Identity Manager LDAP Query Identification for Palo Alto Firewall App-ID
search cancel

Identity Manager LDAP Query Identification for Palo Alto Firewall App-ID

book

Article ID: 226904

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

Identity Manager utilizes standard LDAP protocols to communicate with Provisioning Endpoints. When configuring Palo Alto Firewalls to permit this traffic, administrators often search for a pre-defined "Identity Manager" App-ID. This article clarifies how these requests are identified and provides resources for custom configuration.

Environment

Identity Manager 14.x 

Cause

  • Firewall logs show "unknown-tcp" or generic "ldap" traffic from Identity Manager.
  • Security policies requiring specific Application IDs (App-ID) for Identity Manager traffic are not being met.

Resolution

Palo Alto Networks does not provide a built-in, pre-defined App-ID specifically for Broadcom Identity Manager. Traffic is typically identified by the underlying protocol (LDAP or LDAPS).

To manage Identity Manager traffic in your firewall environment, consider the following options:

  • Use Standard App-IDs: Configure rules to allow the standard ldap and ssl (for LDAPS) App-IDs between the Provisioning Server and its endpoints.
  • Create Custom App-IDs: If your security policy requires a specific identifier for Identity Manager, you can create a custom App-ID based on unique traffic signatures.
  • Request App-ID Addition: Contact Palo Alto Networks to request the creation and inclusion of an Identity Manager App-ID in their global library.

Additional Information