The fw-id-mapper container sends Portnox Cloud’s user-to-IP mapping data to an on-premises firewall, so the firewall can apply policies and write logs based on the user instead of just the IP address. When a user’s IP address changes, for example through Wi-Fi roaming, a VPN connection, or a new DHCP lease, the container reports the change to the firewall so its identity data stays current. As of this moment, the integration only supports Palo Alto firewalls.
The container makes outbound connections only, to Portnox Cloud and to the firewall. It needs no inbound ports, and the firewall does not need to be reachable from the Internet.
The command below is an example, with placeholder values that won’t work as-is. We recommend getting the actual command from Portnox Cloud instead of creating one manually: go to Settings > Integration Services > Firewall Integration Service and click Add Docker container. Portnox Cloud generates the complete command for you, already filled in with your organization ID, instance ID, and API key.
docker run -d \
--name portnox-fw-id-mapper --restart=on-failure --pull always \
-e OrgId=<org_id> \
-e InstanceId=<instance_id> \
-e ApiKey=<api_key> \
portnox/fw-id-mapper:latest
On the firewall side, enable User-ID and its XML API, and create a dedicated administrator account for the integration. You configure firewall connection details, address, port, API key, separately in Portnox Cloud, not in this command. The container fetches them from there once it’s running.
You configure the container using environment variables or a configuration file. Additional variables control things like sync intervals, retry behavior, and custom TLS certificates for firewalls that use a private certificate authority. See the full documentation link below for the complete list of variables.
Update the container by redeploying it manually, or automate updates with the portnox-autoupdate container.
For full documentation, see: docs.portnox.com.
Content type
Image
Digest
sha256:4e924c283…
Size
110.7 MB
Last updated
13 days ago
docker pull portnox/fw-id-mapperPulls:
50
Last week