- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-12-2020 06:44 AM
PA-820
FW: 9.0.8
Check use-id mapping in CLI returned fine. Check user group mapping fine but security not process user-ID info.
I have nine PA-820. After upgrade from 9.0.4 to 9.0.8, three of them act up. six of them are working fine. Tech Support still have no clue.
Think about version bug. reinstall no help. Upgrade to 9.1.2h1 no help
-----------------------------
admin@HOB-820> show user ip-user-mapping ip 10.3.0.49
IP address: 10.3.0.49 (vsys1)
User: the-can\hnguyen
From: UIA
Idle Timeout: 35173s
Max. TTL: 35173s
HIP Query: Disabled
Group(s): the-can\hnguyen(359)
cn=ws_monitoronly,ou=web filtering,ou=global,dc=the-can,dc=org(2147483686)
cn=vpn,ou=web filtering,ou=global,dc=the-can,dc=org(2147483689)
admin@HOB-820> show user ip-user-mapping-mp ip 10.3.0.49
IP address: 10.3.0.49 (vsys1)
User: the-can\hnguyen
From: UIA
Timeout: 35162s
Created: 8038s ago
GP User: No
Local HIP: No
-------------------------------------
06-14-2020 08:46 PM
If it's showing up correctly in the user-id database and not in the traffic logs look at your security zone and verify that the subnet is still listed correctly in the user-acl include-list post upgrade. Kind of sounds like the upgrade could have knocked this out, which would explain the discrepancy you are seeing at the moment.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!