<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reached max allowble probes in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/89070#M43523</link>
    <description>&lt;P&gt;Users have no access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Debug&amp;nbsp; 988]: Reached max allowble probes, adding IP 10.100.xxx.xxx to queue for later processing.&amp;nbsp; Probing 40 IPs, list contains 117 entries&lt;BR /&gt; Reached max allowble probes, adding IP 10.100.xxx.xxx to queue for later processing.&amp;nbsp; Probing 40 IPs, list contains 117 entries&lt;BR /&gt; Probing IP 10.100.xxx.xxx failed. For initial probing, try again after 3 min&lt;BR /&gt; [ Info&amp;nbsp; 938]: IP 10.100.xxx.xxx is already in the probing queue&lt;/P&gt;
&lt;P&gt;[Debug&amp;nbsp; 484]: IP 10.100.xxx.xxx for acme\user cannot be probed.&amp;nbsp; List is full of 201 entries, currently probing 40&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;+0500 Error: pan_user_id_agent_proc_ipuser(pan_user_id_uia.c:444): pan_user_id_agent_send_ip_user_to_dp() failed for user acme\user&lt;/P&gt;
&lt;P&gt;+0500 Error: pan_user_id_uia_handle_ip_msg_i(pan_user_id_uia_v5.c:141): pan_user_id_agent_proc_ipuser(vsys 1, ip 10.100.xxx.xxx, user acme\user, timestamp 1466142528) failed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we can do?&lt;/P&gt;</description>
    <pubDate>Sat, 18 Jun 2016 18:31:57 GMT</pubDate>
    <dc:creator>MaximAvtonenko</dc:creator>
    <dc:date>2016-06-18T18:31:57Z</dc:date>
    <item>
      <title>Reached max allowble probes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/89070#M43523</link>
      <description>&lt;P&gt;Users have no access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Debug&amp;nbsp; 988]: Reached max allowble probes, adding IP 10.100.xxx.xxx to queue for later processing.&amp;nbsp; Probing 40 IPs, list contains 117 entries&lt;BR /&gt; Reached max allowble probes, adding IP 10.100.xxx.xxx to queue for later processing.&amp;nbsp; Probing 40 IPs, list contains 117 entries&lt;BR /&gt; Probing IP 10.100.xxx.xxx failed. For initial probing, try again after 3 min&lt;BR /&gt; [ Info&amp;nbsp; 938]: IP 10.100.xxx.xxx is already in the probing queue&lt;/P&gt;
&lt;P&gt;[Debug&amp;nbsp; 484]: IP 10.100.xxx.xxx for acme\user cannot be probed.&amp;nbsp; List is full of 201 entries, currently probing 40&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;+0500 Error: pan_user_id_agent_proc_ipuser(pan_user_id_uia.c:444): pan_user_id_agent_send_ip_user_to_dp() failed for user acme\user&lt;/P&gt;
&lt;P&gt;+0500 Error: pan_user_id_uia_handle_ip_msg_i(pan_user_id_uia_v5.c:141): pan_user_id_agent_proc_ipuser(vsys 1, ip 10.100.xxx.xxx, user acme\user, timestamp 1466142528) failed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we can do?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jun 2016 18:31:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/89070#M43523</guid>
      <dc:creator>MaximAvtonenko</dc:creator>
      <dc:date>2016-06-18T18:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Reached max allowble probes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/89467#M43537</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Having debug on in&amp;nbsp;a scaled deployment can sometimes cause problems. &amp;nbsp;You could try disabling or lower the debug level to alleviate the problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively you could disable probing :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-User-ID/ta-p/69321" target="_blank"&gt;Getting-Started-User-ID&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Splitting the load over multiple agents is also&amp;nbsp;a good idea in a scaled deployment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 08:07:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/89467#M43537</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-06-20T08:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Reached max allowble probes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/89571#M43542</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem because of NetBIOS probes have &lt;SPAN class="short_text"&gt;&lt;SPAN class=""&gt;queue&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;When we disable NetBIOS probes all users have no access after relogon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Than we enable WMI probes the problem of User-ID disapear&lt;BR /&gt; &lt;BR /&gt; for correct user rights for WMI probes we use:&amp;nbsp;&amp;nbsp; wmic /node:(IP address) computersystem&lt;BR /&gt; get username&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The installation is about 1500 users and 2 User agents.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 11:52:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/89571#M43542</guid>
      <dc:creator>MaximAvtonenko</dc:creator>
      <dc:date>2016-06-20T11:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: Reached max allowble probes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/89806#M43551</link>
      <description>&lt;P&gt;First of all the user to IP mapping should be refreshed at user logon. Please make sure that every logon is generating security events on the LDAP servers and the the agent is able to map them,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Security-Event-IDs-from-Active-Directory-Used-with-User-ID-Agent/ta-p/52448" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Security-Event-IDs-from-Active-Directory-Used-with-User-ID-Agent/ta-p/52448&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems that almost all of your user to ip mapping relies on windows probes which is not ideal, As an alternative method you could enable kerberos SSO in captive portal.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/authentication/configure-kerberos-single-sign-on.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/authentication/configure-kerberos-single-sign-on.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Gerardo.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 18:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/89806#M43551</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2016-06-20T18:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Reached max allowble probes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/167217#M53432</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Probing is more of an active user mapping to verify a user is still linked to a certain IP address. The LDAP server creates user-to-ip mappings where WMI probing actively verifies a user is still valid. The probing variable can be changed from the default setting to a longer duration so that clients are not probed as often or possibly disable probing altogether. When changing the duration, you may set the timer to half the value of your DHCP renewal timer&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By Palo Alto technical support&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 16:53:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reached-max-allowble-probes/m-p/167217#M53432</guid>
      <dc:creator>Matias_Cova</dc:creator>
      <dc:date>2017-07-19T16:53:19Z</dc:date>
    </item>
  </channel>
</rss>

