Using both agentless userid and agent server here.
Support suggested a few steps to try if using agentless.
First disable agentless configuration... Commit... debug software restart user-id... Wait 5-10 min... Enable agentless configuration and then commit.
Did seem to fix the problem for now on our PA-2050.
I have a case open on this as well. PA is aware of it and is actively coding a fix. The timeline is unknown at this point, "will definitely be in 5.0.3" but and could be "weeks away". According to the folks I spoke with it is a serious enough issue there may be some sort of hotfix issued, but he could not state that for sure.
It has been causing quite a bit of issues on or PA500: Captive portal timeouts, problems with UserID mappings etc.
Given the lack of a timeline I rolled back to 5.0.1 which fixed it immediately.
Hope that helps,
We are also seeing the same issue on an PA-5050 installation using 5.0.2.
Seems like this is a 5.0.2 issue then.
We are also seeing this on our PA-500 with 5.0.2. We have attempted to upgrade the agent although this has made no difference.
Same here... since 5.0.2 with PA-2050
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
2317 root 20 0 197m 73m 63m S 101 7.5 3047:40 useridd
22375 root 30 10 90500 49m 4148 S 13 5.1 0:00.41 pan_logdb_index
2106 root 15 -5 40572 3688 1116 S 7 0.4 85:24.78 sysd
8931 root 30 10 3996 1380 1112 S 6 0.1 1:55.05 genindex.sh
22376 root 30 10 26984 1316 924 R 3 0.1 0:00.09 sdb
167 root 20 0 0 0 0 S 1 0.0 13:09.53 kswapd0
We've had a great number of problems (other than just Mgmt CPU) with 5.0.2 on our PA-500's. It seems to me that 5.0.2 has a number of issues, but that they manifest most dramatically (based on the other posts in this thread) on the PA-500 appliances (CPU and Memory capacity would be my guess).
We're rolling back to 4.1.10 tonight on the 500's and 5.0.1 on the VM-100 appliance.
Actually 5.0.0 seemed fine as far as the CPU issue goes. Unfortunately the DHCP server was borked. It would simply stop granting leases.
5.0.2 is perfect w.r.t. the DHCP ;_)
Same issue here PA2050 Running 5.0.2
|PID USER||PR NI VIRT RES SHR S %CPU %MEM||TIME+ COMMAND|
|2331||20 0 244m 75m 64m S 124 7.8 7094:50 useridd|
|2329||20 0 624m 258m 5668 S 13 26.6 406:35.06 mgmtsrvr|
|3672||30 10 4468 992 792 R||8 0.1 0:00.18 top|
|3647||30 10 46936 1980 1672 R||7 0.2 0:00.18 pan_logdb_index|
|3686||20 0 4468 1064 800 R||7 0.1 0:00.10 top|
|3696||20 0 12440 1996 1720 S||7 0.2 0:00.05 wmic|
Yesterday we have moved back to 5.0.1 and everything is OK now.... unless the real time QoS graphical which is not OK... but that is a known bug for this version....
PA confirmed PANOS 5.0.2 has a bug for useridd process and there is no estimated time of correction... so I did that .. and I also suggest everyone to do the same.
Thanks in advance!!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!