Access Denied (Server Monitor)

Reply
Highlighted
L0 Member

Access Denied (Server Monitor)

I configured the Base name and bind name properly but we facing the following error in putty “pan_user_id_win_get_error_status(pan_user_id_win.c:1130): WMIC message from server AD-Monitor: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied” and  “pan_user_id_win_wmic_log_query(pan_user_id_win.c:1439): log query for AD-Monitor failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied”

 

 

Highlighted
Cyber Elite

@shafi.md,

Can you look at the server and verify the setting of 'Network security: LAN Manager authentication level' 

Highlighted
L4 Transporter

@shafi.md 

I presume that you use the build-in User-ID agent. This normally happens, when you have not added the AD account used by the firewall to account with rights to read the WMIC address space.

You need to repeat it on each monitored server:

 

  • Right-click the Windows icon ( png ), Search for wmimgmt.msc, and launch the WMI Management Console.
  • In the console tree, right-click WMI Control and select Properties.
  • Select Security, select RootCIMV2, and click Security.
  • Add the name of the service account you created, Check Names to verify your entry, and click OK.
  • You might have to change the Locations or click Advanced to query for account names. See the dialog help for details.
  • In the Permissions for <Username> section, Allow the Enable Account, and Remote Enable permissions.
  • Click OK twice.
  • Use the Local Users and Groups MMC snap-in (lusrmgr.msc) to add the service account to the local Distributed Component Object Model (DCOM) Users and Remote Desktop Users groups on the system that will be probed.

 

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id/map-ip-addresses-to-users/create-a...

 

Highlighted
L0 Member

Still Same issue (Access Denied)

 

Output

2019-05-01 08:59:20.280 +0530 Error: pan_user_id_win_wmic_sess_query(pan_user_id_win.c:1588): session query for 192.168.0.212 failed: NTSTATUS: NT_STATUS_ACCESS_DENIED - Access denied

 

I have integrate one more firewall with server 2008, that is working fine,

 

The above error i am getting from firewall after running this command (less mp-log useridd.log), integration with server 2012 r2

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!