User identification and group mapping
User identification (user ID) is an integral part of Palo Alto Networks SASE technology, and together with Prisma Access, it forms a very important cornerstone of building security policies. As we’ve seen in previous chapters, all mobile users receive IP addresses from regional or global IP pools. The IP pools are split into 24 subnets and distributed randomly across deployed MU-SPNs, so IP-based policies are difficult to maintain. Deploying security rules based on usernames or AD group membership is much easier and allows users to roam freely between countries while maintaining the same access without needing to maintain complex IP address management.
User ID works by mapping the username associated with a session to the IP address that was assigned from the IP pool. This information can also be shared with other firewalls outside of Prisma Access so that the IP address assigned to a user logging in from the Netherlands, associated with...