Agentless UserID no longer maps users

cancel
Showing results for 
Search instead for 
Did you mean: 

Agentless UserID no longer maps users

L2 Linker

Hello all,

I've had Agentless UserID working fine for over a year now.  Last week our PA-3020 running 6.0.3 stopped being able to identify users which it then started blocking all Internet browsing because it thought everyone was unauthenticated.  Nothing has changed on the firewall and to my knowledge nothing has changed on our AD servers.  The weird thing is I can still log into the firewall with my AD user account just fine.  I opened a ticket with Palo Alto and the tech confirmed that all my settings are correct.  The service account we use to access WMI is not locked out and I even reset the password just to be safe.  The AD servers (2008) show connected but when you run a "show user ip-user-mapping all" it returns no results.  I see no errors on the Palo and the Event Logs on the servers don't show anything that stands out.  Has anyone run into this before?  Palo tech support is basically stumped as am I.  The only thing I haven't done is reboot the Palo but I that is something I have to schedule downtime for.

1 ACCEPTED SOLUTION

Accepted Solutions

L4 Transporter

Hey ClintL,

How long has the box been up for? It is likely that you have encountered the 388 days uptime bug by the looks of it so you should upgrade your device. The fix is in 6.0.4. I recommend contacting your ASC for advice.

thanks,

Ben

View solution in original post

3 REPLIES 3

L4 Transporter

Hey ClintL,

How long has the box been up for? It is likely that you have encountered the 388 days uptime bug by the looks of it so you should upgrade your device. The fix is in 6.0.4. I recommend contacting your ASC for advice.

thanks,

Ben

View solution in original post

You nailed the exact uptime date when this started.  I have an upgrade scheduled for next week so hopefully it will resolve the issue.  Thank you for the answer!

You might reboot the units and the counter start again. You have another 388 days before upgrade or reboot Smiley Wink

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!