User-id error after commit

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

User-id error after commit

L1 Bithead

I have setup user-id mapping using the instruction here:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configur...

 

I have 2 servers with the user-id agent and 2 servers with the terminal server agent all set up and working. If I go into monitoring, i can see logs populating just fine and if I go into the cli and run 

show user ip-user-mapping all

All the users show up mapped correctly.

 

Initially, we were trying to do user mapping by implementing User Mapping Using the PAN-OS Integrated User-ID Agent. We didn't like this solution and backed it all out.  In the 2 weeks since, the only thing we did was upgrade the Pan-Os to version 9.0.8 and now when we run a commit, we intermittently receive the following error:

 

user-id-service is enabled, but no user-id-agent is configured for ntlm-auth

 

I think this may be left over from when we were trying to implement the integrated user-id agent. I have searched for a similar error but can't find anything close.

 

In the firewall, in device>user identification> user-ID agents, in the properties of the server, do I need to check the "Use for NTLM Authentication" check box since we are still using NTLM authentication to clear the error?

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@RussMcIntirethe very short answer is: yes 🙂🙂

at least one of your agents needs to be the NTLM relay

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

@RussMcIntirethe very short answer is: yes 🙂🙂

at least one of your agents needs to be the NTLM relay

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper 

 

Thank you for the reply. I checked the "Use for NTLM Authentication" check box for both servers and the error cleared. I find it odd it did not show up until after the Pan-OS upgrade to 9.0.8 from 8.1.10. We ran this config for nearly 2 weeks with no issue before then. Thoughts?

@RussMcIntire  I can only venture a guess:

maybe the check didn't exist prior to 9.0 or didn't include the clientless configuration

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 6789 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!