02-13-2018 03:05 PM
Hello,
We have been experiencing User-ID server monitor connection timeouts to one of our Windows 2008 R2 Domain controllers. The VM domain controller seems fine with all other services (Non Palo).
domain: 1
receive_time: 2018/02/13 17:19:38
serial:
seqno: 7472192
actionflags: 0x0
type: SYSTEM
subtype: userid
config_ver: 0
time_generated: 2018/02/13 17:19:38
dg_hier_level_1: 0
dg_hier_level_2: 0
dg_hier_level_3: 0
dg_hier_level_4: 0
vsys_name:
device_name: VM200
vsys_id: 0
vsys:
eventid: connect-server-monitor-failure
object:
fmt: 0
id: 0
module: general
severity: high
opaque: User-ID server monitor adjutant.abcd.local(vsys1) Connection timeout"
Occasionally users are prompted the captive portal in the web browser for authentication (usually automatic if a domain client), if the domain user enters their credentials web browsing resumes.
Primary DNS server for the domain is the same server and has no DNS issues, network connectivity has found no problems.
All other DC’s have no time out issues. Regular monthly windows patches are applied to all DC’s.
Tried multiple user ID agent versions and all have the same issue.
The same domain user account is used on all Palo firewalls for user mapping.
ny idea how to fix this?
Thanks in advance.
02-15-2018 03:52 PM
Hi @Mick_Ball,
Sorry for the confusion. We have only UIA on the PA.
We have disabled the Enable Session under Server Monitor Log Frequency and since then no alerts received.
02-14-2018 01:06 AM
@Farzana, Hi.
not sure about the disconnection issue but I'm a bit confused regarding your setup.
you are mentioning user-id agents installed on DC's but your screen shot shows the settings of the user agent on the PA itself...
it seems the the PA itself is losing connection so not sure why you have tried various agents on the server...
what is in your user-id agents tab?
are you using both server and PA local agents to the same servers?
have i missed something here?
02-15-2018 03:52 PM
Hi @Mick_Ball,
Sorry for the confusion. We have only UIA on the PA.
We have disabled the Enable Session under Server Monitor Log Frequency and since then no alerts received.
04-19-2018 01:12 AM
I have seen similar situations where the tcp/389 from PA to the AD is blocked or lost from time to time.
Is traffic crossing other security devices?
This is a "server monitor failure" that should not affect anything else that server check !!
06-17-2022 01:21 AM
I am having similar issues, connect-server-monitor-failure - this since the Last Microsoft Update - June 22 on windows 2016 server. KB 5014630 or KB 5014702.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!