- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-05-2018 03:30 AM
Hi,
We can not identify GP users in a remote FW. We can see all AD mappings but not GP. I explain the scenario:
INTERNET ---------------> FW Central (gateway GP) -----> MPLS --------------> Remote FW PALO ALTO
both PA are integrated with LDAP, but not have userid agents.
We can see the AD users in both PA, but when a user is connecting by Global protect, the remote FW Palo Alto can NOT identify the mapping USER/IP.
In FW Central we can see 10.0.0.1 domain/david.james GP
but in FW remote 10.0.0.1 uknown unknown
This is normal because GP is only in FW Central, but there is any way to redistribute the GP mapping to the remote FW???
thanks
07-08-2018 03:19 AM
@santonic wrote:It redistributes User-ID info no matter which source it came from (GP, User-ID agent, AD, syslog...)
The only exception are mappings from Terminal Server agents which cannot be redistributed.
07-05-2018 06:03 AM - edited 07-05-2018 06:04 AM
Yes, you can redistribute User-ID infor between PA firewalls.
07-05-2018 06:13 AM
Yes, but without userid agents? and GP users information?
what config we have to do in the FW which will receive the mappings??? i see that we only configure the FW will send the mappings, but in the fw receiving?
07-05-2018 06:18 AM
You don't need agents for GP users. PA which terminates GP connections has all the info about these users.
On receiving PA you set the first PA as User-ID agent.
07-05-2018 06:47 AM
Ues, i know its not necessary agents for GP. But a FW can send all GP users info matches to another FWs???? or the FW can only send UIA/AD info to another FW?
07-05-2018 10:51 PM
It redistributes User-ID info no matter which source it came from (GP, User-ID agent, AD, syslog...)
07-08-2018 03:19 AM
@santonic wrote:It redistributes User-ID info no matter which source it came from (GP, User-ID agent, AD, syslog...)
The only exception are mappings from Terminal Server agents which cannot be redistributed.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!