<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Userid Not detected for some traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-not-detected-for-some-traffic/m-p/42702#M31357</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies.&amp;nbsp; We logged a ticket with our support partner and this turns out to be a bug.&amp;nbsp; #64166&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;After approximately 388 days of uptime, the firewall lost the IP address to username mappings on the dataplane. This issue has been addressed so that the firewall does not lose IP address to username mappings when it reaches this uptime.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the firewalls rolled over to 388 days at the weekend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The engineer confirmed by running&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show ip-user-mapping all &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which returned no results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show ip-user-mapping-mp all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;was populated.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The engineer also advised that this issue is only fixed in 6.0.4 and the workaround is a hard reboot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Oct 2014 10:55:39 GMT</pubDate>
    <dc:creator>cdp181</dc:creator>
    <dc:date>2014-10-22T10:55:39Z</dc:date>
    <item>
      <title>Userid Not detected for some traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-not-detected-for-some-traffic/m-p/42699#M31354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using 4 User-id Agents and today some users started experiencing problems with certain sites they use.&amp;nbsp; The same sites for all users.... but not all sites.&amp;nbsp; We have many ad group based rules and some are still working while others seem to have stopped working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the logs I see their userid isn't detected for the blocked traffic but it is for other traffic.&amp;nbsp; Also different AD groups are used by different users and the common factor seems to be the destination IP rather than the AD group used to access it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing appears to have changed and the there is only one userid mapped to the IP of the user.&amp;nbsp; Some users have regained access after logging out and back in... but this has not worked for eveyone.&amp;nbsp; User-ID agents have all been restarted and don't show any problems as far as I can tell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm at a bit of a loss as to how to troubleshoot this really so any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewalls are PA-5050's running 5.0.7&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2014 11:25:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-not-detected-for-some-traffic/m-p/42699#M31354</guid>
      <dc:creator>cdp181</dc:creator>
      <dc:date>2014-10-21T11:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Userid Not detected for some traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-not-detected-for-some-traffic/m-p/42700#M31355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Cdp181,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If logs show no up with no 'user-mapping' for the denied traffic, it could mainly be because of&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i) no ip-user mapping for that ip/user&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : check CLI command &amp;gt;show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;ii) no group mapping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : check &amp;gt; show user group list&lt;/P&gt;&lt;P&gt;iii) the user is not identified part of that group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :check&amp;nbsp; &amp;gt; show user group name "cn=xxxxxx -name of group"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - it will show the way the user id is expecting its users ie domain\username. Make sure it matches with user-ip mapping shown in output i)&lt;/P&gt;&lt;P&gt;iv) security rule has group in its source user part with a 'single user icon(means a user)' rather than 'double user icon(means a group)'&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :In this condition, most likely the group is not identified properly, you can try deleting and adding the groups/users again.&lt;/P&gt;&lt;P&gt;v) Make sure that the source zone has user-identification enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know how it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dileep &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2014 13:41:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-not-detected-for-some-traffic/m-p/42700#M31355</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2014-10-21T13:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Userid Not detected for some traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-not-detected-for-some-traffic/m-p/42701#M31356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi CDP,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its difficult to answer this question in one post, however I will try my best.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First thing is firewall is on 5.0.7 which is atleast one year old release, I would suggest to upgrade to 5.0.13 for future issues. Potentially firewall is effected with one of user-id bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this type of situation its either user-ip mapping issue or group mapping issue. Bottom line is its not a policy or particular destination issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say if user x is having issue, could you please provide me output for&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show user ip-user-mapping ip &amp;lt;x&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will help us to determine potential user-ip or group mapping issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2014 13:41:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-not-detected-for-some-traffic/m-p/42701#M31356</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-21T13:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Userid Not detected for some traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-not-detected-for-some-traffic/m-p/42702#M31357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies.&amp;nbsp; We logged a ticket with our support partner and this turns out to be a bug.&amp;nbsp; #64166&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;After approximately 388 days of uptime, the firewall lost the IP address to username mappings on the dataplane. This issue has been addressed so that the firewall does not lose IP address to username mappings when it reaches this uptime.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the firewalls rolled over to 388 days at the weekend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The engineer confirmed by running&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show ip-user-mapping all &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which returned no results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show ip-user-mapping-mp all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;was populated.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The engineer also advised that this issue is only fixed in 6.0.4 and the workaround is a hard reboot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 10:55:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-not-detected-for-some-traffic/m-p/42702#M31357</guid>
      <dc:creator>cdp181</dc:creator>
      <dc:date>2014-10-22T10:55:39Z</dc:date>
    </item>
  </channel>
</rss>

