- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-11-2026 12:56 PM
Hello,
I am having an issue setting up user-id when the firewall is in FIPS-CC mode. Here is the following issue:
Environment:
Issue:
I have two Windows-based User-ID Agents configured under Device > Data Redistribution > Agents, pointing to two domain controllers (DC-A and DC-B) with identical config (same port 5007, same vsys, both enabled). DC-B connects fine. DC-A has never connected, and it looks like the firewall isn't even attempting a connection to it.
Key diagnostic finding:
> show user user-id-agent statistics
Name Host Port Vsys State Ver
DC-B ... 5007 vsys1 conn:idle 5
> show redistribution agent statistics
Name Host Port Vsys State Ver
DC-A ... 5007 vsys1 not-conn:idle 6
DC-B is registering under the legacy User-ID Agent (protocol v5) handler and connects successfully. DC-A is registering under the newer Redistribution Agent (protocol v6) handler, and show redistribution agent state DC-A shows num of connection tried: 0 — zero attempts, ever.
Already ruled out:
Has anyone run into this issue and any suggestions.
09-14-2026 05:59 PM
Hi @G.Williamson789500 ,
There might be a mismatch or incompatibility in the secure communication settings between the firewall in FIPS-CC mode and DC-A which could be why youre not seeing any connection attempts. I would run a packet capture, Even if number of attempts is reported at 0, it's possible that very early SSL negotiation attempts are failing before a full connection attempt is logged. Also, If you enter "less mp-log distributord.log" , do you see any related ssl/tls errors?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

