Firewall (10.1.10-h1) Unable to connect UID agent (10.1.2)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Firewall (10.1.10-h1) Unable to connect UID agent (10.1.2)

L1 Bithead

UID agents version 7.0.8 upgraded to 10.1.2.
DC (10.2.9)and Perimeter (11.1.2-h3) firewalls connected to Newly upgraded UID agent but unfortunately all branch firewalls(10.1.10-h1) couldn’t make connection to upgraded UID agent and is showing certificate error in logs.
So we have downgraded the UID agent version to 9.0.5 and working fine with all the firewalls now.

 

Is there any compatibility issue between UID agent version 10.1.2 and PAN-OS 10.1.10-h1?

 

#PAN-OS10.1.10-h1 #UID 10.1.2

1 accepted solution

Accepted Solutions

L4 Transporter

Hello @S.Sivan ,

 

The firewalls running 10.1.10-h1 are not compatible with the new UID agent versions listed on Table 2.

If you want to remain on 10.1.10-hx, then you need to run on your firewalls minimum 10.1.10-h5.

Cheers,
Cosmin

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Read more about how and why to accept solutions.

Disclaimer: All messages are my personal ones and do not represent my company's view in any way.

View solution in original post

3 REPLIES 3

L4 Transporter

Hello @S.Sivan 

 

There is a Customer Advisory related to certificate expiration that include information also about User-ID Agent.

https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-exp... 

Continuing to use UID Agent 9.0.5 will result in a loss of functionality from November 18, 2024, due to certificate expiration.

It is necessary to upgrade both your firewalls and UID Agent to the recommended versions. Begin by upgrading the firewall; only after completing this step should you proceed with upgrading the UID Agents (refer to FAQ 7).

For UID Agent version 10.1.2, ensure that your firewalls are running one of the versions listed in Table 2.

Cheers,
Cosmin

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Read more about how and why to accept solutions.

Disclaimer: All messages are my personal ones and do not represent my company's view in any way.

L1 Bithead

@CosminM 
Thank you for your reply 
I am aware that the UID agent certificate is set to expire on November 18, 2024. However, I would like to clarify whether UID version 10.1.2 and PAN-OS version 10.1.10-h1 will remain operational prior to this expiration date. According to the compatibility matrix for PAN-OS 10.1.10, it appears that UID agent version 10.1.2 is compatible.

L4 Transporter

Hello @S.Sivan ,

 

The firewalls running 10.1.10-h1 are not compatible with the new UID agent versions listed on Table 2.

If you want to remain on 10.1.10-hx, then you need to run on your firewalls minimum 10.1.10-h5.

Cheers,
Cosmin

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Read more about how and why to accept solutions.

Disclaimer: All messages are my personal ones and do not represent my company's view in any way.
  • 1 accepted solution
  • 586 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!