Server Monitoring of User-ID agent set-up shows Authentication failed /Connection refused error

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Server Monitoring of User-ID agent set-up shows Authentication failed /Connection refused error

L3 Networker

We have over 80+ firewalls in our environment, all of them of version 10.1.6.-h6 , we are using Kerberos profile in the user-id agent set-up and every server monitor status seems connected. Except for the firewall which is with PAN-OS version 10.2.3.-h4, even after using the same parameters.

getting below error:

Server monitor HOSTNAMEDP(vsys1): connection failed, HTTP code 401, (null)

 

Kindly suggest us on above condition.

1 REPLY 1

Community Team Member

Hi @Sujanya ,

 

That error is too general and requires additional debugging.

 

I'd make sure the clock is synced under the same NTP server everywhere.

Also enable debug logging:

debug user-id on debug
debug user-id set userid servermonitor

Also capture krb5 and http traffic at the time of the issue

1) kerberos traffic is between fw and kdc server on port 88.
2) http traffic is between fw and server monitor server on port 5985.

 

You might want to grab all this info + a tech support file and send it over to TAC for analysis.

 

Kind regards,

-Kiwi.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 2423 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!