<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some Users not Mapping in User-ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73463#M41444</link>
    <description>&lt;P&gt;&amp;gt; What PAN-OS version are you running ?&lt;/P&gt;</description>
    <pubDate>Wed, 24 Feb 2016 17:52:21 GMT</pubDate>
    <dc:creator>vkalal</dc:creator>
    <dc:date>2016-02-24T17:52:21Z</dc:date>
    <item>
      <title>Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73445#M41434</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I'm currently experiencing some issues with user-id mapping. Some users are not being mapped to IP addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Current setup: I have 3 domain controllers - all have Service Accounts with correct privileges. They are also showing as 'Connected'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I ran the command 'show user server-monitor state all' on the CLI and noticed that one of the servers showed some failed queries:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Server: A(vsys: vsys1)&lt;BR /&gt; Host: 10.2.2.59&lt;BR /&gt; num of log query made : 27600&lt;BR /&gt; num of log query failed : 2660&lt;BR /&gt; num of log read : 647253&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other than this, I can't find anything that could be amiss.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas please?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 16:03:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73445#M41434</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2016-02-24T16:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73449#M41438</link>
      <description>&lt;P&gt;Have you enabled User Identification on the appropriate zone?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 16:16:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73449#M41438</guid>
      <dc:creator>Ash2k</dc:creator>
      <dc:date>2016-02-24T16:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73450#M41439</link>
      <description>&lt;P&gt;&amp;gt; Uncheck the LDAP Proxy&lt;/P&gt;
&lt;P&gt;&amp;gt; check the bind DN is should be in the format : adminstartor@domain.com&lt;/P&gt;
&lt;P&gt;&amp;gt; Check the event logs on AD if you are able to see the logon events for any of the test user&lt;/P&gt;
&lt;P&gt;&amp;gt; Clear user cache by commad clear user-cache all&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 16:18:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73450#M41439</guid>
      <dc:creator>vkalal</dc:creator>
      <dc:date>2016-02-24T16:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73457#M41441</link>
      <description>&lt;P&gt;Yes...it has definitely been enabled that's why some users are being mapped. Some others are not being mapped though&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 17:29:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73457#M41441</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2016-02-24T17:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73458#M41442</link>
      <description>&lt;P&gt;Hi Vkalal,&lt;/P&gt;
&lt;P&gt;I'm not using the user-id agent so I don't believe i need to Uncheck LDAP Proxy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll clear the cache and test results&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 17:36:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73458#M41442</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2016-02-24T17:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73462#M41443</link>
      <description>&lt;P&gt;&amp;gt; You can also check if you are able to see the mappings in mangement plane&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;show user ip-user-mapping-mp all&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 17:49:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73462#M41443</guid>
      <dc:creator>vkalal</dc:creator>
      <dc:date>2016-02-24T17:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73463#M41444</link>
      <description>&lt;P&gt;&amp;gt; What PAN-OS version are you running ?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 17:52:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73463#M41444</guid>
      <dc:creator>vkalal</dc:creator>
      <dc:date>2016-02-24T17:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73464#M41445</link>
      <description>&lt;P&gt;Hi Bocsa,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are mapping some users, but not all, could it be that those users are from specific AD group that's not mapped properly?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show user group-mapping state &amp;lt;value&amp;gt;|&amp;lt;all&amp;gt;&lt;BR /&gt;show user group-mapping statistics&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If that's not the case, can you check logs for that particular user (that is not mapped) on all three servers? Could they be mis-matching? Silly question, but also - are your clocks all the same on servers (do they have same NTP server and are they all updating clock properly?) Reason why I ask is that sometimes, when user mappings are shared between servers but one of them has clock that is slightly off, that can produce unwanted results as it depends what logs are parsed last and what was the event.&lt;/P&gt;
&lt;P&gt;If possible, I would also try to simply use only one of three servers temporarily (and test all of them separately, one by one) to see if I will have any missing users when mapping from a single server, that might be faster than looking through the logs of all three servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If that is not the case either, and you cannot find much in the logs on the server side, try raising debug level on the user-id daemon; by default it is on info level. From cli, you can set:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;debug user-id on dump&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;run your diagnostics (get problematic user to log on and log off) and than review logs for that username:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;less mp-log useridd.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When "inside" the log, you can use commands from linux's less command - use / to search for username, etc...&lt;/P&gt;
&lt;P&gt;once you are done, re-set debug level for user-id by doing:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;debug user-id on info&lt;/P&gt;
&lt;P&gt;debug user-id get&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Last, but not the least - what is the uptime of your device? (you can see that from "show system info" in cli). There was a bug where UserID stopped working after 388 days, but that has been fixed long ago, applies only if you are running an old release. If this is the case, simply restart UserID daemon &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If nothing from above helps.... let us know or reach out to TAC and inform them what have you done already to diagnose this &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 18:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73464#M41445</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-02-24T18:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73540#M41454</link>
      <description>&lt;P&gt;Hi Luciano,&lt;/P&gt;
&lt;P&gt;thanks for the suggestions. I'll run some debugs. It definitely hasn't been up for up to 388days.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to clear the log query counters on the Palo? ie&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Server: (vsys: vsys1)&lt;BR /&gt; Host: 192.168.24.51&lt;BR /&gt; &lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;num of log query made : 1008950&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;BR /&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt; num of log query failed : 50&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;BR /&gt; num of log read : 13225867&lt;BR /&gt; last record timestamp : 1456398701&lt;BR /&gt; last record time : 20160225111141.782341-000&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 11:13:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73540#M41454</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2016-02-25T11:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Some Users not Mapping in User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73545#M41458</link>
      <description>&lt;P&gt;For the users whose user-ip mapping is not coming on the firewall for that users do you have security event logs on any of the domain controller. You have to check the security event logs of all domain controller.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check if you have configured&amp;nbsp;any included/excluded network&amp;nbsp;on firewall under user-identification or on user-id agent.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 13:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/some-users-not-mapping-in-user-id/m-p/73545#M41458</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-02-25T13:40:10Z</dc:date>
    </item>
  </channel>
</rss>

