: Intelligent Security and User Equipment Correlation with IP Addresses
Focus
Focus

Intelligent Security and User Equipment Correlation with IP Addresses

Table of Contents
Learn how to configure Intelligent Security to correlate user equipment with IP addresses.
In a mobile network, identity information such as:
  • the Subscriber ID, such as the International Mobile Subscriber Identity (IMSI) or 5G Subscriber Permanent Identifier (SUPI)
  • the Equipment ID, such as the International Mobile Equipment Identity (IMEI) or Permanent Equipment Identifier (PEI) for User Equipment (UE) and mobile devices
are critical for deploying and establishing a Zero Trust Security policy in 5G and 4G/LTE mobile networks. Intelligent Security helps correlate user equipment information with IP addresses to enforce Security policy. It does this by mapping the subscriber ID and equipment ID to the IP address associated with traffic from the UE This helps to ensure consistent Security policy enforcement in your mobile network.
If you're planning to deploy Intelligent Security (also known as UEIP Correlation), the following platforms support this capability:
  • VM-Series
  • CN-Series
  • PA-3430 and PA-3440
  • PA-5200 Series
  • PA-5400 Series
  • PA-5450 series
  • PA-7000b series
  • PA-7500 series (For HA cluster using PAN-OS 11.1.5 with RADIUS only)
When you enable Intelligent Security, it obtains the UE-to-IP-address mappings and adds them to a database on the firewall. The firewall queries the database for the correlated mobile user information to enforce Security policy. To obtain the mappings, select one of the following supported protocols.
Deploying Intelligent Security helps enforce a more adaptive Security policy for your mobile network by associating user equipment (UE) with IP addresses. This allows your Security policy to evolve as your network and number of users grows without requiring manual updates when the IP address of UE changes.