<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clientless User-ID problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33082#M24240</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I deleted the servers, discovered them again, re-entered the credentials and didn't get the same error again. Customer has also been changing rights on user account so I'm not sure what solved the issue. However it would be good to get some explanation about what that error message actually means and how to solve it if it happens again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now I am encountering situation, where PA is able to connect to one of 2 AD servers and is getting 'access denied' for the other. The user has domain admin rights, both servers are in same domain and in the same network. So i can only assume that their AD cluster has some issues. Has anyone encountered similar situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, &lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Apr 2014 13:57:16 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2014-04-10T13:57:16Z</dc:date>
    <item>
      <title>Clientless User-ID problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33078#M24236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When debugging clientless User-ID I've noticed a strange entry in useridd.log log file. I'm trying to connect to 2 AD servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2014-04-07 10:44:09.875 +0200 Error:&amp;nbsp; pan_user_id_win_log_query(pan_user_id_win.c:1319): log query for server1.xyz.aa failed: [lib/socket/interface.c:212:load_in&lt;/P&gt;&lt;P&gt;terfaces()] ERROR: Could not determine network interfaces, you must use a interfaces config line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't find any info about this entry. Any ideas what does it mean?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For 2nd server I'm getting more usual error message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2014-04-07 10:51:54.723 +0200 Error:&amp;nbsp; pan_user_id_win_log_query(pan_user_id_win.c:1319): log query for server2.xyz.aa failed: [wmi/wmic.c:200:main()] ERROR: Log&lt;/P&gt;&lt;P&gt;in to remote object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both are of course listed as 'access denied'. Both servers are reachable and in same network. I'm pretty certain 2nd error means insufficient rights on user credentials. But 1st error looks strange and I can't find any info about it.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Apr 2014 08:56:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33078#M24236</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-04-07T08:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless User-ID problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33079#M24237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First question, are You able to ping from CLI to your AD servers? if not - You must configure Device&amp;gt;Setup&amp;gt;Services&amp;gt;Service Route Configuration&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Apr 2014 10:21:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33079#M24237</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-04-07T10:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless User-ID problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33080#M24238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep, i can resolve both names and ping them both. I already checked Service Route Configuration and everything is on default.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Apr 2014 11:57:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33080#M24238</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-04-07T11:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless User-ID problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33081#M24239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a test use a domain admin account, the first error message speaks of [lib/socket/interface.c:212:load_interfaces()] ERROR ===&amp;gt; To me it looks like its unable to open a socket for connection, restart the useridd agent should take of it since it would teardown and open new sockets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Deepak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Apr 2014 13:38:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33081#M24239</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2014-04-07T13:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless User-ID problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33082#M24240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I deleted the servers, discovered them again, re-entered the credentials and didn't get the same error again. Customer has also been changing rights on user account so I'm not sure what solved the issue. However it would be good to get some explanation about what that error message actually means and how to solve it if it happens again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now I am encountering situation, where PA is able to connect to one of 2 AD servers and is getting 'access denied' for the other. The user has domain admin rights, both servers are in same domain and in the same network. So i can only assume that their AD cluster has some issues. Has anyone encountered similar situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, &lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Apr 2014 13:57:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33082#M24240</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-04-10T13:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless User-ID problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33083#M24241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Simon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please create dedicated AD user for PAN very carefully according to manual of User-ID, this part is very important, also configuration of domain controllers (rights for this user).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reagrds&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Apr 2014 16:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33083#M24241</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-04-10T16:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless User-ID problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33084#M24242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-5404" title="https://live.paloaltonetworks.com/docs/DOC-5404"&gt;https://live.paloaltonetworks.com/docs/DOC-5404&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw a case even domain admin did not work and we created a user with the above rights.And it worked.&lt;/P&gt;&lt;P&gt;This was because some changes has been done on DC(for admin accoıunt) in the past.Maybe it will work for you too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Apr 2014 20:12:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33084#M24242</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-04-10T20:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Clientless User-ID problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33085#M24243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep, we started with dedicated user with only required permissions according to PA guide. However customer has 2003 AD and 'event reader' groups is not present there. So instead of going through specific procedure for 2003 AD permissions (also described in one of the PA guides), the customer decided to give domain admin rights to the user. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2014 08:03:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/clientless-user-id-problem/m-p/33085#M24243</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-04-14T08:03:01Z</dc:date>
    </item>
  </channel>
</rss>

