- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-14-2025 02:09 AM
We have been using CIE for about half a year now for a spesific usecase where we use som groups that are maintained in Entra ID to control network access, monday we were made aware that that access did not update for new users.
CIE does have the correct group mapping, but the firewalls does not sync with CIE.
Debugging the issue we have found that the firewall does not manage to find the instance of CIE:
We checked with a second pair of firewalls we have on the same tennant and the same issure happens there.
In the logs we have found one supicious event about instance region 'kr' that started monday(have repeated multiple times), but dont find anything in the config that refers to that region:
looking at the log in the cli we found some more errors:
In the traffic log all traffic out from the management ip is allowed. The firewalls device certificate is valid.
We have repportet the problem to partner support, have not had the need to use them before so dont know what to expect, but they have broken the 4h responce time at least now 😞
So reaching out here to hear if someone got some suggestions of possible errors or have experienced something similar before?
05-14-2025 03:59 AM - edited 05-14-2025 04:03 AM
make sure the firewall is properly associated to your tenant via common services > device association
verify that the device certificate is valid and not throwing an error
whats the output of
show device-certificate status
show user cloud-identity-engine status all
05-14-2025 11:46 PM
Thank you for the reply, all 4 of our firewalls are listed under device association on common services.
output from those commands are:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!