<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-id error after commit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-error-after-commit/m-p/330430#M83760</link>
    <description>&lt;P&gt;I have setup user-id mapping using the instruction here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent.html#idf8932678-911a-4153-ab89-94f19b988aef" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent.html#idf8932678-911a-4153-ab89-94f19b988aef&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 servers with the user-id agent and 2 servers with the terminal server agent all set up and working. If I go into monitoring, i can see logs populating just fine and if I go into the cli and run&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;All the users show up mapped correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Initially, we were trying to do user mapping by implementing&amp;nbsp;User Mapping Using the PAN-OS Integrated User-ID Agent. We didn't like this solution and backed it all out.&amp;nbsp; In the 2 weeks since, the only thing we did was upgrade the Pan-Os to version 9.0.8 and now when we run a commit, we intermittently receive the following error:&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;user-id-service is enabled, but no user-id-agent is configured for&amp;nbsp;ntlm-auth&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;I think this may be left over from when we were trying to implement the integrated user-id agent. I have searched for a similar error but can't find anything close.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;In the firewall, in device&amp;gt;user identification&amp;gt; user-ID agents, in the properties of the server, do I need to check the "&lt;SPAN&gt;Use for NTLM Authentication" check box since we are still using NTLM authentication to clear the error?&lt;/SPAN&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2020 22:46:49 GMT</pubDate>
    <dc:creator>RussMcIntire</dc:creator>
    <dc:date>2020-05-28T22:46:49Z</dc:date>
    <item>
      <title>User-id error after commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-error-after-commit/m-p/330430#M83760</link>
      <description>&lt;P&gt;I have setup user-id mapping using the instruction here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent.html#idf8932678-911a-4153-ab89-94f19b988aef" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent.html#idf8932678-911a-4153-ab89-94f19b988aef&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 servers with the user-id agent and 2 servers with the terminal server agent all set up and working. If I go into monitoring, i can see logs populating just fine and if I go into the cli and run&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;All the users show up mapped correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Initially, we were trying to do user mapping by implementing&amp;nbsp;User Mapping Using the PAN-OS Integrated User-ID Agent. We didn't like this solution and backed it all out.&amp;nbsp; In the 2 weeks since, the only thing we did was upgrade the Pan-Os to version 9.0.8 and now when we run a commit, we intermittently receive the following error:&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;user-id-service is enabled, but no user-id-agent is configured for&amp;nbsp;ntlm-auth&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;I think this may be left over from when we were trying to implement the integrated user-id agent. I have searched for a similar error but can't find anything close.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;In the firewall, in device&amp;gt;user identification&amp;gt; user-ID agents, in the properties of the server, do I need to check the "&lt;SPAN&gt;Use for NTLM Authentication" check box since we are still using NTLM authentication to clear the error?&lt;/SPAN&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 22:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-error-after-commit/m-p/330430#M83760</guid>
      <dc:creator>RussMcIntire</dc:creator>
      <dc:date>2020-05-28T22:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: User-id error after commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-error-after-commit/m-p/331811#M83965</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135892"&gt;@RussMcIntire&lt;/a&gt;the very short answer is: yes &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;at least one of your agents needs to be the NTLM relay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 07:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-error-after-commit/m-p/331811#M83965</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-06-05T07:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: User-id error after commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-error-after-commit/m-p/331976#M83991</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the reply.&amp;nbsp;I checked the "Use for NTLM Authentication" check box for both servers and the error cleared. I find it odd it did not show up until after the Pan-OS upgrade to 9.0.8 from 8.1.10. We ran this config for nearly 2 weeks with no issue before then. Thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 19:45:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-error-after-commit/m-p/331976#M83991</guid>
      <dc:creator>RussMcIntire</dc:creator>
      <dc:date>2020-06-05T19:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: User-id error after commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-error-after-commit/m-p/331980#M83992</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135892"&gt;@RussMcIntire&lt;/a&gt;&amp;nbsp; I can only venture a guess:&lt;/P&gt;&lt;P&gt;maybe the check didn't exist prior to 9.0 or didn't include the clientless configuration&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 20:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-error-after-commit/m-p/331980#M83992</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-06-05T20:14:17Z</dc:date>
    </item>
  </channel>
</rss>

