<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserID What's the best practice for configuration crossing multiple firewalls in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-what-s-the-best-practice-for-configuration-crossing/m-p/102452#M44562</link>
    <description>&lt;P&gt;Currently user-id information is only locally known on each firewall where the connections to AD are configured. &amp;nbsp;And the firewalls do not communicate with each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus any firewall along the path of a client communication using user-id will need to have the appropriate rules and AD connections in place to enforce policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on how the traffic goes and how many firewalls you cross, you might be able to organize the most specific rules at either a central point or at a point closest to the users. &amp;nbsp;Then apply more general policies at the other points in the path. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the basic premise is that the traffic will be evaluated based on local PAN knowledge at each firewall crossing. &amp;nbsp;So you need ot consider what that PAN knows about user-id when setting up the rule base.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2016 21:36:43 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2016-08-11T21:36:43Z</dc:date>
    <item>
      <title>UserID What's the best practice for configuration crossing multiple firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-what-s-the-best-practice-for-configuration-crossing/m-p/102091#M44546</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are starting to deploy UserID based policies across our enterprise.&lt;/P&gt;&lt;P&gt;I'd like to know what is the best practice when dealing with rule policies that cross multiple zones/firewalls that are in different locations?&lt;/P&gt;&lt;P&gt;Does the user portion of the rule only need to be as close to the client then go to network rules in between the firewalls and resource or can userID go through the entire network path from client/user to resource?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2016 22:22:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-what-s-the-best-practice-for-configuration-crossing/m-p/102091#M44546</guid>
      <dc:creator>jezkerwin</dc:creator>
      <dc:date>2016-08-10T22:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: UserID What's the best practice for configuration crossing multiple firewalls</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-what-s-the-best-practice-for-configuration-crossing/m-p/102452#M44562</link>
      <description>&lt;P&gt;Currently user-id information is only locally known on each firewall where the connections to AD are configured. &amp;nbsp;And the firewalls do not communicate with each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus any firewall along the path of a client communication using user-id will need to have the appropriate rules and AD connections in place to enforce policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on how the traffic goes and how many firewalls you cross, you might be able to organize the most specific rules at either a central point or at a point closest to the users. &amp;nbsp;Then apply more general policies at the other points in the path. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the basic premise is that the traffic will be evaluated based on local PAN knowledge at each firewall crossing. &amp;nbsp;So you need ot consider what that PAN knows about user-id when setting up the rule base.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2016 21:36:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-what-s-the-best-practice-for-configuration-crossing/m-p/102452#M44562</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-08-11T21:36:43Z</dc:date>
    </item>
  </channel>
</rss>

