Received the error message: "Failed to reset All User ID manager!" when attempting to reset the User-ID manager

Received the error message: "Failed to reset All User ID manager!" when attempting to reset the User-ID manager

9361
Created On 10/21/22 17:18 PM - Last Modified 07/07/25 20:20 PM


Symptom


  • Unable to reset the User-ID manager on a high-availability (HA) enabled firewall when the peer status is shown as "unknown."


Environment


  • PAN-OS
  • Palo Alto Network Firewall
  • High-availability
  • User-id-manager


Cause


  • When the firewall is operating in high-availability mode, the User-ID manager must be reset on the peer device first. Attempting to reset it on the active device initially will fail and generate the following error in the useridd.log:
    2022-10-21 12:43:17.384 -0500 reset the idmgr of peer first
    2022-10-21 12:43:17.384 -0500 Error:  pan_shmgr_reset_peer(pan_shmgr.c:4574): sysd_modify_obj($(HA-PEER)ha.lib.idmgr.user.impl.usr.base.idmgr-reset) failed: ALIAS_NOT_FOUND(active)> debug user-id reset user-id-manager type all 
    
    Failed to reset All User ID manager!  <<<<<<<<<<
    
    (active)>grep pattern 'reset the idmgr of peer first\|pan_shmgr_reset_peer' mp-log useridd.log 
    2022-10-21 12:43:17.384 -0500 reset the idmgr of peer first
    2022-10-21 12:43:17.384 -0500 Error:  pan_shmgr_reset_peer(pan_shmgr.c:4574): sysd_modify_obj($(HA-PEER)ha.lib.idmgr.user.impl.usr.base.idmgr-reset) failed: ALIAS_NOT_FOUND


Resolution


  • If the peer device status is unknown, disable high-availability temporarily via the Web UI by navigating to Device > High Availability > General > Setup, unchecking Enable HA, committing the changes, and then resetting the User-ID manager as a workaround

          OR

  • Bring up the peer device and reset the user-id-manager on the Passive device first and then on the Active one


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kEfkCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language