- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-23-2016 02:06 AM
Hi,
We are expecting several issues with user identificatiom. We see connections identifying users but suddently the connections stop identifying.
I attach an screenshot
12-23-2016 02:37 AM
It looks like users are losing their IP mapping.
Check this document : https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-User-ID-Group-and-User-to-I...
The section "IP mappings are created but disappear too soon" might help you on your way.
Cheers !
-Kim.
12-28-2016 01:14 AM
We are using SYSLOG in Palo to take the users.
If we go into "show user ip-user-mapping all | match 10.162.246" we see that user: mcabr is identified correctly but going into traffic logs we see connections where mapping is lost.
(active)> show user ip-user-mapping all | match 10.162.246
10.162.246.22 vsys1 SYSLOG mcab.in 2353 2353
10.162.246.20 vsys1 SYSLOG mcab.in 2406 2406
10.162.246.23 vsys1 SYSLOG mcab.in 1545 1545
(active)> show user ip-user-mapping all | match 10.162.246.
10.162.246.23 vsys1 SYSLOG mcab.in 1518 1518
(active)> show clock
Wed Dec 28 09:24:07 CET 2016
12-28-2016 02:19 PM
Has this method of user-id ever worked correctly?
12-29-2016 01:38 AM
im not sure. Palo alto uses syslog server for mappings......
12-29-2016 07:56 AM
Hello,
This is usually caused by the 'User Identification Timeout'. Happened to me a few times as well. If you are using agents, go into the setup and change the timeout value:
If you are using agentless, log into the PAN and change the value there:
Hope this helps.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!