Dell W-Series 334 Instant 6.5.1.0-4.3.1.0 User Guide - Page 294

Integration with Instant, Configuring a W-IAP for PAN integration, login, logout, More > Services

Page 294 highlights

Integration with Instant The functionality provided by the PAN firewall based on user ID requires the collection of information from the network. W-IAP maintains the network (such as mapping IP address) and user information for its clients in the network and can provide the required information for the user ID on PAN firewall. Before sending the user-ID mapping information to the PAN firewall, the W-IAP must retrieve an API key that will be used for authentication for all APIs. W-IAP provides the User ID mapping information to the PAN firewall for integration. The client user id for authentication will not be sent to the PAN firewall unless it has a domain prefix. The W-IAP checks for the domain information in the client username for all login and logout requests sent to the PAN firewall. If the user id already has a domain prefix, W-IAP forwards the request to the PAN firewall. Otherwise, the static client domain configured in the PAN firewall profile will be prefixed to the user id and then sent to the PAN firewall. W-IAP and PAN firewall integration can be seamless with the XML-API that is available with PAN-OS 5.0 or later. To integrate a W-IAP with PAN user ID, a global profile is added. This profile can be configured on a W-IAP with PAN firewall information such as IP address, port, username, password, firewall-enabled or firewall-disabled status. The W-IAP sends messages to PAN based on the type of authentication and client status: l After a client completes the authentication and is assigned an IP address, W-IAP sends the login message. l After a client is disconnected or dissociated from the W-IAP, the W-IAP sends a logout message. Configuring a W-IAP for PAN integration You can configure a W-IAP for PAN firewall integration by using the Instant UI or the CLI. In the Instant UI To configure PAN firewall integration in a W-IAP: 1. Click More > Services. 2. Click Network Integration. The PAN firewall configuration options are displayed. 294 | Services Dell Networking W-Series Instant 6.5.1.0-4.3.1.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435

294
| Services
Dell Networking W-Series Instant 6.5.1.0-4.3.1.0 | User Guide
Integration with Instant
The functionality provided by the PAN firewall based on user ID requires the collection of information from the
network. W-IAP maintains the network (such as mapping IP address) and user information for its clients in the
network and can provide the required information for the user ID on PAN firewall. Before sending the user-ID
mapping information to the PAN firewall, the W-IAP must retrieve an API key that will be used for
authentication for all APIs.
W-IAP provides the User ID mapping information to the PAN firewall for integration. The client user id for
authentication will not be sent to the PAN firewall unless it has a domain prefix. The W-IAP checks for the
domain information in the client username for all login and logout requests sent to the PAN firewall. If the user
id already has a domain prefix, W-IAP forwards the request to the PAN firewall. Otherwise, the static client
domain configured in the PAN firewall profile will be prefixed to the user id and then sent to the PAN firewall.
W-IAP and PAN firewall integration can be seamless with the XML-API that is available with PAN-OS 5.0 or later.
To integrate a W-IAP with PAN user ID, a global profile is added. This profile can be configured on a W-IAP with
PAN firewall information such as IP address, port, username, password, firewall-enabled or firewall-disabled
status.
The W-IAP sends messages to PAN based on the type of authentication and client status:
l
After a client completes the authentication and is assigned an IP address, W-IAP sends the
login
message.
l
After a client is disconnected or dissociated from the W-IAP, the W-IAP sends a
logout
message.
Configuring a W-IAP for PAN integration
You can configure a W-IAP for PAN firewall integration by using the Instant UI or the CLI.
In the Instant UI
To configure PAN firewall integration in a W-IAP:
1. Click
More > Services
.
2. Click
Network Integration
. The PAN firewall configuration options are displayed.