User-id error after commit

Reply
Highlighted
L1 Bithead

User-id error after commit

I have setup user-id mapping using the instruction here:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configur...

 

I have 2 servers with the user-id agent and 2 servers with the terminal server agent all set up and working. If I go into monitoring, i can see logs populating just fine and if I go into the cli and run 

show user ip-user-mapping all

All the users show up mapped correctly.

 

Initially, we were trying to do user mapping by implementing User Mapping Using the PAN-OS Integrated User-ID Agent. We didn't like this solution and backed it all out.  In the 2 weeks since, the only thing we did was upgrade the Pan-Os to version 9.0.8 and now when we run a commit, we intermittently receive the following error:

 

user-id-service is enabled, but no user-id-agent is configured for ntlm-auth

 

I think this may be left over from when we were trying to implement the integrated user-id agent. I have searched for a similar error but can't find anything close.

 

In the firewall, in device>user identification> user-ID agents, in the properties of the server, do I need to check the "Use for NTLM Authentication" check box since we are still using NTLM authentication to clear the error?

 


Accepted Solutions
Highlighted
L7 Applicator

Re: User-id error after commit

@RussMcIntirethe very short answer is: yes

at least one of your agents needs to be the NTLM relay

 

reaper - PANgurus.com
I drink and I know things

View solution in original post


All Replies
Highlighted
L7 Applicator

Re: User-id error after commit

@RussMcIntirethe very short answer is: yes

at least one of your agents needs to be the NTLM relay

 

reaper - PANgurus.com
I drink and I know things

View solution in original post

Highlighted
L1 Bithead

Re: User-id error after commit

@reaper 

 

Thank you for the reply. I checked the "Use for NTLM Authentication" check box for both servers and the error cleared. I find it odd it did not show up until after the Pan-OS upgrade to 9.0.8 from 8.1.10. We ran this config for nearly 2 weeks with no issue before then. Thoughts?

Highlighted
L7 Applicator

Re: User-id error after commit

@RussMcIntire  I can only venture a guess:

maybe the check didn't exist prior to 9.0 or didn't include the clientless configuration

reaper - PANgurus.com
I drink and I know things
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!