Enable the sharing of user context such as IP address-to-username mappings across
your Next-Generation Firewalls.
| Where Can I Use This? | What Do I Need? |
As Next-Generation Firewall (NGFW) deployments scale across sites and regions,
sharing user context (identity mappings, for example) across NGFWs ensures
consistent policy enforcement. Cloud redistribution enables NGFWs to exchange
mapping information without requiring direct peer-to-peer connections between them.
The User Context Cloud Redistribution Service acts as a central exchange point:
NGFWs upload the user context they learn locally and download what they need from
other NGFWs through the service.
The user context (data types) supported for redistribution through the User Context
Cloud Redistribution Service are as follows:
| Data Type | Description |
|
|
Maps an IP address to the specific port range that the Terminal
Server agent allocates to a Windows-based terminal server user.
This mapping identifies individual users in environments, such
as Virtual Desktop Infrastructure (VDI), where multiple users
share the same IP address.
|
|
|
Maps an IP address to a network tag, which enables you to enforce
security policy rules using Dynamic Address Groups.
|
|
|
Maps an IP address to a specific username. This information is
gathered from various sources, including GlobalProtect,
Authentication Portals, Syslog, XML APIs, XFF Headers, and
Server Monitoring.
|
|
|
Maps a tag to a user, which enables you to enforce security
policy rules based on user attributes with Dynamic User
Groups.
|
|
|
Lists devices that GlobalProtect or Cortex XDR flagged as
compromised or non-compliant, so you can block them from
accessing your network.
|
Data flows through
segments, which are logical groupings of NGFWs you
define based on region or other use cases. You control which data your NGFW
contributes or receives and the segments through which that data flows. Each NGFW
can contribute a given data type to only one segment but can receive from multiple
segments.
You can choose one of two operation modes for the cloud service:
If you have multiple virtual systems (vsys), you can select a vsys as a
User-ID hub to share identity mappings
between virtual systems. For a given data type, all vsyses must use the same segment
ID and the same contributing setting (all enabled or all disabled). To receive data,
you must configure a hub vsys: the hub vsys downloads mappings from the cloud and
distributes them to all other vsyses. If no hub vsys is configured, the commit
fails.