<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agentless User-ID &amp;quot;Not Connected&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226680#M65254</link>
    <description>&lt;P&gt;you can use tcpdump&amp;nbsp;in the CLI and filter for your AD to see if packets are going out and being replied to properly&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(view by&amp;nbsp;&lt;SPAN class="s1"&gt;&amp;gt; view-pcap mgmt-pcap mgmt.pcap )&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Aug 2018 07:24:39 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-08-10T07:24:39Z</dc:date>
    <item>
      <title>Agentless User-ID "Not Connected"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226606#M65227</link>
      <description>&lt;P&gt;PAN-OS 8.0.9&lt;/P&gt;&lt;P&gt;Server 2008-R2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am in the process of investigating the setup of User-ID, utilising our test network which has a&amp;nbsp;VM500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am starting using the Agentless option. ( The production site has 500 users, mostly Citrix Terminal Sessions but also Some PC's so I guess I will also need the TS agent further down the line.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done the three basic steps that seem to be outlined in every guide&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create service account with Domain Admin privs.&lt;/P&gt;&lt;P&gt;In user mapping server monitorig Discovered the DC's...&lt;/P&gt;&lt;P&gt;added the WMI Authentication Creds on agent setup.&lt;/P&gt;&lt;P&gt;Committed...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But all i get is "Status [Not Connected]"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can't seem to find any info on why it's nto working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 15:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226606#M65227</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-09T15:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID "Not Connected"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226618#M65231</link>
      <description>&lt;P&gt;By default the user id will try to connect to the server via management port. If this is an issue then change it in device/setup/services&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there are other rasons but start with this one as it caught me out...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*reasons not rasons lol.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 17:05:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226618#M65231</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-09T17:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID "Not Connected"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226680#M65254</link>
      <description>&lt;P&gt;you can use tcpdump&amp;nbsp;in the CLI and filter for your AD to see if packets are going out and being replied to properly&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(view by&amp;nbsp;&lt;SPAN class="s1"&gt;&amp;gt; view-pcap mgmt-pcap mgmt.pcap )&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 07:24:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226680#M65254</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-08-10T07:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID "Not Connected"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226684#M65255</link>
      <description>&lt;P&gt;Well the PCAP did not give much joy, although it did show some "ICMP unreachable" to the server...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The server Pinged fine on the CLI by&amp;nbsp;"ShortDN" and "FQDN"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HunchTime.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So althoug I could ping from the management interface, there seemed to be some issue with the Management Plane making some connection via DNS entry..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added another server in the list but specified it by IP rather than DNS name... Committed , Connected!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No idea if the production environment will have the same issue but at least I have a workarround..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 09:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226684#M65255</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-08-10T09:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless User-ID "Not Connected"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226686#M65256</link>
      <description>&lt;P&gt;ok nice one...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why dont you just modify the original server entry to "IP Address" just to make sure its nothing else in that server config causing the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also add fqdn to second entry...&amp;nbsp; just for dns test purpose&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 09:26:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-quot-not-connected-quot/m-p/226686#M65256</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-10T09:26:05Z</dc:date>
    </item>
  </channel>
</rss>

