<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HIP distribution into Remote Networks in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/hip-distribution-into-remote-networks/m-p/1258774#M1312</link>
    <description>&lt;P&gt;As have not given enough information to be honest your case sounds as when users connect to a on-prem Gateway FW that and the connection then does not go through Prisma Access but directly to the DC or remote networks and this seems not possible but maybe with CIA as a central point for User Identification as I mentioned this could work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-user-based-policy/identity-redistribution#idfb8c3233-fc37-46c3-8473-4bfd9da1ba17" target="_blank" rel="noopener"&gt;Identity Redistribution&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2026 06:07:24 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2026-07-13T06:07:24Z</dc:date>
    <item>
      <title>HIP distribution into Remote Networks</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/hip-distribution-into-remote-networks/m-p/1256583#M1304</link>
      <description>&lt;P&gt;We have:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* Mobile Users&lt;/P&gt;
&lt;P&gt;* Remote Networks&lt;/P&gt;
&lt;P&gt;* Internal Gateways&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We get Mobile Users userid and hip data by redistributing into the on-prem environment from all three Service Connections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, we setup distribution into Remote Networks from the Internal Gateway and TAC said it's not a supported configuration to distribute into Remote Networks, since it introduces a loop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that correct?&lt;/P&gt;
&lt;P&gt;Is there a way to prevent Remote Networks from redistributing back to the Service Connections?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For others who use Mobile Users, Remote Networks, and Internal Gateways, how do you redistribute userid/hip appropriately?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 21:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/hip-distribution-into-remote-networks/m-p/1256583#M1304</guid>
      <dc:creator>sk_display</dc:creator>
      <dc:date>2026-06-17T21:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: HIP distribution into Remote Networks</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/hip-distribution-into-remote-networks/m-p/1256877#M1305</link>
      <description>&lt;P&gt;If TAC itself said it is an issue then in the forum you may not get a better answer. Better try something else in that case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe Prisma Access can feed this to CIA (Cloud Identity Engine &lt;SPAN&gt;) and then everything else can get the data from there:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/identity/cloud-identity-engine/identify-users-and-devices-with-cie" target="_blank"&gt;Identify Users and Devices with Cloud Identity Engine&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jun 2026 05:01:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/hip-distribution-into-remote-networks/m-p/1256877#M1305</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2026-06-21T05:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: HIP distribution into Remote Networks</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/hip-distribution-into-remote-networks/m-p/1258774#M1312</link>
      <description>&lt;P&gt;As have not given enough information to be honest your case sounds as when users connect to a on-prem Gateway FW that and the connection then does not go through Prisma Access but directly to the DC or remote networks and this seems not possible but maybe with CIA as a central point for User Identification as I mentioned this could work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-user-based-policy/identity-redistribution#idfb8c3233-fc37-46c3-8473-4bfd9da1ba17" target="_blank" rel="noopener"&gt;Identity Redistribution&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 06:07:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/hip-distribution-into-remote-networks/m-p/1258774#M1312</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2026-07-13T06:07:24Z</dc:date>
    </item>
  </channel>
</rss>

