user-id agent/agentless is showing no source user
26025
Created On 06/07/22 00:36 AM - Last Modified 06/15/23 20:44 PM
Symptom
The show user ip-user-mapping all command is showing ip addresses without source users.
Environment
- PANOS versions: all
- User-ID agent version: all
- Microsoft servers: all
Cause
There are many things can cause the issue. The resolution will provide the steps to narrow down the cause and the guidance for the next steps.
Resolution
- Find any affected user and ask to log off and log in back to Windows.
- Send any traffic.
- Find out the source zone then confirm that the user-identification checkbox is checked (this can be the cause of the issue if the checkbox is not checked).
- From the affected windows machine, issue a echo %logonserver% command. The output is the DC/AD information which the windows machine is connected to.
- Verify the DC/AD above is configured in User-Id agent or Server Monitoring (Agentless User-ID).
- Verify connectivity between User-Id agent/Firewall (Sever Monitoring - Agentless User-ID) and DC/AD. Make sure they are connected.
- Check User IP mappings on the DC/AD Server by following this KB article: How to Check User IP Mappings on AD Server
- The above steps should provide ideas whether the issue is on User-ID's environment, or User-ID's component. If the above steps are working then go to the next step to verify the User-ID's component.
- From the Firewall's Command Line prompt, issue the following command:
show user ip-user-mapping ip <ip of one of the impacted user>
- If you don't see a user-name being mapped to user's ip address. Collect all the outputs from all the above steps and open a Support case for TAC to investigate further.