<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to probe IP x.x.x.x, list is full with 201 entries, currently probing 40 IPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/169792#M53908</link>
    <description>&lt;P&gt;Do you have user-id enabled on a zone where users are not located?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(if you go to network &amp;gt; zones , check which zones have 'user id' enabled)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any zones where users are not physically located should not have user-id enabled, as the firewall will request the agent for identification for any source ip it sees coming from a zone where user-id is enabled and it doesn't have&amp;nbsp; a mapping for&lt;/P&gt;
&lt;P&gt;so if for example user-id is enabled on the internet zone, the firewall will request authentication for every connection sourced from the internet&lt;/P&gt;
&lt;P&gt;if the agent does not have a mapping, it will try a probe to see if it can find information from the host itself&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if there are too many probe requests you will see the above issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there are several solutions:&lt;/P&gt;
&lt;P&gt;-disable user-id on inappropriate zones,&lt;/P&gt;
&lt;P&gt;-move user-id networks to a different zone/interface from non-user-id networks&lt;/P&gt;
&lt;P&gt;-add an ip include/exclude list to the user-id agent,&lt;/P&gt;
&lt;P&gt;-disable probing&lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2017 09:53:46 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-08-03T09:53:46Z</dc:date>
    <item>
      <title>Unable to probe IP x.x.x.x, list is full with 201 entries, currently probing 40 IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/38462#M28185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have two PA Boxes(4.1.9) and one User-ID Agent(5.0.4-5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've got unknown message from User-ID Agent log. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===== UaDebug Log =====&lt;/P&gt;&lt;P&gt; 06/17/13 08:57:50:139[Debug&amp;nbsp; 911]: Unable to probe IP 172.19.73.93, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt; 06/17/13 08:57:50:139[Debug&amp;nbsp; 911]: Unable to probe IP 10.201.120.66, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt; 06/17/13 08:57:50:139[Debug&amp;nbsp; 911]: Unable to probe IP 10.200.107.46, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt; 06/17/13 08:57:50:139[Debug&amp;nbsp; 911]: Unable to probe IP 10.40.29.211, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt; 06/17/13 08:57:50:139[Debug&amp;nbsp; 911]: Unable to probe IP 10.200.158.12, list is full with 201 entries, currently probing 40 IPs&lt;/P&gt;&lt;P&gt;=====================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP address 192.19.73.93 is not my internal address, and IP 10.40.29.211 also located in outside of the PA. &lt;/P&gt;&lt;P&gt;As a note, i don't set a Access Control List in the Palo Alto Networks User-ID Agent(User Identification &amp;gt; Setup &amp;gt; Access Control List).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. why do i receive many unable to probe IP message?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; is it problem of the performance problem of the User-ID Agent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. what mean that the message of the unable to probe IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. why the log showing the external IP address in the UaDebug log ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know who know of it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Eugene.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 00:54:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/38462#M28185</guid>
      <dc:creator>willstech</dc:creator>
      <dc:date>2013-06-17T00:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to probe IP x.x.x.x, list is full with 201 entries, currently probing 40 IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/38463#M28186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; wmi probing is not successful so you see that logs.&lt;/P&gt;&lt;P&gt;you can disable wmi from agent(or enable wmi and use an account with privilages)&lt;/P&gt;&lt;P&gt;There is an include and exclude list you can configure inside agent.include only LAN network(Access control list is not for that usage.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 06:16:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/38463#M28186</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-17T06:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to probe IP x.x.x.x, list is full with 201 entries, currently probing 40 IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/169730#M53894</link>
      <description>Sorry i do not understand . Could you let me know how to fix this problem. I am getting the same issue log. Thank you</description>
      <pubDate>Thu, 03 Aug 2017 06:16:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/169730#M53894</guid>
      <dc:creator>Frries</dc:creator>
      <dc:date>2017-08-03T06:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to probe IP x.x.x.x, list is full with 201 entries, currently probing 40 IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/169768#M53898</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Probing is a mechanism for firewall to verify&amp;nbsp;if a user is still linked to a certain IP address. The LDAP server creates user-to-ip mappings where WMI probing actively verifies a user is still valid.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If the probing cache gets too full. Firewall has a limit to how many IPs it can probe at a givem point of time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If the probing interval is too aggressive you have&amp;nbsp;more chances of running into this issue. You can adjust the probing interval to a more appropriate value to avoid this.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 08:42:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/169768#M53898</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2017-08-03T08:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to probe IP x.x.x.x, list is full with 201 entries, currently probing 40 IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/169792#M53908</link>
      <description>&lt;P&gt;Do you have user-id enabled on a zone where users are not located?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(if you go to network &amp;gt; zones , check which zones have 'user id' enabled)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any zones where users are not physically located should not have user-id enabled, as the firewall will request the agent for identification for any source ip it sees coming from a zone where user-id is enabled and it doesn't have&amp;nbsp; a mapping for&lt;/P&gt;
&lt;P&gt;so if for example user-id is enabled on the internet zone, the firewall will request authentication for every connection sourced from the internet&lt;/P&gt;
&lt;P&gt;if the agent does not have a mapping, it will try a probe to see if it can find information from the host itself&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if there are too many probe requests you will see the above issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there are several solutions:&lt;/P&gt;
&lt;P&gt;-disable user-id on inappropriate zones,&lt;/P&gt;
&lt;P&gt;-move user-id networks to a different zone/interface from non-user-id networks&lt;/P&gt;
&lt;P&gt;-add an ip include/exclude list to the user-id agent,&lt;/P&gt;
&lt;P&gt;-disable probing&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 09:53:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/169792#M53908</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-08-03T09:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to probe IP x.x.x.x, list is full with 201 entries, currently probing 40 IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/169856#M53924</link>
      <description>&lt;P&gt;I ran into a similar issue and it was due to another admin enabling user-id on my DMZ connection so that we could get user-id information from 1 server. What he didn't realize was that all our other DMZ machines aren't tied to the domain , so enabling it on that zone didn't really have any good effects.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 15:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-probe-ip-x-x-x-x-list-is-full-with-201-entries/m-p/169856#M53924</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-03T15:03:42Z</dc:date>
    </item>
  </channel>
</rss>

