<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user-id agent issues in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/re-user-id-agent-issues/m-p/241152#M69084</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91991"&gt;@Sanssj&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using&amp;nbsp; windows user-id agent for parsing the user and user group mapping info. often i see in the logs that the user is being not recognized and hitting the deny rule.&amp;nbsp; after couple of minutes it starts recognizing the user and allows the traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I can come up with at least 3 different reasons as to why this could be happening from my own experience, but that might not be the case for you.&amp;nbsp; Can you elaborate&amp;nbsp;on your auth set up more?&amp;nbsp; Have you tried looking into the aging timers and comparing that to the users that are having issues?&lt;/P&gt;</description>
    <pubDate>Mon, 26 Nov 2018 13:48:43 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2018-11-26T13:48:43Z</dc:date>
    <item>
      <title>Re: user-id agent issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-user-id-agent-issues/m-p/241083#M69061</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using&amp;nbsp; windows user-id agent for parsing the user and user group mapping info. often i see in the logs that the user is being not recognized and hitting the deny rule.&amp;nbsp; after couple of minutes it starts recognizing the user and allows the traffic i am skeptical what could be the reason for this disparity.&amp;nbsp; why would any user info and user group mapping info go stale.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;on a different note given the limitation of 10000 user group limitation on PAN&amp;nbsp;what would be best go to approach to overcome this shortage.&lt;BR /&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Nov 2018 07:28:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-user-id-agent-issues/m-p/241083#M69061</guid>
      <dc:creator>Sanssj</dc:creator>
      <dc:date>2018-11-25T07:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: user-id agent issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-user-id-agent-issues/m-p/241092#M69063</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91991"&gt;@Sanssj&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It really depends on how often you have the user-id agent reading the logs, and how often you have the firewall polling your user-id agent. Multiple things to look at here depending on how/when exactly you are running into the issue. Could be anything from the user-id being aged out on the firewall, to logging events not being generated due to where you are pulling the information and your users are just constantly using cached credentials.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the 10,000 user group limitation, when exactly do you think you'll actually have to deal with this limitation? Most companies really don't have to deal with this and don't utilize 10,000 groups in their security policies. If you do, then you break it out to the groups that would actively be utilized on that particular firewall. I've never seen a deployment that couldn't work around the limitations.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Nov 2018 16:58:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-user-id-agent-issues/m-p/241092#M69063</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-25T16:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: user-id agent issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/re-user-id-agent-issues/m-p/241152#M69084</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91991"&gt;@Sanssj&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using&amp;nbsp; windows user-id agent for parsing the user and user group mapping info. often i see in the logs that the user is being not recognized and hitting the deny rule.&amp;nbsp; after couple of minutes it starts recognizing the user and allows the traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I can come up with at least 3 different reasons as to why this could be happening from my own experience, but that might not be the case for you.&amp;nbsp; Can you elaborate&amp;nbsp;on your auth set up more?&amp;nbsp; Have you tried looking into the aging timers and comparing that to the users that are having issues?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 13:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/re-user-id-agent-issues/m-p/241152#M69084</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-11-26T13:48:43Z</dc:date>
    </item>
  </channel>
</rss>

