<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Redistribute Global protect mappings to another FW in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220817#M63654</link>
    <description>&lt;P&gt;It redistributes User-ID info no matter which source it came from (GP, User-ID agent, AD, syslog...)&lt;/P&gt;</description>
    <pubDate>Fri, 06 Jul 2018 05:51:25 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2018-07-06T05:51:25Z</dc:date>
    <item>
      <title>Redistribute Global protect mappings to another FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220592#M63620</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can not identify GP users in a remote FW. We can see all AD mappings but not GP. I explain the scenario:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;INTERNET&amp;nbsp; ---------------&amp;gt; FW Central (gateway GP) -----&amp;gt; MPLS --------------&amp;gt; Remote FW PALO ALTO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;both PA are integrated with LDAP, but not have userid agents.&lt;/P&gt;&lt;P&gt;We can see the AD users in both PA, but when a user is connecting by Global protect, the remote FW Palo Alto can NOT identify the mapping USER/IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In FW Central we can see&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1 domain/david.james&amp;nbsp; GP&lt;/P&gt;&lt;P&gt;but in FW remote &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; uknown unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is normal because GP is only in FW Central, but there is any way to redistribute the GP mapping to the remote FW???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 10:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220592#M63620</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2018-07-05T10:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Redistribute Global protect mappings to another FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220617#M63624</link>
      <description>&lt;P&gt;Yes, you can redistribute User-ID infor between PA firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/deploy-user-id-in-a-large-scale-network/redistribute-user-mappings-and-authentication-timestamps/configure-user-id-redistribution" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/deploy-user-id-in-a-large-scale-network/redistribute-user-mappings-and-authentication-timestamps/configure-user-id-redistribution&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 13:04:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220617#M63624</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-05T13:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Redistribute Global protect mappings to another FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220619#M63626</link>
      <description>&lt;P&gt;Yes, but without userid agents? and GP users information?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what config we have to do in the FW which will receive the mappings??? i see that we only configure the FW will send the mappings, but in the fw receiving?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 13:13:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220619#M63626</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2018-07-05T13:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Redistribute Global protect mappings to another FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220621#M63627</link>
      <description>&lt;P&gt;You don't need agents for GP users. PA which terminates GP connections has all the info about these users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On receiving PA you set the first PA as User-ID agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 13:18:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220621#M63627</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-05T13:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Redistribute Global protect mappings to another FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220624#M63629</link>
      <description>&lt;P&gt;Ues, i know its not necessary agents for GP. But a FW can send all GP users info matches to another FWs???? or the FW can only send UIA/AD info to another FW?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 13:47:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220624#M63629</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2018-07-05T13:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Redistribute Global protect mappings to another FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220817#M63654</link>
      <description>&lt;P&gt;It redistributes User-ID info no matter which source it came from (GP, User-ID agent, AD, syslog...)&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 05:51:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/220817#M63654</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-06T05:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Redistribute Global protect mappings to another FW</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/221071#M63701</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;It redistributes User-ID info no matter which source it came from (GP, User-ID agent, AD, syslog...)&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The only exception are mappings from Terminal Server agents which cannot be redistributed.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jul 2018 10:19:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/redistribute-global-protect-mappings-to-another-fw/m-p/221071#M63701</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-08T10:19:48Z</dc:date>
    </item>
  </channel>
</rss>

