Identifying user rules UserID

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Identifying user rules UserID

L4 Transporter

Hi,

 

We are expecting several issues with user identificatiom. We see connections identifying users but suddently the connections stop identifying. 

 

I attach an screenshot

 

UserID captura.jpg

5 REPLIES 5

Community Team Member

Hi @soporteseguridad,

 

It looks like users are losing their IP mapping.

Check this document : https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-User-ID-Group-and-User-to-I...

 

The section "IP mappings are created but disappear too soon" might help you on your way.

 

Cheers !

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

We are using SYSLOG in Palo to take the users. 

 

If we go into "show user ip-user-mapping all | match 10.162.246" we see that user: mcabr is identified correctly but going into traffic logs we see connections where mapping is lost.

 

(active)> show user ip-user-mapping all | match 10.162.246

 

10.162.246.22   vsys1  SYSLOG  mcab.in                 2353           2353              

10.162.246.20   vsys1  SYSLOG  mcab.in                 2406           2406            

10.162.246.23   vsys1  SYSLOG  mcab.in                1545           1545        

 

 

(active)> show user ip-user-mapping all | match 10.162.246.

 

10.162.246.23   vsys1  SYSLOG  mcab.in               1518           1518        

 

 

(active)> show clock

Wed Dec 28 09:24:07 CET 2016

 

mngo.png

 

 

Has this method of user-id ever worked correctly?

im not sure. Palo alto uses syslog server for mappings......

Hello,

This is usually caused by the 'User Identification Timeout'. Happened to me a few times as well. If you are using agents, go into the setup and change the timeout value:

 

agent.JPG

 

If you are using agentless, log into the PAN and change the value there:

 

agentless.JPG

 

Hope this helps.

 

  • 2448 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!