Learn to redistribute HIP reports from GlobalProtect gateways to other firewalls and
Panorama appliances.
| Where Can I Use This? | What Do I Need? |
- NGFW (managed by Panorama or Strata Cloud Manager)
- Prisma Access (managed by Panorama or Strata Cloud
Manager)
|
- GlobalProtect Gateway license or Prisma Access license with
the Mobile User subscription (All GlobalProtect gateways and
firewalls that redistribute HIP reports must have a
GlobalProtect Gateway license. Panorama appliances that
redistribute HIP reports don't require a GlobalProtect
gateway license.)
|
To ensure consistent Host Information Profile (HIP) policy enforcement and to simplify policy
management, you can distribute HIP reports from the GlobalProtect internal or
external gateway to other firewalls, and Panorama appliances in the enterprise. HIP
report redistribution can be useful in the following cases:
You want to apply consistent policies to both
internal and external GlobalProtect gateways.
You want to apply consistent HIP policies for traffic for a specific user who goes through
multiple firewalls.
To redistribute HIP reports, use the same deployment recommendations and best practices that you
use to
redistribute User-ID information. Keep in
mind that GlobalProtect internal and external gateways don't support bi-directional
HIP redistribution. Therefore, the best practice is to use your Panorama appliance
as your redistribution point. In this deployment, you would configure your internal
and external gateways to send the HIP reports to Panorama and have Panorama forward
them on to your firewalls for consistent policy enforcement across your
environment.
Use
the following steps to configure HIP report redistribution.