<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/614867#M985</link>
    <description>&lt;P&gt;OK, I've connected firewall in the site of another SC to sc-user-id for that location...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And it changes nothing. I see the user-id data for the same gateways as before, but the broken are still broken.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Escalating in TAC...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Kacper&lt;/P&gt;</description>
    <pubDate>Fri, 25 Oct 2024 14:37:41 GMT</pubDate>
    <dc:creator>VTQNetwork</dc:creator>
    <dc:date>2024-10-25T14:37:41Z</dc:date>
    <item>
      <title>Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/605681#M868</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem with user-id data redistribution from Prisma Access to on-prem (panorama).&lt;/P&gt;
&lt;P&gt;I have 13 globalprotect gateways globally, I see the usernames in traffic logs for all gateways.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I redistribute user-id from prisma to on-prem panorama via service connection and then redistribute from panorama to on-prem firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, I have no user-id redistribution for 4 of 13 gateways in Panorama -&amp;gt; on-prem NGFWs, so user-based security policies does not work when user is connected to the "affected gateway".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it something I can fix on my side?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Kacper&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 14:27:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/605681#M868</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2024-10-17T14:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/607220#M872</link>
      <description>&lt;P&gt;I have a questions&lt;BR /&gt;&amp;gt; Are those gateways [for which you are seeing the user ID] are connected to service connection?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 13:05:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/607220#M872</guid>
      <dc:creator>abhinav2308</dc:creator>
      <dc:date>2024-10-19T13:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/607222#M873</link>
      <description>&lt;P&gt;A small correction&lt;BR /&gt;&lt;SPAN&gt;for which you are not seeing the user ID&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 13:06:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/607222#M873</guid>
      <dc:creator>abhinav2308</dc:creator>
      <dc:date>2024-10-19T13:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/609173#M875</link>
      <description>&lt;P&gt;I have two service connections.&lt;/P&gt;
&lt;P&gt;Panorama is connected behind one of them.&lt;/P&gt;
&lt;P&gt;Working gateway IS in the same compute center as SC connecting Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not working gateways is another SC location and locations without SC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the testing purpose, I’ve connected two user-ids (IP address specified for two SCs) to the Panorama (behind one of these two SC).&lt;/P&gt;
&lt;P&gt;I see status connected, but it does not change the situation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kacper&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 06:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/609173#M875</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2024-10-21T06:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/613562#M957</link>
      <description>&lt;P&gt;Check if you have enabled the identity redistribution on that service connection (where the non working gateways are connected)&lt;/P&gt;
&lt;P&gt;Check if you have enabled these option for the SC&lt;/P&gt;
&lt;P&gt;ip to user&lt;/P&gt;
&lt;P&gt;Ip to tag&lt;/P&gt;
&lt;P&gt;User to tag&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 08:37:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/613562#M957</guid>
      <dc:creator>abhinav2308</dc:creator>
      <dc:date>2024-10-23T08:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/614867#M985</link>
      <description>&lt;P&gt;OK, I've connected firewall in the site of another SC to sc-user-id for that location...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And it changes nothing. I see the user-id data for the same gateways as before, but the broken are still broken.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Escalating in TAC...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Kacper&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 14:37:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/614867#M985</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2024-10-25T14:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/614880#M986</link>
      <description>&lt;P&gt;Users connected:&lt;/P&gt;
&lt;P&gt;Gateway OK: 192.168.227.13&lt;/P&gt;
&lt;P&gt;Gateway NOK: 192.168.229.46&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;User-id info:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@panorama&amp;gt; show user ip-user-mapping-mp all | match as.test&lt;BR /&gt;192.168.227.13 REDIST as.test@domain 10187 100.107.127.169&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@firewall(active)&amp;gt; show user ip-user-mapping-mp all | match as.test&lt;BR /&gt;192.168.227.13 vsys1 REDIST domain\as.test 10466 100.107.127.169&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1050809597"&gt;@abhinav2308&lt;/a&gt;&amp;nbsp;: What do you mean by "&lt;SPAN&gt;Check if you have enabled the identity redistribution on that service connection &lt;/SPAN&gt;"?&lt;BR /&gt;&lt;BR /&gt;Kacper&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 14:53:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/614880#M986</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2024-10-25T14:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/615433#M998</link>
