08-13-2020 06:59 PM
Hi Legends,
I'm a bit stumped and trying to find a solution on parsing credentials when users authenticate via VPN/ISE and then trying to access data centre services.
Our setup is as follows
We do not want to change this because if we get a ‘man in the middle’ attack, they can replicate the VPN IP Pool and access DC services without a username associated.
Do you guys have any idea how we can get VPN users keep their domain/username when traversing the network. Is it possible for ISE to forward these to the PANs?
Any thoughts/ideas will be greatly appreciated.
Solved! Go to Solution.
08-13-2020 08:07 PM
ISE can pass the username-IP mapping to PANW firewalls via syslog. You then need to allow the USER-ID syslog Listener-UDP service into PANW mgmt interface (or Panorama if you are using that) and setup a parser to extract the information for use in your PANW identity policy.
See this article for example:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5sCAC
08-13-2020 08:07 PM
ISE can pass the username-IP mapping to PANW firewalls via syslog. You then need to allow the USER-ID syslog Listener-UDP service into PANW mgmt interface (or Panorama if you are using that) and setup a parser to extract the information for use in your PANW identity policy.
See this article for example:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5sCAC
08-18-2020 11:52 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide