Connect Cloud NGFW for AWS to your private identity infrastructure through AWS
Resource Gateway to enforce User-ID based security policies.
| Where Can I Use This? | What Do I Need? |
User-ID is the ability of the Palo Alto Networks® firewall to identify
the username associated with a specific IP address. User-ID based policies provide a
unified management workflow that mirrors managing physical and virtual firewalls, so
you can enforce identity-based security without the operational overhead of managing
the underlying cloud infrastructure.
For more information, see Overview of User-ID and LDAP.
You can securely connect Cloud NGFW for AWS instances to your private
infrastructure—LDAP, Active Directory, and User-ID redistribution agents—using AWS
Resource Gateway. The AWS Resource Gateway architecture lets Cloud NGFW interact
with private network resources that reside on-premises or within separate VPCs
without exposing them to the public internet. Your Panorama acts as a User-ID
Redistribution Agent, learning mappings from upstream firewalls or agents and
redistributing them to your Cloud NGFW resources. The key benefits include, the
following:
Architecture and Integration
To access private hybrid cloud resources—such as on-premises Active Directory
servers, syslog servers, or User-ID agents—without exposing them publicly, Cloud
NGFW uses the AWS Resource Gateway. The Resource Gateway leverages AWS PrivateLink
to create a secure resource VPC endpoint, enabling Cloud NGFW to communicate with
private resources in your hybrid environment.
By configuring a Resource Gateway, you can:
This eliminates the need to expose identity infrastructure to the public
internet or construct complex networking workarounds, preserving strict security
best practices.
Prerequisites