No User-ID mapping from an included network
386
Created On 02/21/22 04:01 AM - Last Modified 10/27/25 16:47 PM
Symptom
- The User-ID mapping is missing for some included networks.
- For instance, in the situation below, 2 networks are included in User-ID mapping.
- The User-ID mapping is present for the lan-1 (UserA - 192.168.1.10) but not for the new lan (UserB - 192.168.2.10).
Environment
- PAN-OS
- User-ID Agentless with Include/Exclude list.
Cause
The Network object is not in the Custom Include/Exclude Sequence.
Resolution
To add the missing Network object in the custom Include/Exclude sequence :
- Go to Device>User Identification.
- Click Custom Include/Exclude Network Sequence.
- Click Add.
- Select the Network Object to add.
- Click OK.
- Commit the configuration.
Additional Information
PAN-OS Documentation - Include or Exclude Subnetworks for User Mapping