Palo-Alto network user-ID agent set-up

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Palo-Alto network user-ID agent set-up

L3 Networker

I am configuring user-id agent in firewall. So created some Kerberos profile and called in user-ID agent set-up of user mapping and push the changes to firewall.

All the configurations were pushed ( server monitoring, Kerberos profile) except user-ID agent set-up filed. It is not giving the option for me even to manually configure the same set-up.

Note : These configurations are in global template and I am pushing the template stack for the firewalls ( where priority is for Global and later for device templates)

Kindly help me on the same.

8 REPLIES 8

Cyber Elite
Cyber Elite

Hello @Sujanya

 

did it failed while pushing to Firewall? If it is so, it would be helpful to share the details of the error?

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi Pavel,

 

Thanks for responding. No I didn't failed. The configurations were pushing without any issues. All these tabs ( server monitoring, Kerberos profile) are visible with required config in GUI. But "Palo-Alto network user-ID agent set-up" is showing empty in GUI.

For my surprise , When i  taken the xml output ( backup-file ) of the firewall and reviewed the  configurations, it is visible there. 

 

Cyber Elite
Cyber Elite

Thank you for reply @Sujanya

 

could you confirm PAN-OS version of Panorama and Firewall you are pushing this configuration to?

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi Pavel,

 

Both Panorama and palo-Alto version is 10.2.2-h2.

Cyber Elite
Cyber Elite

Thank you for reply @Sujanya

 

the closest issue I could find that re-assembles to what you described is a bug: PAN-189894 addressed in PAN-OS 10.2.3:

 

PavelK_0-1669370532351.png

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi PavelK,
This is the error I am getting when I tried it to configure manually. But to override it there is no template symbol is showing near the user-id-agent set-up tab.

Sujanya_0-1669980617406.png

 

Cyber Elite
Cyber Elite

Thank you for reply @Sujanya

 

to be honest, based on description of the issue, this looks like a bug. I would upgrade Panorama to 10.2.3 which is as of now recommended version.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi @PavelK ,

 

I upgraded the Palo-Alto to 10.2.3 version, and now Kerberos profile issue has been resolved. But I still I can see server monitoring status is not showing as connected.

  • 1914 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!