防火墙无法随机识别用户
3708
Created On 03/21/22 13:12 PM - Last Modified 12/27/24 08:16 AM
Symptom
- User does not appear in the ip-user-mapping at the time of issue.
PA_Firewall> show user ip-user-mapping ip x.x.x.x IP address: x.x.x.x (vsys1) User: unknown From: Unknown Idle Timeout: 1s Max. TTL: 4s HIP Query: Disabled - Logs under "useridd.log" (less mp-log useridd.log) on Firewall shows that the domain for that user does not exist in group-mapping
Warning: pan_user_group_user_prime_uid_lookup(pan_user_group_multi_attr.c:1292): For domain\username user, domain <domain_name> does not exist in group-mapping Warning: pan_user_group_user_prime_uid_lookup(pan_user_group_multi_attr.c:1292): For domain\username user, domain <domain_name> does not exist in group-mapping
Environment
- Palo Alto 防火墙
- 支持的 PAN OS
- 配置基于用户的安全规则
- 配置为 User-ID 代理和无代理的相同域控制器:
Cause
用户 ID 代理的映射可以被无代理配置覆盖,反之亦然。
Resolution
确保域控制器在用户 ID 代理或无代理配置中使用,但不能同时使用两者。
Additional Information
两种不同类型的用户ID-代理: