Firewall does not recognize users randomly
3716
Created On 03/21/22 13:12 PM - Last Modified 12/13/24 21:56 PM
Symptom
- User does not appear in the ip-user-mapping at the time of issue.
PA_Firewall> show user ip-user-mapping ip x.x.x.x IP address: x.x.x.x (vsys1) User: unknown From: Unknown Idle Timeout: 1s Max. TTL: 4s HIP Query: Disabled - Logs under "useridd.log" (less mp-log useridd.log) on Firewall shows that the domain for that user does not exist in group-mapping
Warning: pan_user_group_user_prime_uid_lookup(pan_user_group_multi_attr.c:1292): For domain\username user, domain <domain_name> does not exist in group-mapping Warning: pan_user_group_user_prime_uid_lookup(pan_user_group_multi_attr.c:1292): For domain\username user, domain <domain_name> does not exist in group-mapping
Environment
- Palo Alto Firewalls
- Supported PAN-OS
- User based Security Rules configured
- Same Domain Controllers configured as User-ID Agent and Agentless:
Cause
The mappings of User-ID Agent can be overwritten by the Agentless configuration and visa versa.
Resolution
Ensure the Domain controllers are used in the User-ID Agent or in the Agentless configuration, but not both.
Additional Information
Two different types of User ID-Agent: