Security policy Not process user-ID mapping after upgrade 9.0.4 to 9.0.8

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Security policy Not process user-ID mapping after upgrade 9.0.4 to 9.0.8

L1 Bithead

PA-820

FW: 9.0.8

Check use-id mapping in CLI returned fine. Check user group mapping fine but security not process user-ID info.

I have nine PA-820. After upgrade from 9.0.4 to 9.0.8, three of them act up. six of them are working fine. Tech Support still have no clue.

Think about version bug. reinstall no help. Upgrade to 9.1.2h1 no help

-----------------------------

admin@HOB-820> show user ip-user-mapping ip 10.3.0.49

IP address: 10.3.0.49 (vsys1)
User: the-can\hnguyen
From: UIA
Idle Timeout: 35173s
Max. TTL: 35173s
HIP Query: Disabled
Group(s): the-can\hnguyen(359)
cn=ws_monitoronly,ou=web filtering,ou=global,dc=the-can,dc=org(2147483686)
cn=vpn,ou=web filtering,ou=global,dc=the-can,dc=org(2147483689)

 

admin@HOB-820> show user ip-user-mapping-mp ip 10.3.0.49

IP address: 10.3.0.49 (vsys1)
User: the-can\hnguyen
From: UIA
Timeout: 35162s
Created: 8038s ago
GP User: No
Local HIP: No

-------------------------------------

HNguyen_0-1591969110163.png

 

 

1 REPLY 1

Cyber Elite
Cyber Elite

@HNguyen,

If it's showing up correctly in the user-id database and not in the traffic logs look at your security zone and verify that the subnet is still listed correctly in the user-acl include-list post upgrade. Kind of sounds like the upgrade could have knocked this out, which would explain the discrepancy you are seeing at the moment. 

  • 2269 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!