You use service connections, also
known as service connection—corporate access nodes (SC-CANs), in
Prisma Access to secure private apps. To limit access to the apps
based on User-ID or Device-ID, you can deploy a Next-Generation
Firewall (NGFW) in the data center or headquarters location where
the private apps are located; then, configure policy rules on the
NGFW based on User-ID mapping, Device-ID mapping, or both.
To use these rules, the NGFW must receive the User- or Device-ID
mapping from the SC-CAN; however, if users are connecting to Prisma
Access using GlobalProtect and the SC-CAN has Data
Traffic source NAT enabled, the NGFW can't obtain
this mapping. If Data Traffic source NAT is
enabled on the SC-CAN, it performs NAT on the Mobile User IP address
pool and does not advertise those IP addresses in the data center or
headquarters location. In this case, the NGFW can't retrieve the
GlobalProtect users' User- or Device-ID, which means that you can't
enforce policy based on User- or Device-ID.
To make sure that your network distributes the User- or Device-ID
mapping to the headquarters or data center, select one or more of
the following parameters on the NGFW, which allows the NGFW to
enforce security policy rules based on the User-ID mapping it learns
from GlobalProtect.
- User-ID—Preserves the mobile user User-ID
mapping used before the IP addresses were NATted. Enable this if
you're using User-IDs in security policy rules.
- Device-ID—Preserves the mobile user
Device-ID mapping used before the IP addresses were NATted.
Enable this if you're using Device-ID in security policy
rules.
- Source Lookup—Enables you to match the
original Source IP address received from GlobalProtect. If
you're using source lookup in QoS or policy-based forwarding
(PBF) policies, the source IP comparison is based on the pre-NAT
source IP address. For example, if you had a security policy
that allowed a source IP address of 1.1.1.1 and a destination IP
address of Any, 1.1.1.1 is compared with the pre-NAT source IP
address in the packet header.
- Enable Original ID Downstream—If you have
two NGFWs in a row, specify this option to have the first NGFW
send the pre-NAT information to the second NGFW after the first
NGFW has inspected the traffic and applied policies to it. This
is the default configuration on SC-CANs.
|