Received the error message: "Failed to reset All User ID manager!" when attempting to reset the User-ID manager
9361
Created On 10/21/22 17:18 PM - Last Modified 07/07/25 20:20 PM
Symptom
- Unable to reset the User-ID manager on a high-availability (HA) enabled firewall when the peer status is shown as "unknown."
Environment
- PAN-OS
- Palo Alto Network Firewall
- High-availability
- User-id-manager
Cause
- When the firewall is operating in high-availability mode, the User-ID manager must be reset on the peer device first. Attempting to reset it on the active device initially will fail and generate the following error in the useridd.log:
2022-10-21 12:43:17.384 -0500 reset the idmgr of peer first 2022-10-21 12:43:17.384 -0500 Error: pan_shmgr_reset_peer(pan_shmgr.c:4574): sysd_modify_obj($(HA-PEER)ha.lib.idmgr.user.impl.usr.base.idmgr-reset) failed: ALIAS_NOT_FOUND(active)> debug user-id reset user-id-manager type all Failed to reset All User ID manager! <<<<<<<<<< (active)>grep pattern 'reset the idmgr of peer first\|pan_shmgr_reset_peer' mp-log useridd.log 2022-10-21 12:43:17.384 -0500 reset the idmgr of peer first 2022-10-21 12:43:17.384 -0500 Error: pan_shmgr_reset_peer(pan_shmgr.c:4574): sysd_modify_obj($(HA-PEER)ha.lib.idmgr.user.impl.usr.base.idmgr-reset) failed: ALIAS_NOT_FOUND
Resolution
- If the peer device status is unknown, disable high-availability temporarily via the Web UI by navigating to Device > High Availability > General > Setup, unchecking Enable HA, committing the changes, and then resetting the User-ID manager as a workaround
OR
- Bring up the peer device and reset the user-id-manager on the Passive device first and then on the Active one