- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-24-2022 10:02 PM
I am configuring user-id agent in firewall. So created some Kerberos profile and called in user-ID agent set-up of user mapping and push the changes to firewall.
All the configurations were pushed ( server monitoring, Kerberos profile) except user-ID agent set-up filed. It is not giving the option for me even to manually configure the same set-up.
Note : These configurations are in global template and I am pushing the template stack for the firewalls ( where priority is for Global and later for device templates)
Kindly help me on the same.
11-25-2022 12:12 AM
Hello @Sujanya
did it failed while pushing to Firewall? If it is so, it would be helpful to share the details of the error?
Kind Regards
Pavel
11-25-2022 12:18 AM
Hi Pavel,
Thanks for responding. No I didn't failed. The configurations were pushing without any issues. All these tabs ( server monitoring, Kerberos profile) are visible with required config in GUI. But "Palo-Alto network user-ID agent set-up" is showing empty in GUI.
For my surprise , When i taken the xml output ( backup-file ) of the firewall and reviewed the configurations, it is visible there.
11-25-2022 12:32 AM
Thank you for reply @Sujanya
could you confirm PAN-OS version of Panorama and Firewall you are pushing this configuration to?
Kind Regards
Pavel
11-25-2022 12:33 AM
Hi Pavel,
Both Panorama and palo-Alto version is 10.2.2-h2.
11-25-2022 02:03 AM
Thank you for reply @Sujanya
the closest issue I could find that re-assembles to what you described is a bug: PAN-189894 addressed in PAN-OS 10.2.3:
Kind Regards
Pavel
12-02-2022 03:32 AM
Hi PavelK,
This is the error I am getting when I tried it to configure manually. But to override it there is no template symbol is showing near the user-id-agent set-up tab.
12-05-2022 09:02 PM
Thank you for reply @Sujanya
to be honest, based on description of the issue, this looks like a bug. I would upgrade Panorama to 10.2.3 which is as of now recommended version.
Kind Regards
Pavel
03-24-2023 02:49 AM
Hi @PavelK ,
I upgraded the Palo-Alto to 10.2.3 version, and now Kerberos profile issue has been resolved. But I still I can see server monitoring status is not showing as connected.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!