Data plane User-ID mappings empty

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Data plane User-ID mappings empty

Not applicable

We currently have a pair 5020s using LDAP for User-ID - up until about a week ago it was working.

I can see in the logs that the mappings are taking place, and the management plane mappings are there, however the data plane table is empty.

This is causing drops on policies which have User-ID as a stipulation.

Any ideas?

1 accepted solution

Accepted Solutions

L7 Applicator

What PAN-OS version are you running and what is the Active device's uptime ?

Based on your description, I suspect Bug 64166, resolved in PAN-OS 6.0.4 and 5.0.14.

View solution in original post

4 REPLIES 4

L7 Applicator

I don't see anything on this issue specifically, so here are some general thoughts.

Sounds like a bug.  So I would make a quick search of the latest release notes for your PanOS chain and see if this is listed as a solved issue in a release higher than what you are running.  If so, then upgrade.  If not, open a ticket to get this registered as a bug and into the release chain.

For a quick fix on issues like this a restart of the management plane will sometimes restore service.

debug software restart management-server

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

L7 Applicator

What PAN-OS version are you running and what is the Active device's uptime ?

Based on your description, I suspect Bug 64166, resolved in PAN-OS 6.0.4 and 5.0.14.

Thanks for doing the bug search and providing the ID.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Thanks guys, that bug looks exactly like the issue - we're running 6.0.2 with 400 days of update as of this morning.

We'll get'er upgraded and I'll shoot back if it doesn't resolve it but I have a feeling it will.

  • 1 accepted solution
  • 2866 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!