Learn how to preserve the User-ID mapping for GlobalProtect users who are accessing
apps behind a data center with ZTNA Connector.
| Where Can I Use This? | What Do I Need? |
You can use ZTNA Connector in Prisma Access to secure private applications. To limit
access to the applications based on User-ID, you can deploy a Next-Generation
Firewall (NGFW) in the data center or headquarters location where the private
applications are located; then, configure policy rules on the NGFW based on User-ID
mapping.
If your deployment uses NGFW in the data center or headquarters location where the
private applications are located, and ZTNA Connector does source NAT, the NGFW can't
retrieve the User-ID mapping because the NGFW can't retrieve the user device's
source IP address. If the NGFW can't retrieve this source IP address, it can't
enforce the zone-based Security policy rules you have created on it based on User-ID
mapping.
ZTNA Connector has the following responsibilities to enable User-ID within the NGFW
secured data center:
- Provide a secure connection from the NGFW to the regional ZTNA Connector Tunnel
Terminators (ZTTs) for the NGFW to connect to its User-ID redistribution
agent.
- For FQDN applications, with the health probe set to tcp ping, application probe the data
center applications to determine if the application is up and reachable from
this individual connector.
- Optionally, encapsulate user-to-app post-NAT data center IP address packets
within a Generic Network Virtualization Encapsulation (Geneve) packet including
the original source IP address.
The following diagram illustrates the network elements that provide the source IP
address to User-ID mapping to the NGFW and deliver Geneve encapsulated data packets
including the original
Prisma Access source IP address option
to the NGFW. These elements enable the NGFW to effectively enforce security policy
rules based on User-ID.
Restrictions:- User-ID Support with ZTNA Connector is only available post these
versions:
- NGFW version: 11.2.0 version and later
- ZTNA Connector version: 6.2.4-ztna-connector-b3 version and
later
- NGFW service route configuration for an User-ID agent only supports
interfaces with static IP addresses. If the NGFW interface is configured to
be in a dynamic mode (IP address assignment through DHCP), the User-ID
channel from NGFW to ZTT can't establish support for the ZTNA Connector
User-ID. To resolve this issue, set up static IP addressing on the NGFW
interface to support the User-ID agent configuration.
- Diagnostic tools like ping and
traceroute are not supported for User-ID based connectors.
This procedure assumes that you have the following network configurations in
place:
To make sure that your network distributes the User-ID mapping to the headquarters or
data center, complete the following steps, which enables NGFW to enforce the
security policy rules based on the User-ID mapping it learns from GlobalProtect.