NOT known. &lt;/EM&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So before you troubleshoot that portion, you need go back to step 1.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are 2 steps to get UserID working (FW connecting to LDAP server) and (getting user to IP mappings). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are 6 ways (at least) to get IPs (Security Login/Logff from AD/Exchange, WMI, CP, XML API, etc) So...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the question you should ask is: &lt;EM&gt;&lt;STRONG&gt;WHY is the UserID agent not able to query your AD to determine who your IP users are?&lt;/STRONG&gt;&lt;/EM&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Remember that active probing is for anyone that is NOT known, and to confirm that a User still has IP address that is cached.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is your user id cache set for?&amp;nbsp; Is it the default (45 minutes)?&amp;nbsp; &lt;/P&gt;&lt;P&gt;Maybe you can increase to 1/2 of your DHCP time(which is when users will ask for their same IP from your DHCP server).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 17:38:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-getting-ip-user-mapping-with-probing-error/m-p/21075#M15380</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-03-01T17:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting  ip-user mapping with probing error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-getting-ip-user-mapping-with-probing-error/m-p/21076#M15381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The agent settings are set to default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Part of the log also shows below. So, should we be probing ips like that? &lt;/P&gt;&lt;P&gt;Using only AD method and could it be a problem with an inability to read the security log?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.45.81, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.17.21, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.58.111, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.96.188, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.96.224, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.110.78, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;02/21/13 11:37:47:675[Debug&amp;nbsp; 838]: Unable to probe IP 10.74.51.184, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 18:01:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-getting-ip-user-mapping-with-probing-error/m-p/21076#M15381</guid>
      <dc:creator>vinesh</dc:creator>
      <dc:date>2013-03-01T18:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting  ip-user mapping with probing error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-getting-ip-user-mapping-with-probing-error/m-p/21077#M15382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmmm, this gets tough to answer. I think that if you are getting some AD information, then you are reading security logs. I think I would turn OFF probing entirely (for now), so that you can focus on troubleshooting the UserID issue. I would change the timeout to 1/2 of your DHCP timer (so if DHCP is 8 hours, change cache to 4 hours), you need to effectively make some change to see if it a positive change or no change. I do not know the limits of how many IPs can be probed, but maybe the 201 entries is the max amount.&amp;nbsp; So, I would stop probing.&amp;nbsp; The net effect is that you have not lost any UserID information, because that is what we are troubleshooting. Make sure your UserID has the proper permissions to reach the Security Logs on the AD. Do you have the FW communicating to the LDAP server directly, or are you using the UserID agent in LDAP proxy mode? Is the FW and the DC in the same location (not across a WAN link, etc)? Ultimately, I would not have a problem creating a TAC case in this issue.&amp;nbsp; That is why there are here.&amp;nbsp; We the in the community can provide guidelines to help, but of course TAC will be the best to T-shoot and resolve this. Let me know what you find.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 19:39:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-getting-ip-user-mapping-with-probing-error/m-p/21077#M15382</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-03-01T19:39:25Z</dc:date>
    </item>
  </channel>
</rss>

