UserID weird behaviour

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

UserID weird behaviour

L4 Transporter

Hi,

Our UserID is doing a weird behaviour. UserID is sending "probing" and weird connections to a lot of machines. We havent configured anything for these computers where userid is sending connections, why is the UseriID doing this???

I attached a screenshot with the diferent tries to random IP´s in my network.

We have disabled WMI probing and Netbios probing and these connections disappear.......why?? what this kind of connection do?

Thanks...Multiple tries.jpg 

1 accepted solution

Accepted Solutions

L3 Networker

It is an expected behavior when WMI and netbios  probing is enabled . If a ip-user mapping doesn't exist in firewall or user-idagent and traffic is seen on firewall from that specific ip , user-id agent will try to get the resolve IP > user mapping through WMI/netbios probing Disabling wmi probing is recommended if the account used in user-id agent doesn't have permissions on the client machines to probe through WMI . Same is the case with netbios probe as well if the clients are not allowing remote netbios probe Following link has the document on User-id configuration tips https://live.paloaltonetworks.com/docs/DOC-1052

View solution in original post

1 REPLY 1

L3 Networker

It is an expected behavior when WMI and netbios  probing is enabled . If a ip-user mapping doesn't exist in firewall or user-idagent and traffic is seen on firewall from that specific ip , user-id agent will try to get the resolve IP > user mapping through WMI/netbios probing Disabling wmi probing is recommended if the account used in user-id agent doesn't have permissions on the client machines to probe through WMI . Same is the case with netbios probe as well if the clients are not allowing remote netbios probe Following link has the document on User-id configuration tips https://live.paloaltonetworks.com/docs/DOC-1052

  • 1 accepted solution
  • 1741 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!