Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A network security engineer has configured a new security policy rule to allow specific internal users (identified by User-ID) to access a critical internal application. However, users are reporting that access is still being denied. Upon reviewing the traffic logs, the engineer notices that the 'Source User' field for the denied sessions is showing 'unknown'. What is the most probable cause for this issue?

  1. AThe source zone for the security policy rule is misconfigured.
  2. BThe security policy rule is placed below a more general 'deny' rule.
  3. CThe application defined in the security policy rule is incorrect.
  4. DThe User-ID agent is not deployed or properly configured to collect user mappings.
Show answer & explanation

Correct answer: D. The User-ID agent is not deployed or properly configured to collect user mappings.

If the 'Source User' field in the traffic logs shows 'unknown', it indicates that the firewall is not receiving or correctly processing user-to-IP mappings. This is typically caused by a misconfigured or non-functional User-ID agent, which is responsible for collecting these mappings from sources like Active Directory.

Why the other options are wrong

  • A. A misconfigured source zone would likely result in the traffic not even hitting this specific rule, or a different denial reason, but wouldn't directly cause 'unknown' for the user.
  • B. While rule order is important, if 'Source User' is 'unknown', the rule itself is not being matched based on user identity, suggesting a prior issue with User-ID.
  • C. An incorrect application would lead to an 'application-not-allowed' or 'incomplete' log, not an 'unknown' source user.

User-ID 'Unknown' Source

When User-ID fails to identify the user associated with an IP address, traffic logs will show 'unknown' in the Source User field, preventing user-based policies from matching.

  • Requires User-ID agent or other mapping sources.
  • Mappings are IP-to-user associations.
  • Essential for user-based policy enforcement.

Memory trick: Unknown User? Check the User-ID Collector.

More Security Policy Configuration questions