<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserID Redistribution Filters working weirdly in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-redistribution-filters-working-weirdly/m-p/1235427#M6162</link>
    <description>&lt;P&gt;Update:&lt;BR /&gt;I confirmed it now: The include/exlude Filters apply to both the "import" and "export" (terms borrowed from routing) of mappings to other firewalls.&lt;/P&gt;
&lt;P&gt;So, it seems the filter do not allow me to build a design with redundancy / bi-directional flow of mappings without having a lot of duplicates flowing/looping around.&lt;BR /&gt;There is a limit of 10 hops for user-ip-mappings. But still this seems unfortunate.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Aug 2025 07:40:21 GMT</pubDate>
    <dc:creator>AndreasTrautmann</dc:creator>
    <dc:date>2025-08-05T07:40:21Z</dc:date>
    <item>
      <title>UserID Redistribution Filters working weirdly</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-redistribution-filters-working-weirdly/m-p/1235363#M6158</link>
      <description>&lt;P&gt;Hi there&lt;BR /&gt;&lt;BR /&gt;I have a customer setup with a central "Hub"/HQ-Firewall (Pair) and a lot of smaller "Spoke"/Site firewalls connected via S2S Tunnels. Each Site and the HQ have local AD DCs and UserID-Agent Server to collect User/IP-Mappings locally. Also in some Sites and HQ ther is Global-Protect running (adds more mappings).&lt;/P&gt;
&lt;P&gt;The customer needs all the user-ip-mappings in all the sites. So we have redistribution configured in both ways from each spoke to the hub. Obviously this leads to a load of redundant mappings floating and looping around.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, I wanted to improve this by using Redistribution Filters (Include/Exclude Networks). I must say, the documentation about this feature is scarce... But I thought i understood what it did... but I was wrong: Since each Site has a /16 Network-Prefix, I just added this prefix as an include statement. My hope was, that this would lead the site to only send mappings of its own prefix back to the hub (and therefore stop the loops of the mappings).&lt;/P&gt;
&lt;P&gt;What actually happened was that the site only learned mappings of the prefix in the inlclude statement... And I think (need to confirm) it also only redistributed those to the hub. So, If I got this right, the feature is nealy useless (for my case).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have experience with this feature / behaviour of the feature?&lt;BR /&gt;How do you understand it works - from your experience?&lt;BR /&gt;&lt;BR /&gt;Any idea how I could solve this problem (bearing in mind that mappings need to flow both ways)?&lt;BR /&gt;I have also a working instance of CIE in place. But this is thought as a backup-path. The customer does not want to rely on it a the primary path.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;BR /&gt;Andreas&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 16:15:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-redistribution-filters-working-weirdly/m-p/1235363#M6158</guid>
      <dc:creator>AndreasTrautmann</dc:creator>
      <dc:date>2025-08-04T16:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: UserID Redistribution Filters working weirdly</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-redistribution-filters-working-weirdly/m-p/1235427#M6162</link>
      <description>&lt;P&gt;Update:&lt;BR /&gt;I confirmed it now: The include/exlude Filters apply to both the "import" and "export" (terms borrowed from routing) of mappings to other firewalls.&lt;/P&gt;
&lt;P&gt;So, it seems the filter do not allow me to build a design with redundancy / bi-directional flow of mappings without having a lot of duplicates flowing/looping around.&lt;BR /&gt;There is a limit of 10 hops for user-ip-mappings. But still this seems unfortunate.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 07:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-redistribution-filters-working-weirdly/m-p/1235427#M6162</guid>
      <dc:creator>AndreasTrautmann</dc:creator>
      <dc:date>2025-08-05T07:40:21Z</dc:date>
    </item>
  </channel>
</rss>

