Usernames Missing in Traffic Logs After Enabling Panorama User-ID Redistribution
Symptom
-
User-ID redistribution enabled from Panorama
-
User-to-IP mapping populates on local firewalls (verified via CLI command >
show user ip-user-mapping all) -
Source User column in traffic logs displays only IP addresses instead of usernames
Environment
- on-prem firewalls
- Panorama
- User-ID Redistribution
Cause
User-ID processing is disabled on the source security zone where user traffic originates. The firewall only maps IP addresses to usernames for traffic originating from zones with User-ID explicitly enabled.
Resolution
Local Firewall Management:
-
Log into the firewall WebUI.
-
Navigate to Network > Zones.
-
Select the source zone where user traffic originates.
-
Select the Enable User-ID checkbox.
-
Click OK to close the dialog box.
-
Click Commit.
Panorama Management:
-
Log into the Panorama WebUI.
-
Navigate to Network > Zones (or Templates > Network > Zones).
-
Select the template or template stack associated with the local firewall.
-
Select the source zone where user traffic originates.
-
Select the Enable User-ID checkbox.
-
Click OK to close the dialog box.
-
Click Commit and push changes to the target firewall.