Skip to main content

200157 - User-ID Authorization Failed

Uploading...Agent error code #200157 means the API key Knocknoc presented is valid, but the administrator it belongs to is not permitted to submit User-ID updates. The firewall authenticated the request and then refused the operation.

Registering an IP-tag mapping through the XML API needs the User-ID Agent permission for the virtual system being targeted. A key that can read configuration, or that works for an External Dynamic List refresh, does not necessarily have it.

Common causes include:

    The admin role attached to the API user does not enable the XML API User-ID Agent option The role enables User-ID for one virtual system but the knoc targets another The account uses a predefined read-only role On Panorama, the role permits the operation but not the proxying of it to a managed firewall

    Steps to Resolve

    Enable User-ID Agent on the Admin Role

      Open Device > Admin Roles (or Panorama > Admin Roles) and edit the role attached to the API user Select the XML API tab Enable User-ID Agent Commit the change

      A role-based administrator with a custom role needs this explicitly. A superuser has it already, which is why the same knoc can work with one account and not another.

      Confirm the Virtual System Scope

      If the role grants access per virtual system, confirm the vsys named on the knoc is one the role covers. In the Knocknoc admin portal, read the vsys from the knoc's PAN-OS settings, then check it against the role's Virtual Systems access in the firewall UI.

      Commit and Push the Change

      Permission changes take effect only once committed. When the role is defined on Panorama, commit to Panorama and then push to the managed devices; a commit alone leaves the firewalls unchanged.

      Confirm the Fix

      Have a user request access again. If it still fails, open Support > Agent Logs in the admin portal and read agent_error_vendor_msg on the tag registration failed line: the firewall says which permission it wanted.