Hi there, We discovered an issue with our User-ID setup in our BranchOffices. Some times the source user is not recognized as <child-domain>\<user> but as <parent-domain>\<user>. This happens from time to time but only for a short perioid of time (less than 30 seconds). Does anyone have an idea on how we could further troubleshoot this issue? Here's our setup: BranchOffice: - PA-200 (v5.0.7) - Local Domain Controller (Win2012) --> <child-domain> - Local PA-200 queries the security log of the local DC every 2 seconds, no WMI probing - In addition two User-ID agents are configured. The two agents are hosted on servers in the HQ (see below). Headquarters: - PA-2050 - Four local Domain Controllers (Win2012) --> <parent-domain> - One Backup Domain Controller (Win2012) --> <child-domain> - Two servers with User-ID Agents installed (not installed on DCs directly). The User-ID agents query only local DCs, meaning the four DCs of the parent domain plus the backup DC of the child-domain. So the local PA-200 has two sources to get user-ip mapping information from: - The local DC - The two User-ID agents in the HQ That user only exists in the child domain but it uses various services hosted in the parent domain (like MS Exchange). Any help is appreciated. Thanks, Oliver
... View more