user-id agent/agentless is showing no source user

user-id agent/agentless is showing no source user

26025
Created On 06/07/22 00:36 AM - Last Modified 06/15/23 20:44 PM


Symptom


The show user ip-user-mapping all command is showing ip addresses without source users.

Environment


  • PANOS versions: all
  • User-ID agent version: all
  • Microsoft servers: all


Cause


There are many things can cause the issue.  The resolution will provide the steps to narrow down the cause and the guidance for the next steps.


Resolution


  1. Find any affected user and ask to log off and log in back to Windows.
  2. Send any traffic.
  3. Find out the source zone then confirm that the user-identification checkbox is checked (this can be the cause of the issue if the checkbox is not checked).
  4. From the affected windows machine, issue a echo %logonserver% command.  The output is the DC/AD information which the windows machine is connected to.
  5. Verify the DC/AD above is configured in User-Id agent or Server Monitoring (Agentless User-ID).
  6. Verify connectivity between User-Id agent/Firewall (Sever Monitoring - Agentless User-ID) and DC/AD.  Make sure they are connected.
  7. Check User IP mappings on the DC/AD Server by following this KB article: How to Check User IP Mappings on AD Server
  8. The above steps should provide ideas whether the issue is on User-ID's environment, or User-ID's component.  If the above steps are working then go to the next step to verify the User-ID's component.
  9. From the Firewall's Command Line prompt, issue the following command: 
show user ip-user-mapping ip <ip of one of the impacted user>
  1. If you don't see a user-name being mapped to user's ip address. Collect all the outputs from all the above steps and open a Support case for TAC to investigate further.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000CpuKCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language