I've had Agentless UserID working fine for over a year now. Last week our PA-3020 running 6.0.3 stopped being able to identify users which it then started blocking all Internet browsing because it thought everyone was unauthenticated. Nothing has changed on the firewall and to my knowledge nothing has changed on our AD servers. The weird thing is I can still log into the firewall with my AD user account just fine. I opened a ticket with Palo Alto and the tech confirmed that all my settings are correct. The service account we use to access WMI is not locked out and I even reset the password just to be safe. The AD servers (2008) show connected but when you run a "show user ip-user-mapping all" it returns no results. I see no errors on the Palo and the Event Logs on the servers don't show anything that stands out. Has anyone run into this before? Palo tech support is basically stumped as am I. The only thing I haven't done is reboot the Palo but I that is something I have to schedule downtime for.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!