200156 - User-ID Authentication Failed
Uploading...Agent error code #200156 means the Palo Alto Networks firewall or Panorama rejected the API key Knocknoc presented when registering an IP-tag mapping. The credential was refused, so nothing about the request itself was evaluated.
This covers the User-ID path specifically. A knoc that also refreshes an External Dynamic List reports #298003 for the same problem on that path, and a knoc that uses a separate credential for username mapping can fail on one and not the other.
Common causes include:
Steps to Resolve
Generate a Fresh API Key
Generate the key on the same firewall or Panorama the knoc points at, for the administrator account Knocknoc should use. A key generated on one device is not valid on another.
In the firewall or Panorama UI, open Device > Administrators, select the account, and generate an API key for it. Copy the key without leading or trailing whitespace.
Update the Credential in Knocknoc
If the knoc uses a separate credential for username mapping, update that one too. They are stored separately and only one may have expired.
Confirm the Administrator Account
In Device > Administrators, check the account the key belongs to still exists and is enabled. An API key generated for an account that has since been removed fails this way rather than reporting the account as missing.
Check the Target Address
An API key is valid only on the device that issued it. If the knoc points at Panorama, the key must be a Panorama key; if it points at a firewall directly, it must be that firewall's. Confirm the hostname on the knoc matches where the key came from.