Firewall suddenly stopped reading EntraID groups from CIE

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Firewall suddenly stopped reading EntraID groups from CIE

L0 Member

We have been using CIE for about half a year now for a spesific usecase where we use som groups that are maintained in Entra ID to control network access, monday we were made aware that that access did not update for new users.

 

CIE does have the correct group mapping, but the firewalls does not sync with CIE.

 

Debugging the issue we have found that the firewall does not manage to find the instance of CIE:

StianKantebakke_0-1747212225376.png

We checked with a second pair of firewalls we have on the same tennant and the same issure happens there.

 

In the logs we have found one supicious event about instance region 'kr' that started monday(have repeated multiple times), but dont find anything in the config that refers to that region:

StianKantebakke_1-1747212443937.png

looking at the log in the cli we found some more errors:

StianKantebakke_2-1747212811193.png

In the traffic log all traffic out from the management ip is allowed. The firewalls device certificate is valid.

 

We have repportet the problem to partner support, have not had the need to use them before so dont know what to expect, but they have broken the 4h responce time at least now 😞

 

So reaching out here to hear if someone got some suggestions of possible errors or have experienced something similar before?

2 REPLIES 2

Cyber Elite
Cyber Elite

make sure the firewall is properly associated to your tenant via common services > device association

verify that the device certificate is valid and not throwing an error

 

whats the output of 

show device-certificate status

show user cloud-identity-engine status all

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Thank you for the reply, all 4 of our firewalls are listed under device association on common services.

 

output from those commands are:

StianKantebakke_0-1747291559228.png

 

  • 473 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!