<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cloud Identity Engine (CIE) and group mapping on firewalls - Groups and/or group membership updates not working as expected in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cloud-identity-engine-cie-and-group-mapping-on-firewalls-groups/m-p/566067#M2117</link>
    <description>&lt;P&gt;I just wanted to let more folks know about this KB article concerning Cloud Identity Engine (CIE) and group mapping on firewalls. Knowing about this issue documented in the KB ahead of time would have saved a &lt;EM&gt;lot&lt;/EM&gt; of frustration for us. Its information that SHOULD be in the main documentation, but isn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"How to push Cloud Identity Engine (CIE) managed group-mapping to the Firewalls"&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkppCAA" target="_self"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkppCAA&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What Happened&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;We have Prisma Access. (This would also apply to GlobalProtect VPN and any use case that needs groups and group membership coming from CIE.) We have an Internal Gateway defined. The firewalls use a group sourced from CIE to gate who can connect to the Internal Gateway. The group existed, but the membership was not being updated. It had 58 members on the firewall. It has 149 members on CIE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What You Need To Do (KB Article Summary)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you have groups in your firewalls that come from Cloud Identity Engine (CIE), those groups MUST be added under the Security Policy somewhere for the firewall to properly pick them up and keep the memberships up to date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you don't do this, the firewall may or may not get the group and/or may not apply updates to the group membership.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Workaround / Fix:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;After reading the KB article, I ended up defining a do-nothing, impossible to satisfy, rule at the bottom of my security policy that references the CIE groups I needed. Group mapping, specifically getting group membership updates, started working properly as soon as the firewall commit was completed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this is useful information for other folks!&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cloud Identity" id="Cloud_Identity"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Nov 2023 01:11:42 GMT</pubDate>
    <dc:creator>jjhernandez</dc:creator>
    <dc:date>2023-11-17T01:11:42Z</dc:date>
    <item>
      <title>Cloud Identity Engine (CIE) and group mapping on firewalls - Groups and/or group membership updates not working as expected</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cloud-identity-engine-cie-and-group-mapping-on-firewalls-groups/m-p/566067#M2117</link>
      <description>&lt;P&gt;I just wanted to let more folks know about this KB article concerning Cloud Identity Engine (CIE) and group mapping on firewalls. Knowing about this issue documented in the KB ahead of time would have saved a &lt;EM&gt;lot&lt;/EM&gt; of frustration for us. Its information that SHOULD be in the main documentation, but isn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"How to push Cloud Identity Engine (CIE) managed group-mapping to the Firewalls"&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkppCAA" target="_self"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wkppCAA&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What Happened&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;We have Prisma Access. (This would also apply to GlobalProtect VPN and any use case that needs groups and group membership coming from CIE.) We have an Internal Gateway defined. The firewalls use a group sourced from CIE to gate who can connect to the Internal Gateway. The group existed, but the membership was not being updated. It had 58 members on the firewall. It has 149 members on CIE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What You Need To Do (KB Article Summary)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you have groups in your firewalls that come from Cloud Identity Engine (CIE), those groups MUST be added under the Security Policy somewhere for the firewall to properly pick them up and keep the memberships up to date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you don't do this, the firewall may or may not get the group and/or may not apply updates to the group membership.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Workaround / Fix:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;After reading the KB article, I ended up defining a do-nothing, impossible to satisfy, rule at the bottom of my security policy that references the CIE groups I needed. Group mapping, specifically getting group membership updates, started working properly as soon as the firewall commit was completed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this is useful information for other folks!&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cloud Identity" id="Cloud_Identity"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 01:11:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cloud-identity-engine-cie-and-group-mapping-on-firewalls-groups/m-p/566067#M2117</guid>
      <dc:creator>jjhernandez</dc:creator>
      <dc:date>2023-11-17T01:11:42Z</dc:date>
    </item>
  </channel>
</rss>

