User ID redistribution
When users log on to a MU-SPN via GlobalProtect, they receive an IP address from the pool used by the SPN. Their username is also mapped against that IP address to form a user ID. These User-IDs can be used to grant users access to specific resources via security rules, provide them with a specific GlobalProtect agent configuration, or simply log what they are doing in terms of traffic, URLs, and threat logs.
This user ID can also be shared with other Palo Alto NGFW so that policies can be applied to down range
. This can be useful when a user is connecting to a datacenter resource that is behind a service connection. Security is only enforced on the SPN in Prisma Access, so the datacenter must have its own security enforcement, and any subsequent connected networks may also be equipped with their own NGFW. Without user ID redistribution, these firewalls outside Prisma Access will only be able to apply security based on the source address.
There is already...