User-id not working correctly

Reply
L3 Networker

User-id not working correctly

Hi All!

 

i have a issue with the user-id feature: some users are not recognized by the PA device: if i check the logs searching for the username i see the last access some days ago, but if i search for his ip he is doing traffic.

Even checking via CLI with ' show user ip-user-mapping all | match username ' i don't see anything.

 

PA is running PAN-OS 7.0.7 (i know it is going to be in EOL, we will plan the upgrade).

 

Can you please give me some hints to check?

 

Regards,

Daniele

L6 Presenter

Re: User-id not working correctly

what is tour user identification timeout set to?

L3 Networker

Re: User-id not working correctly

hi Mick,

 

the user id timeout is set to 600 min, but i don't think it is the issue, because for a user i had'nt trace for 15 days.

 

Regards,

Daniele

L6 Presenter

Re: User-id not working correctly

does "show user ip-user-mapping all" display any mappings?

 

Is the server monitoring status showing "connected"

 

 

 

have you tried "debug user-id refresh user-id ip <IP-Address> agent <User-ID Agent>" to update the PA database

L3 Networker

Re: User-id not working correctly

Hi Mick,

 

if i perform "show user ip-user-mapping all" works correctly, as i told in the discussion's opening, only some users aren't recognized, not all.

DCs are shown as connected.

I will try to perform that debug command.

 

Regards,

Daniele

Tags (1)
L6 Presenter

Re: User-id not working correctly

Are all your DCs the same version? 

Is it worth searching the DC security logs to ensure user has actually registered an ip address.

 

could you confirm the group membership of the service account used to interrogate logs.

 

more “clutching at straws” really but you never know...

 

also... have you tried to use the windows server user-id agent.

 

this has pretty good dynamic logging and search capabilities.

 

we have 4 pointing to 12 DCs and seems to work well.

 

 

L6 Presenter

Re: User-id not working correctly

To boot.... sorry...

 

have you checked user mapping on each user id profile, rather than “all”.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!