Security policy Not process user-ID mapping after upgrade 9.0.4 to 9.0.8

Reply
Highlighted
L1 Bithead

Security policy Not process user-ID mapping after upgrade 9.0.4 to 9.0.8

PA-820

FW: 9.0.8

Check use-id mapping in CLI returned fine. Check user group mapping fine but security not process user-ID info.

I have nine PA-820. After upgrade from 9.0.4 to 9.0.8, three of them act up. six of them are working fine. Tech Support still have no clue.

Think about version bug. reinstall no help. Upgrade to 9.1.2h1 no help

-----------------------------

admin@HOB-820> show user ip-user-mapping ip 10.3.0.49

IP address: 10.3.0.49 (vsys1)
User: the-can\hnguyen
From: UIA
Idle Timeout: 35173s
Max. TTL: 35173s
HIP Query: Disabled
Group(s): the-can\hnguyen(359)
cn=ws_monitoronly,ou=web filtering,ou=global,dc=the-can,dc=org(2147483686)
cn=vpn,ou=web filtering,ou=global,dc=the-can,dc=org(2147483689)

 

admin@HOB-820> show user ip-user-mapping-mp ip 10.3.0.49

IP address: 10.3.0.49 (vsys1)
User: the-can\hnguyen
From: UIA
Timeout: 35162s
Created: 8038s ago
GP User: No
Local HIP: No

-------------------------------------

HNguyen_0-1591969110163.png

 

 

Highlighted
Cyber Elite

Re: Security policy Not process user-ID mapping after upgrade 9.0.4 to 9.0.

@HNguyen,

If it's showing up correctly in the user-id database and not in the traffic logs look at your security zone and verify that the subnet is still listed correctly in the user-acl include-list post upgrade. Kind of sounds like the upgrade could have knocked this out, which would explain the discrepancy you are seeing at the moment. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!