The following are some points that you can consider to troubleshoot issues related to user-based access rules:
- Make sure that above your user-based access rules, there are rules that allow DNS, DHCP, and AD traffic to the corresponding servers.
- If a user-based rule is not working as expected, change the Source User to any and see if the rule is working fine.
- If you are unable to view the users or user groups in the Firewall page, check the communication between the Manager and the McAfee Logon Collector.
- CLI commands related to user-based access rules:
- show userInfo stats: Displays the number of full (bulk) updates and incremental updates to the Sensor. Also, displays the number of users, user groups, and host IP addresses currently present in the Sensor.
- The Manager raises a fault message for the following conditions :
- The Manager is unable to contact McAfee Logon Collector.
- The number of IPs to users mapping has exceeded 100,000.
- The number of users has exceeded 75,000.
- The bulk update from the Manager to the Sensor is more than 25 MB in size. In this case, the fault is raised and the Manager aborts the update.
- When the user groups limit exceed the specified values, the following faults are raised:
- AD user groups size exceeded
- MLC IP-User mapping/ User count exceeds limit
- MLC Group Size fault
For more information on these faults, see the section Manager faults in Trellix Intrusion Prevention System Product Guide.