      <description>&lt;P&gt;Identity redistribution is same as user id redistribution&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also the commands which you executed&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These need to be executed on the gateway by TAC&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest you to open a case.with the TAC team&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you can refer to this document for the identity redistribution&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 12:12:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/615433#M998</guid>
      <dc:creator>abhinav2308</dc:creator>
      <dc:date>2024-10-28T12:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/615434#M999</link>
      <description>&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/3-2/prisma-access-panorama-admin/configure-user-based-policies-with-prisma-access/redistribute-userid-information-for-users-and-networks" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/3-2/prisma-access-panorama-admin/configure-user-based-policies-with-prisma-access/redistribute-userid-information-for-users-and-networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 12:13:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/615434#M999</guid>
      <dc:creator>abhinav2308</dc:creator>
      <dc:date>2024-10-28T12:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/615462#M1000</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;Yeah, I already know this document by heart &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I also have support case open for 2 weeks, but here I have better support than with TAC...&lt;BR /&gt;&lt;BR /&gt;My question is one (if you have the Prisma):&lt;BR /&gt;Is only one SC user-id enough to get info about all users connected to all gateways globally?&lt;/P&gt;
&lt;P&gt;Or if I have 3 SC in 3 sites, should I connect all 3 user-ids from all 3 sites with SC?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Kacper&lt;/P&gt;
&lt;P&gt;Kacper&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 15:25:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/615462#M1000</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2024-10-28T15:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/615594#M1001</link>
      <description>&lt;P&gt;One service connection configured as user id is enough&amp;nbsp;&lt;BR /&gt;&amp;nbsp;for user id you need only two things&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; agent&lt;BR /&gt;&amp;gt; collector&lt;BR /&gt;here your service connection will act as a collector, the main task of collector is collect the user-id&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and so what I know is only one service connection is enough to configure.&lt;/P&gt;
&lt;P&gt;I will check more about this and update you&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 15:50:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/615594#M1001</guid>
      <dc:creator>abhinav2308</dc:creator>
      <dc:date>2024-10-29T15:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/639073#M1018</link>
      <description>&lt;P&gt;There is new a feature to select which SC is used for identity redistribution if you have several &lt;A href="https://docs.paloaltonetworks.com/prisma-access/release-notes/5-0/prisma-access-about/new-features" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma-access/release-notes/5-0/prisma-access-about/new-features&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 08:50:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/639073#M1018</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2024-11-20T08:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/643782#M1025</link>
      <description>&lt;P&gt;Great news, thank you!&lt;BR /&gt;&lt;BR /&gt;"By default, all of your service connections, in order of proximity, are used for identity redistribution. However, you may not know which specific service connections are being used for identity redistribution at a given moment. And, depending on the number of service connections you have and the number of User-ID agents you’ve configured, this method for identity redistribution can test the limits of your system resources. To solve this, we now give you the option to decide which service connections you want to use for identity redistribution."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The "proximity" in my case was in the 5000km radius &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;With the new feature deployment I should be able to manage redistribution.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 11:35:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/643782#M1025</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2024-11-21T11:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/643787#M1026</link>
      <description>&lt;P&gt;TAC helped me to solve it. I've had third SC defined, but not used. The lost user-id was being there. So the correct answer is - you MUST connect all SC user-ids even if you think you do not use it. Nobody knows the "proximity" definition.&lt;BR /&gt;&lt;BR /&gt;I'll mark your answer with a link to manual as the solution. It was written "repeat with all"....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 11:38:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/643787#M1026</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2024-11-21T11:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Mobile Users - User-id data redistribution to on-prem NGFWs</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/650517#M1028</link>
      <description>&lt;P&gt;got to know something new&lt;BR /&gt;thank you for the information&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 05:32:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-mobile-users-user-id-data-redistribution-to-on/m-p/650517#M1028</guid>
      <dc:creator>abhinav2308</dc:creator>
      <dc:date>2024-11-23T05:32:41Z</dc:date>
    </item>
  </channel>
</rss>

