- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-03-2017 04:49 AM
Hi All!
i have a issue with the user-id feature: some users are not recognized by the PA device: if i check the logs searching for the username i see the last access some days ago, but if i search for his ip he is doing traffic.
Even checking via CLI with ' show user ip-user-mapping all | match username ' i don't see anything.
PA is running PAN-OS 7.0.7 (i know it is going to be in EOL, we will plan the upgrade).
Can you please give me some hints to check?
Regards,
Daniele
11-03-2017 06:26 AM
hi Mick,
the user id timeout is set to 600 min, but i don't think it is the issue, because for a user i had'nt trace for 15 days.
Regards,
Daniele
11-03-2017 07:56 AM
does "show user ip-user-mapping all" display any mappings?
Is the server monitoring status showing "connected"
have you tried "debug user-id refresh user-id ip <IP-Address> agent <User-ID Agent>" to update the PA database
11-03-2017 08:04 AM
Hi Mick,
if i perform "show user ip-user-mapping all" works correctly, as i told in the discussion's opening, only some users aren't recognized, not all.
DCs are shown as connected.
I will try to perform that debug command.
Regards,
Daniele
11-05-2017 07:01 AM
Are all your DCs the same version?
Is it worth searching the DC security logs to ensure user has actually registered an ip address.
could you confirm the group membership of the service account used to interrogate logs.
more “clutching at straws” really but you never know...
also... have you tried to use the windows server user-id agent.
this has pretty good dynamic logging and search capabilities.
we have 4 pointing to 12 DCs and seems to work well.
11-05-2017 07:06 AM
To boot.... sorry...
have you checked user mapping on each user id profile, rather than “all”.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!