User-ID Based Policy for Cloud NGFW for AWS
Focus
Focus
Cloud NGFW for AWS

User-ID Based Policy for Cloud NGFW for AWS

Table of Contents

User-ID Based Policy for Cloud NGFW for AWS

Connect Cloud NGFW for AWS to your private identity infrastructure through AWS Resource Gateway to enforce User-ID based security policies.
Where Can I Use This?What Do I Need?
  • Cloud NGFW for AWS (Managed by Panorama)
  • Cloud NGFW subscription
  • Panorama version 11.2.14 or later
  • AWS Plugin 5.5.1 or later installed on Panorama
  • For on-premises resources: site-to-site connectivity via AWS Direct Connect or AWS Site-to-Site VPN
User-ID is the ability of the Palo Alto Networks® firewall to identify the username associated with a specific IP address. User-ID based policies provide a unified management workflow that mirrors managing physical and virtual firewalls, so you can enforce identity-based security without the operational overhead of managing the underlying cloud infrastructure. For more information, see Overview of User-ID and LDAP.
You can securely connect Cloud NGFW for AWS instances to your private infrastructure—LDAP, Active Directory, and User-ID redistribution agents—using AWS Resource Gateway. The AWS Resource Gateway architecture lets Cloud NGFW interact with private network resources that reside on-premises or within separate VPCs without exposing them to the public internet. Your Panorama acts as a User-ID Redistribution Agent, learning mappings from upstream firewalls or agents and redistributing them to your Cloud NGFW resources. The key benefits include, the following:
  • Unified policy authoring: You can author security rules using the Source User field in Panorama device groups dedicated to Cloud NGFW.
  • Identity source integration: Panorama can be configured to use LDAP or Cloud Identity Engine (CIE) as the source for user-to-group mappings, which are then referenced in your cloud security policies.
  • Visibility and reporting: Usernames appear in the Panorama Log Viewer, providing identity-aware visibility into cloud traffic instead of just IP addresses.
  • Granular enforcement: Policies can be defined by user groups rather than static IP ranges, which is critical for securing shared services and virtual desktop infrastructure (VDI) environments in the cloud.
  • Hybrid consistency: You can reuse existing address objects and custom security profiles from your on-premises Panorama setup for your cloud deployments.
Architecture and Integration
To access private hybrid cloud resources—such as on-premises Active Directory servers, syslog servers, or User-ID agents—without exposing them publicly, Cloud NGFW uses the AWS Resource Gateway. The Resource Gateway leverages AWS PrivateLink to create a secure resource VPC endpoint, enabling Cloud NGFW to communicate with private resources in your hybrid environment.
By configuring a Resource Gateway, you can:
  • Securely access Active Directory for User-Group mappings.
  • Connect to on-premises User-ID agents.
  • Alternatively, connect to an on-premises Panorama appliance configured as a User-ID redistribution agent.
This eliminates the need to expose identity infrastructure to the public internet or construct complex networking workarounds, preserving strict security best practices.
Prerequisites
  • Ensure that you have Panorama version 11.2.14 and above with AWS Plugin 5.5.1 version installed.
  • If your private resources (LDAP/Active Directory/UserID Redistribution Agent) reside on-premises, you must ensure existing site-to-site connectivity to the client VPC using AWS Direct Connect (DX) or an AWS Site-to-Site VPN.

