- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-19-2023 05:45 AM - edited 09-19-2023 10:08 PM
Hi,
In our Panorama system log I see a lot of logs giving the output shown below:
Event: connect-agent-failure )
Description: 'Redistribution Agent "data redistribution agent id"(vsys1): details: close connection to agent'
I see this messages are coming in from all our firewalls and it started around 18 months ago.
I tried to look through some documents on what the Data Redistribution Agent does and why this entry shows up in the system log but I can`t seem to get it.
Anyone who can answer that or got some ideas why?
09-20-2023 07:46 PM
Hello @Richard_M
Data Distribution Agents can be Firewall/Panorama or a Windows UID agent. They essentially gather user-IP mapping information from resources like AD. The Firewalls in your network act as clients to retrieve this information from the agents.
For example, in step 7 of the document, it explains how to set up a data distribution agent in a Firewall.
Configure the Windows User-ID Agent for User Mapping
The system logs you discovered typically indicate connectivity problems. To gain a better understanding, perform a packet capture or tcpdump (for the management interface) between the Firewall and the distribution agent. This will provide you with a comprehensive overview.
09-21-2023 05:51 AM - edited 09-21-2023 06:15 AM
Hi @akuzhuppilly
Thanks for your reply.
According to the last step (I) in the 7th step in the guide it says
At the firewall here it says "No" under Connected. How do I exactly make become connected?
For all the other fw`s it says "Yes" under connected.
Regarding that the log indicates connectivity problems. Do you fix that at the firewall or somewhere else?
I see in the same document, step 8 it says something about the user id-agent. Where do you "launch the User-ID agent"
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!