Security policy Not process user-ID mapping after upgrade 9.0.4 to 9.0.8

Showing results for 
Search instead for 
Did you mean: 

Security policy Not process user-ID mapping after upgrade 9.0.4 to 9.0.8

L1 Bithead


FW: 9.0.8

Check use-id mapping in CLI returned fine. Check user group mapping fine but security not process user-ID info.

I have nine PA-820. After upgrade from 9.0.4 to 9.0.8, three of them act up. six of them are working fine. Tech Support still have no clue.

Think about version bug. reinstall no help. Upgrade to 9.1.2h1 no help


admin@HOB-820> show user ip-user-mapping ip

IP address: (vsys1)
User: the-can\hnguyen
From: UIA
Idle Timeout: 35173s
Max. TTL: 35173s
HIP Query: Disabled
Group(s): the-can\hnguyen(359)
cn=ws_monitoronly,ou=web filtering,ou=global,dc=the-can,dc=org(2147483686)
cn=vpn,ou=web filtering,ou=global,dc=the-can,dc=org(2147483689)


admin@HOB-820> show user ip-user-mapping-mp ip

IP address: (vsys1)
User: the-can\hnguyen
From: UIA
Timeout: 35162s
Created: 8038s ago
GP User: No
Local HIP: No






Cyber Elite
Cyber Elite


If it's showing up correctly in the user-id database and not in the traffic logs look at your security zone and verify that the subnet is still listed correctly in the user-acl include-list post upgrade. Kind of sounds like the upgrade could have knocked this out, which would explain the discrepancy you are seeing at the moment. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!