Deploy User-ID Based Policy for Cloud NGFW for AWS

This section outlines the implementation and management of User-ID based policies for Cloud Next-Generation Firewalls (NGFW) deployed in AWS and managed centrally via Panorama. This integration allows network security teams to leverage their existing Identity Provider (IdP) infrastructures to enforce granular, user-based access controls for cloud workloads.
Use the following end-to-end workflow to implement User-ID based policy enforcement on Cloud NGFW for AWS.
  • Cloud NGFW cannot act as a redistribution agent or User-ID agent.
  • Ensure that your Cloud NGFW firewall is not the primary device in the Panorama device group configuration when retrieving LDAP group information.
  • IPv6 is not supported.
Step 1- Retrieve User-Group mapping source from Panorama for CNGFW for AWS
You must review your Panorama configuraton for the User-Group mappings.
  • Identify the Identity Source Type.
  • Check Panorama Configuration Based on Source.
Step 2- Retrieve User-IP redistribution agent from Panorama
Review your Panorama configuraton for the Redistribution agent information. For more information, see Configure Data Redistribution.
Step 3- Enable Cloud NGFW for AWS resource to reach the User-Group redistribution source to retrieve User-group mappings
Create a Resource Gateway
Share the User-Group source and User-IP redistribution agent information with Cloud NGFW service using AWS resource gateway and AWS RAM.
1. Get your resource configuration ID from resource gateway.
2. Add the resource configuration ID to the Cloud NGFW resource.
Step 4- Enable Cloud NGFW for AWS resource to reach the Data Redistribution Agent to retrieve the User-IP mappings
To map private resources in Cloud NGFW, log into the Cloud NGFW Console, go to the Private Access tab, and create a new integration entry.
Enter a tracking name, choose Group or Single as the Resource Configuration Type, set the Host property to the exact static Private IP address of the Redistribution Agent configured in AWS, and input both the Parent ARN and Child ARN from your AWS Resource Configuration.
Step 5- Verify the connectivity and Status Commit and Push to Devices in Panorama.
  1. Retrieve User-Group mapping source from Panorama for CNGFW for AWS.
    Review your Panorama configuration for User-Group mappings. Determine whether Panorama is acquiring user-to-group mappings from Cloud Identity Engine or an LDAP/Active Directory server.
    • If using Cloud Identity Engine: Open the Panorama console and verify that Cloud Identity Engine is integrated with Panorama for user group mappings. No IP address or port extraction is required for the Resource Gateway configuration—mappings are automatically learned and synced to Cloud NGFW.
    • If using LDAP/Active Directory:
      1. In the Panorama console, select DeviceServer ProfilesLDAP.
      2. Open your active LDAP server profile.
      3. In the Server List table, note the exact static private IP address of your Active Directory/LDAP server (for example, 172.31.27.193) and the port number (389 or 636).
      4. Select User IdentificationGroup Mapping and verify that the group mapping profile references this LDAP server profile and that the Active Directory tree is pulling directory containers.
  2. Retrieve User-IP redistribution agent from Panorama.
    Review your Panorama configuration for the User-IP redistribution agent.
    You must have the exact native Private IP address and port number (typically 5007). Make sure to record the native private IP address rather than any transformed endpoint string, as this exact IP and port combination will be required when setting up your AWS Resource Configuration.
  3. Create and share the AWS Resource Gateway configuration.
    1. In the AWS Console, go to the Resource Gateway service page and click Create Resource Gateway.
    2. Specify a unique identifier, choose your network stack properties (IPv4, IPv6, or Dual Stack), assign the target client VPC, and configure your security groups, then click Create.
    3. Go to Resource Configuration and click Create Configuration.
    4. Choose your configuration type and resource definition type.
    5. Enter the exact private IP address and port ranges of your destination resource (for example, your Panorama instance or primary Active Directory/LDAP server), then click Create Resource Configuration.
    6. In the Cloud NGFW Console, go to the Firewall page, open the Private Access tab, and copy the Deployment Plane Account ID.
      The DP Account ID is found in your CNGFW Console Private Access Tab. See Step 4.
    7. In the AWS Resource Access Manager (RAM) dashboard, create a new resource share. Attach the Amazon Resource Name (ARN) of the resource configuration you created, paste the copied Deployment Plane Account ID as the principal recipient, and click Share.
      The platform automatically accepts the share request.
  4. Map private resources in the Cloud NGFW Console.
    1. In the Cloud NGFW Console, go to the Private Access tab.
    2. Click Add
      • A maximum of 2 ARNs can be configured when the resource configuration type is Single.
      • A maximum of 40 ARNs can be configured when the resource configuration type is Group.
    3. Enter a tracking name and choose Group or Single as the Resource Configuration Type.
    4. For Host, enter the same static private IP address you used when building the AWS resource configuration.
    5. Enter the Parent ARN and Child ARN from your AWS resource configuration, then click Add.
      After you save the mapping, the backend automatically provisions a VPC endpoint link connecting the deployment plane to the client network through the resource gateway. The link displays one of the following statuses:
    1. In Panorama, select DeviceData Redistribution and click Add.
    2. For Host, enter the private IP address of the redistribution agent.
    3. For Port, enter 5007.
    1. In Panorama, select DeviceServer ProfilesLDAP and click Add.
    2. Configure the profile with your Active Directory server details:
      • Type/Host: Enter the private IP address of your Active Directory server.
      • Base DN: Define your directory structure (for example, DC=demo,DC=local).
      • Credentials: Enter the lookup account credentials and authentication type.
    1. In Panorama, go to User Identification and create a new group mapping that references the LDAP server profile you configured.
    2. Under the group include list, click Add.
      Select Add under the group include window to verify the network path. The environment pulls your Active Directory tree dynamically to confirm the Resource Gateway route is functional.
      Dynamic group population in drop-down menus during policy authoring requires configuring your Cloud Device Group as a child of a regular Device Group with an assigned master device. For more information, see Map User to Groups and Manage your Device group configurations.
    3. Select the directory containers you want to enforce policy on (for example, Human Resources or Administrators).
    Build security policies in your Panorama device group to enforce controls based on user identity.
    • User group rule: Define a rule identifying a source group (for example, demo/all-user-groups) directed to a specific destination with the action Deny.
    • Individual user rule: Define a rule for a specific source user account (for example, demo/paloalto) directed to a specific destination with the action Deny.
  5. In Panorama, Commit and Push to Devices to push the security changes to your firewalls.