<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID agent issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271716#M74854</link>
    <description>&lt;P&gt;i follow the link and run the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user ip-user-mapping all type UNKNOWN option count&lt;/P&gt;&lt;P&gt;Total: 122 users&lt;/P&gt;&lt;P&gt;why i am seeing this as unknown?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jun 2019 14:45:28 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-06-20T14:45:28Z</dc:date>
    <item>
      <title>User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269089#M74587</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;currently, we are facing with a strange issue related to user agent. Scenario is that, once the user login to his/her laptop then tries to surf, e/she will get dropped by the firewall. After further investigation, we found that the time the firewall takes to identify the user agent causing the issue.&lt;/P&gt;&lt;P&gt;in other words, user logs in to the laptop try to surf to the internet drops, then about 5-10min later user is now identified. also, our usage to use the internet via the firewall has increase a lot.&lt;/P&gt;&lt;P&gt;so, my question would be, how can we delay the process to identify the user by the firewall, are&amp;nbsp; there any tweaks where we could make some changes. At the moment on user-identification the timers are default (45min for cache )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any advaice?&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;Lance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 09:13:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269089#M74587</guid>
      <dc:creator>Shadow</dc:creator>
      <dc:date>2019-06-12T09:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269091#M74588</link>
      <description>&lt;P&gt;to the above,&lt;/P&gt;&lt;P&gt;OS : 7.1.22&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 09:16:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269091#M74588</guid>
      <dc:creator>Shadow</dc:creator>
      <dc:date>2019-06-12T09:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269275#M74601</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What are the agents looking at to obtain the user-id? Domain controler logs, exchange, etc.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 16:22:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269275#M74601</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-06-12T16:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269484#M74624</link>
      <description>&lt;P&gt;Also increase the timer to 4 hours if you are running the user id agent on windows server&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 04:59:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269484#M74624</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-06-13T04:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269941#M74678</link>
      <description>&lt;P&gt;Hi MP18,&lt;/P&gt;&lt;P&gt;thanks for the response. I take this as the timer is on agent itself. cause I have access only to the firewall.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Lance&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 13:18:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269941#M74678</guid>
      <dc:creator>Shadow</dc:creator>
      <dc:date>2019-06-14T13:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269990#M74681</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87163"&gt;@Shadow&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Timers such as 'Security Log Monitor Frequency' is found on the agent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Monitor Frequency" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20389iEA6B567A9D1A2BA0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rtaImage.png" alt="Monitor Frequency" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Monitor Frequency&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 14:05:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/269990#M74681</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-06-14T14:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/270046#M74685</link>
      <description>&lt;P&gt;thank you, I have a TAC case open already. however, until this resolved they require some kind of workaround. this sounds good&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://ip1.i.lithium.com/993f7a0e2164347a68a1cfa8f1ee34f1dde83a06/68747470733a2f2f7062732e7477696d672e636f6d2f70726f66696c655f696d616765732f3834373036383333353932313638303338342f496a5036347770455f343030783430302e6a7067" alt="Image result for hats off to you" width="160" height="160" border="0" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 14:58:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/270046#M74685</guid>
      <dc:creator>Shadow</dc:creator>
      <dc:date>2019-06-14T14:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271648#M74847</link>
      <description>&lt;P&gt;the issue was too many user mapping been used, max is 100 which could be handled by the firewall and currently 4xx been used.&lt;/P&gt;&lt;P&gt;article : &lt;SPAN class="tabs2_section tabs2_section_2 tabs2_section2 tab_section"&gt;&lt;SPAN class="section "&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRzCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRzCAK&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;credit to : Birk Hageloh (PA TAC)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this would help someone in the feature&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 10:21:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271648#M74847</guid>
      <dc:creator>Shadow</dc:creator>
      <dc:date>2019-06-20T10:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271655#M74848</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87163"&gt;@Shadow&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Great news that it's fixed now !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Max 100 user mappings ? I believe the smallest platform can handle 64000 mappings ?&lt;/P&gt;
&lt;P&gt;Or did you mean a maximum of 100 user-ID-agents ? As explained here :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-web-interface-help/user-identification/device-user-identification-user-id-agents/configure-access-to-user-id-agents.html#" target="_self"&gt;configure-access-to-user-id-agents&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you sure about that link that you added ?&amp;nbsp; It's about PBF &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Can you clarify ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 11:27:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271655#M74848</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-06-20T11:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271686#M74853</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;&lt;P&gt;its about :&amp;nbsp;Unknown IP Rate Limit Mitigation for User-ID Mappings, sorry if I have posted the incorrect link:&lt;/P&gt;&lt;P&gt;Link: &lt;SPAN class="tabs2_section tabs2_section_2 tabs2_section2 tab_section"&gt;&lt;SPAN class="section "&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cls9CAC" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cls9CAC&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If I havent explained on my initial comment.&lt;/P&gt;&lt;P&gt;user logs in to the AD, tries to access the internet, get dropped by the firewall, then after a while(~10-15min) they can access the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we saw the following in the live logs&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;&lt;SPAN&gt;pan user id agent_update_unknown_ip_rate_limit: Unknown IP rate is now 101.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;&lt;SPAN&gt;when it hits above 100 user get match to the incorrect policy(hence the drop)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;&lt;SPAN&gt;once again apologies for false information on my last comment&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 13:32:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271686#M74853</guid>
      <dc:creator>Shadow</dc:creator>
      <dc:date>2019-06-20T13:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271716#M74854</link>
      <description>&lt;P&gt;i follow the link and run the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user ip-user-mapping all type UNKNOWN option count&lt;/P&gt;&lt;P&gt;Total: 122 users&lt;/P&gt;&lt;P&gt;why i am seeing this as unknown?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 14:45:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271716#M74854</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-06-20T14:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271778#M74864</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This simply means that there are 122 clients that the firewall is unable to get user-id information for. Just because you have 122 users as unknown doesn't mean that you'll run into the issue mentioned in the article, but it means you potentially could if you cross the 100 sessions/s metric.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 16:48:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/271778#M74864</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-06-20T16:48:44Z</dc:date>
    </item>
  </channel>
</rss>

