connect-server-monitor-failure

Reply
Highlighted
L3 Networker

connect-server-monitor-failure

Has anyone experienced numerous of these "connect-server-monitor-failure" alerts when using agentless user ID?

 

I have 20+ firewalls using a few specific domain controllers to get user ID info, but these alerts are constantly, 100's an hour.

 

It seems to be related to WMI memory error, but I've already increased the wmi memory, described in this article

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CltXCAS

 

DCs are Win2k8 R2

 

Tags (1)
Highlighted
L7 Applicator

If you have so many firewalls polling only a handful AD servers, it's probably better to install agents on the AD (or one or more servers near the AD) and have the firewalls poll the agents instead, this will dramatically cut down on all the WMI probes you'll need to do

Tom Piens - PANgurus.com
Find my book at amazon.com/dp/1789956374
Highlighted
L3 Networker

I agree, but I don't find 20 firewalls to be a lot.  Is this too much for agentless user-ID?

 

Highlighted
L7 Applicator

You'd need to investigate logs on your ADs to make sure but it sounds like some of the WMI arentimjngnout which could be a sign that the AD are not keeping up with the amount of requests coming from the firewalls

If the volume is unusually high you could also look into why this is: maybe a zone that does not have mapped IPs does have user-id enabled which will trigger a query for each unidentified IP (user-id only needs to be enabled on the 'source' zone of the identified users)
Tom Piens - PANgurus.com
Find my book at amazon.com/dp/1789956374
Highlighted
L3 Networker


@reaper wrote:
You'd need to investigate logs on your ADs to make sure but it sounds like some of the WMI arentimjngnout which could be a sign that the AD are not keeping up with the amount of requests coming from the firewalls

If the volume is unusually high you could also look into why this is: maybe a zone that does not have mapped IPs does have user-id enabled which will trigger a query for each unidentified IP (user-id only needs to be enabled on the 'source' zone of the identified users)

 

I think you may be on to something here, even though I keep being told no.  There is only 1 Trust zone on most of the firewalls, but there a few subnets where a user will never map. I think it can benefit from those subnets being excluded

Highlighted
L7 Applicator

That sounds like the perfect place to start!
Tom Piens - PANgurus.com
Find my book at amazon.com/dp/1789956374
Highlighted
L0 Member

I know this is a fairly old thread but curious if your investigation turned up any findings with regard to this zone enablement issue? We're having a similar issue and looking for solutions.

Highlighted
L3 Networker

@codyweber54 I decided to use the Windows User-ID agent instead.  No more issues, since switching to that

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!