UserID Redistribution Filters working weirdly

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

UserID Redistribution Filters working weirdly

L1 Bithead

Hi there

I have a customer setup with a central "Hub"/HQ-Firewall (Pair) and a lot of smaller "Spoke"/Site firewalls connected via S2S Tunnels. Each Site and the HQ have local AD DCs and UserID-Agent Server to collect User/IP-Mappings locally. Also in some Sites and HQ ther is Global-Protect running (adds more mappings).

The customer needs all the user-ip-mappings in all the sites. So we have redistribution configured in both ways from each spoke to the hub. Obviously this leads to a load of redundant mappings floating and looping around.

 

So, I wanted to improve this by using Redistribution Filters (Include/Exclude Networks). I must say, the documentation about this feature is scarce... But I thought i understood what it did... but I was wrong: Since each Site has a /16 Network-Prefix, I just added this prefix as an include statement. My hope was, that this would lead the site to only send mappings of its own prefix back to the hub (and therefore stop the loops of the mappings).

What actually happened was that the site only learned mappings of the prefix in the inlclude statement... And I think (need to confirm) it also only redistributed those to the hub. So, If I got this right, the feature is nealy useless (for my case).

 

Does anyone have experience with this feature / behaviour of the feature?
How do you understand it works - from your experience?

Any idea how I could solve this problem (bearing in mind that mappings need to flow both ways)?
I have also a working instance of CIE in place. But this is thought as a backup-path. The customer does not want to rely on it a the primary path. 

 

thanks
Andreas

 

1 REPLY 1

L1 Bithead

Update:
I confirmed it now: The include/exlude Filters apply to both the "import" and "export" (terms borrowed from routing) of mappings to other firewalls.

So, it seems the filter do not allow me to build a design with redundancy / bi-directional flow of mappings without having a lot of duplicates flowing/looping around.
There is a limit of 10 hops for user-ip-mappings. But still this seems unfortunate.

  • 209 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!