Redistribute User-ID Information From Prisma Access to an
on-premises Firewall.
In cases where mobile users need to access a resource on a remote network
location or HQ/data center and the resource is secured by an on-premises
next-generation firewall with user-based policies, you must redistribute IP
address-to-username mapping from the Prisma Access mobile users and users at
remote networks to the on-premises firewall. When the user connects to Prisma
Access, it collects this user-to-IP address mapping and stores it.
The following figure shows two mobile users who have an existing IP
address-to-username mapping in Prisma Access. Prisma Access then redistributes
this mapping by way of a either a service connection (SC-CAN) or remote network
connection (RN-SPN) to the on-premises firewall that secures the HQ/data
center.
Prisma Access uses the service connection or remote network connection as an
IPSec tunnel that serves as the underlay path to the Layer 3 network. You
can use any route path over an IPSec trusted tunnel for privately addressed
destinations to redistribute this mapping.
To redistribute User-ID mappings from Prisma Access to an on-premises firewall,
complete the following steps.
Make sure you don't apply any SSL decryption on any connection that
redistributes user identity to the on-premises firewall (the SC-CAN or
RN-SPN), including any firewalls that are in the redistribution path.
Alternatively, you can apply a
decryption exclusion to the
redistribution traffic.