u/snovah

Prisma Access, Global Protect, User-ID, and on-prem NGFWs

Rejected title: "Prisma Access, User-ID, and Me"

Hey there folks, hoping someone here might be able to point me in the right direction. I've inherited an environment that's running a combination of things: about 20 on-prem NGFWs, including cloud-hosted VM-series, Prisma Access (specifically Mobile Users), Cloud Identity Engine, and Panorama managing all of these.

The issue I've been running into is a bit of a weird one: to get User-ID working "again". Apparently, when this environment was built (about ~3-4 years ago), the MSP tasked with it left with User-ID (and applicable security policies) working. Something in 2023 or 2024 broke it, and there was no-one available at the time to investigate, so the folks there just focused on working around it.

Currently, I know that CIE and Prisma Access/Global Protect are functional in fetching and applying User-ID information. For actual remote users, there's no problems. However, we also have internal host discovery enabled for employees so that, when they're on-site, it doesn't build a tunnel and force all that traffic over to the Prisma gateways; instead, the GP instance just flips to "Internal". All as expected so far.

Except, for some reason, when the Global Protect App switches to "Internal", no User-ID information is being passed on to the NGFW, despite authentication having been successful (and therefore, to my understanding, having "captured" user info).

My guess is that there's some redistribution component that was changed in the past and is now broken, except I have no what it is, and having gone around to look, I'm finding a lot of conflicting or overlapping advice/suggestions: configure local gateways and put them in the Mobile_Users_Template->Portal->Agent (etc.) config; configure it in Remote Networks (a subscription we don't use); there was some major feature changes that possibly broke it in 2024; and so on.

Basically, I'm just trying to understand: is there a configuration with the assets we currently have that would allow local users to authenticate, not have GP build a tunnel, but still pass the User-ID information to the NGFW?

reddit.com
u/snovah — 3 days ago