Configure HIP Redistribution in Prisma Access
Focus
Focus
Prisma Access

Configure HIP Redistribution in Prisma Access

Table of Contents

Configure HIP Redistribution in
Prisma Access

How to configure HIP redistribution in a
Prisma Access (Managed by Panorama)
deployment.
Where Can I Use This?
What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • Prisma Access
    license
When a mobile user whose endpoint has the GlobalProtect app installed connects to Prisma Access,
Prisma Access
collects the user’s HIP information from the endpoint’s GlobalProtect app, which makes the HIP report available in
Prisma Access
.
To use HIP redistribution, users must have the GlobalProtect app installed on their endpoint. While
Prisma Access
supports Clientless VPN, you can't redistribute HIP information for Clientless VPN users.
HIP redistribution is applicable to both mobile users and users at remote networks. However, for users at remote networks, an on-premises gateway must detect that the user is internal to the organization’s network using internal host detection before the on-premises gateway can send HIP information to
Prisma Access
.
In
Prisma Access
, you configure internal host detection when you configure your mobile user deployment.
To assure consistent policy enforcement, you can use HIP redistribution to allow Prisma Access to distribute users’ HIP information to other Panorama appliances, gateways, firewalls, and virtual systems in your deployment, as well as distribute HIP information from those devices to
Prisma Access
in some cases. This ability allows you to consistently apply HIP-based policy enforcement for users’ traffic, including policies for internet-bound traffic or for traffic that is accessing an internal application or resource in your organization’s headquarters or data center. Redistributing HIP information to the Panorama appliance also lets you view detailed HIP information for
Prisma Access
users from that appliance.

Cloud Management

Learn how to redistribute HIP information.

Panorama

Learn how to redistribute HIP information.
To allow
Prisma Access
to collect and redistribute HIP information, complete the following task.
  1. Allow
    Prisma Access
    to redistribute HIP information.
    1. In Panorama, select
      Panorama
      Cloud Services
      Configuration
      Service Setup
      .
    2. Click the gear icon to edit the settings.
    3. In the
      Advanced
      tab, select
      Enable HIP Redistribution
      .
      Enabling HIP Redistribution enables
      Prisma Access
      to redistribute the HIP reports received from the GlobalProtect app to internal firewalls and to Panorama.
  2. Configure Panorama to receive HIP reports from
    Prisma Access
    .
    1. Select
      Panorama
      Setup
      Interfaces
      .
    2. Select the
      Management
      interface.
    3. Select
      User-ID
      .
  3. Configure Panorama to collect the User-ID mapping from
    Prisma Access
    .
    1. From the Panorama that manages
      Prisma Access
      , select
      Panorama
      Data Redistribution
      Agents
      (for Panorama 10.
      x
      appliances) or
      Panorama
      User Identification
      User-ID Agents
      (for 9.1.
      x
      Panorama appliances).
    2. Add
      a User-ID Agent and give it a
      Name
      .
    3. Enter one of the following values in the
      Host
      field, depending on the types of HIP information you want to collect.
      • To collect HIP information for mobile users, enter the
        User-ID Agent Address
        (
        Panorama
        Cloud Services
        Status
        Network Details
        Service Connection
        User-ID Agent Address
        ).
      • To collect HIP information from users at a remote network locations with an internal gateway, enter the IP address of the internal gateway.
      • To collect HIP information from users are a remote network connection, enter the
        EBGP Router
        address (
        Panorama
        Cloud Services
        Status
        Network Details
        Remote Networks
        EBGP Router
        as the User-ID host.
    4. Enter
      5007
      in the port field.
      By default, the User-ID agent uses port 5007 to listen for HIP information requests.
      Make sure that your network does not block access to this port between
      Prisma Access
      and the Active Directory server or User-ID Agent.
    5. Select
      Enabled
      to enable Panorama to communicate with the User-ID agent.
    6. Select
      IP User Mappings
      and
      HIP
      to enable Panorama to receive IP address-to-username mappings and GlobalProtect HIP data from all mobile user locations.
    7. Click
      OK
      .
  4. Repeat Step 3 for each service connection to which you want to configure HIP report collection.

Recommended For You