<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does User-ID suddenly stops ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-user-id-suddenly-stops/m-p/1098#M855</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While I don't know exactly why this is happening, there have been a great deal of fixes to various User-ID issues between 5.0.2 and 5.0.9. Some of the changes were indeed regarding ip-to-user mappings not displaying in logs, so it might be worth upgrading to 5.0.9 to see if the issue is resolved before going with a support ticket.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, you can also turn on debugging in the user ID process and tail the log. When the mapping starts to show up blank, turn off debugging and parse through the log to see what may be happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turn on the debug:&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id on debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turn off the debug:&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id on info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Parse through the log (uses standard linux "less" navigation):&lt;/P&gt;&lt;P&gt;&amp;gt; less mp-log useridd.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That may help explain what is going on when the mapping stops to display.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Dec 2013 17:10:58 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2013-12-11T17:10:58Z</dc:date>
    <item>
      <title>Why does User-ID suddenly stops ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-user-id-suddenly-stops/m-p/1097#M854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a customer who is using &lt;STRONG&gt;PA-3020 in L3 A/P cluster, running PanOS 5.0.2&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have set up &lt;STRONG&gt;User-ID with PanAgent services&lt;/STRONG&gt; (Primary and Secondary) installed on two different servers members of the domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User-ID is configured to be based on :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Security logs&lt;/P&gt;&lt;P&gt;- Sessions&lt;/P&gt;&lt;P&gt;- Probing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On 4 different servers :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- 2 AD servers&lt;/P&gt;&lt;P&gt;- 2 Exchange servers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The User-ID agents and the monitored servers are all &lt;STRONG&gt;well connected&lt;/STRONG&gt;, and there is&lt;STRONG&gt; nothing wrong in the system logs regarding User-ID&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of the time, all is working fine : users are well identified and thus the proper rules are applied (based on user groups).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it seems that sometimes the User-ID just stops, and the users are no more identified. Indeed, we can see in the traffic log monitoring that the &lt;EM&gt;&lt;STRONG&gt;Source User&lt;/STRONG&gt;&lt;/EM&gt; field is empty. As a result, the applied rule is not the right one and the URL Filtering profile that is applied is not the expected one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer is obviously complaining about this and I don't really know how to figure out what's wrong with this User-ID...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see on the following prinscreen that the Source User field is suddenly empty, and starting this point, the matched rule is of course not the same.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/10226_pastedImage_2.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user-ID agents are connected as you can see&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="10224" alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/10224_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the monitored servers as well&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="10223" alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/10223_pastedImage_8.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, &lt;STRONG&gt;the User-ID restarts after just 1 hour&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/10225_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I monitor the User-ID and ensure that this won't occur again ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or maybe this is a bug ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Dec 2013 09:45:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-user-id-suddenly-stops/m-p/1097#M854</guid>
      <dc:creator>ldormond</dc:creator>
      <dc:date>2013-12-11T09:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why does User-ID suddenly stops ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-user-id-suddenly-stops/m-p/1098#M855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While I don't know exactly why this is happening, there have been a great deal of fixes to various User-ID issues between 5.0.2 and 5.0.9. Some of the changes were indeed regarding ip-to-user mappings not displaying in logs, so it might be worth upgrading to 5.0.9 to see if the issue is resolved before going with a support ticket.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, you can also turn on debugging in the user ID process and tail the log. When the mapping starts to show up blank, turn off debugging and parse through the log to see what may be happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turn on the debug:&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id on debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Turn off the debug:&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id on info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Parse through the log (uses standard linux "less" navigation):&lt;/P&gt;&lt;P&gt;&amp;gt; less mp-log useridd.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That may help explain what is going on when the mapping stops to display.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Dec 2013 17:10:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-user-id-suddenly-stops/m-p/1098#M855</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-12-11T17:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why does User-ID suddenly stops ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-does-user-id-suddenly-stops/m-p/1099#M856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for these helpful advices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will first try the debug procedure you suggested (I only have PaloAlto ACE certification, also I don't know about troubleshooting tips).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I will suggest the customer to perform an upgrade to last 5.0.9 release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laurent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 13:53:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-does-user-id-suddenly-stops/m-p/1099#M856</guid>
      <dc:creator>ldormond</dc:creator>
      <dc:date>2013-12-12T13:53:28Z</dc:date>
    </item>
  </channel>
</rss>

