User-id not working correctly

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

User-id not working correctly

L3 Networker

Hi All!

 

i have a issue with the user-id feature: some users are not recognized by the PA device: if i check the logs searching for the username i see the last access some days ago, but if i search for his ip he is doing traffic.

Even checking via CLI with ' show user ip-user-mapping all | match username ' i don't see anything.

 

PA is running PAN-OS 7.0.7 (i know it is going to be in EOL, we will plan the upgrade).

 

Can you please give me some hints to check?

 

Regards,

Daniele

6 REPLIES 6

L7 Applicator

what is tour user identification timeout set to?

hi Mick,

 

the user id timeout is set to 600 min, but i don't think it is the issue, because for a user i had'nt trace for 15 days.

 

Regards,

Daniele

L7 Applicator

does "show user ip-user-mapping all" display any mappings?

 

Is the server monitoring status showing "connected"

 

 

 

have you tried "debug user-id refresh user-id ip <IP-Address> agent <User-ID Agent>" to update the PA database

Hi Mick,

 

if i perform "show user ip-user-mapping all" works correctly, as i told in the discussion's opening, only some users aren't recognized, not all.

DCs are shown as connected.

I will try to perform that debug command.

 

Regards,

Daniele

Are all your DCs the same version? 

Is it worth searching the DC security logs to ensure user has actually registered an ip address.

 

could you confirm the group membership of the service account used to interrogate logs.

 

more “clutching at straws” really but you never know...

 

also... have you tried to use the windows server user-id agent.

 

this has pretty good dynamic logging and search capabilities.

 

we have 4 pointing to 12 DCs and seems to work well.

 

 

To boot.... sorry...

 

have you checked user mapping on each user id profile, rather than “all”.

  • 3121 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!