- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-05-2018 03:30 AM
Hi,
We can not identify GP users in a remote FW. We can see all AD mappings but not GP. I explain the scenario:
INTERNET ---------------> FW Central (gateway GP) -----> MPLS --------------> Remote FW PALO ALTO
both PA are integrated with LDAP, but not have userid agents.
We can see the AD users in both PA, but when a user is connecting by Global protect, the remote FW Palo Alto can NOT identify the mapping USER/IP.
In FW Central we can see 10.0.0.1 domain/david.james GP
but in FW remote 10.0.0.1 uknown unknown
This is normal because GP is only in FW Central, but there is any way to redistribute the GP mapping to the remote FW???
thanks