SASE Design Guide for Internet Security
SASE Design Guide for Internet Security
GUIDE
JUNE 2024
Table of Contents
Table of Contents
Preface......................................................................................................................................................................................................... 3
Purpose of This Guide................................................................................................................................................................................ 5
Audience.............................................................................................................................................................................................. 5
Related Documentation........................................................................................................................................................................5
Introduction.................................................................................................................................................................................................. 7
On-Premises Solution Challenges........................................................................................................................................................ 7
Secure Access Service Edge...............................................................................................................................................................8
Palo Alto Networks SASE Solution...................................................................................................................................................... 8
Prisma Access Add-On Capabilities.................................................................................................................................................. 13
Design Details............................................................................................................................................................................................19
Prisma Access Design Details........................................................................................................................................................... 19
Prisma SD-WAN Design Details.........................................................................................................................................................44
Design Model.............................................................................................................................................................................................47
Securing Internet for Mobile-Users.................................................................................................................................................... 47
Securing Internet for Remote Sites....................................................................................................................................................51
Summary.................................................................................................................................................................................................... 53
Feedback....................................................................................................................................................................................................54
Preface
GUIDE TYPES
Design guides provide an architectural overview for using Palo Alto Networks® technologies to provide visibility, control, and
protection to applications built in a specific environment. These guides are required reading prior to using their companion
deployment guides.
Deployment guides provide decision criteria for deployment scenarios, as well as procedures for combining Palo Alto
Networks technologies with third-party technologies in an integrated design.
DOCUMENT CONVENTIONS
Blue text indicates a configuration variable for which you need to substitute the correct value for your environment.
• Command-line commands.
• User-interface elements.
• Navigational paths.
• A value to be entered.
An external dynamic list is a file hosted on an external web server so that the firewall can import objects.
ABOUT PROCEDURES
These guides sometimes describe other companies’ products. Although steps and screen-shots were up-to-date at the time
of publication, those companies might have since changed their user interface, processes, or requirements.
[Link]
• Added Remote Browser Isolation and App Acceleration to the Prisma Access Add-On section
• Replaced SD-WAN CloudBlade integration with Prisma Access with the SD-WAN easy onboarding process
This guide:
• Provides a framework for Prisma Access and Prisma SD-WAN architectural discussions between Palo Alto Networks
and your organization.
• Describes the technical design aspects of Prisma Access and how an organization uses it for secure access to the
internet and cloud-based applications.
• Provides a technical overview and design for the Prisma Access GlobalProtect® mobile-user connection method for
secure access to internet and cloud-based applications.
• Explores the recommended design for integrating Prisma SD-WAN with Prisma Access using the Prisma SD-WAN
easy onboarding process.
This design guide focuses specifically on securing access to internet and SaaS applications. For a more complete discussion
of how to secure access to private applications, refer to the SASE for Securing Private Applications: Design Guide.
AUDIENCE
This guide is for technical readers, including system architects and design engineers, who want to deploy Prisma Access. It
assumes the reader is familiar with the basic concepts of applications, networking, routing, security, and high availability. The
reader should also have a basic understanding of network and data center architectures.
To be successful, you must have a working knowledge of networking and security policy.
RELATED DOCUMENTATION
The following documents support this guide:
• SASE for Securing Internet: Design Guide—Provides design and deployment guidance for using Prisma Access
and Prisma SD-WAN to secure internet access for mobile users and users located at remote-site locations.
• SASE for Securing Internet: Deployment Guide—Provides implementation details for using Prisma Access and
Prisma SD-WAN to secure internet access for mobile users and users located at remote-site locations. Includes
decision criteria for deployment scenarios, as well as step-by-step procedures to achieve an integrated design.
• SASE for Securing Private Applications: Design Guide—Provides design and deployment guidance for using
Prisma Access and Prisma SD-WAN to secure access to private applications for mobile users and users located at
remote-site locations.
• SASE for Securing Private Applications: Deployment Guide—Provides implementation details for using Prisma
Access and Prisma SD-WAN to secure access to private applications for mobile users and users located at
remote-site locations. Includes decision criteria for deployment scenarios, as well as step-by-step procedures for
programming features to achieve an integrated design.
• SASE Secure Internet Policy Design: Solution Guide—Provides policy design and deployment guidance for
securing internet services by using the Prisma Access cloud-delivered security platform.
• Identity-Based and Posture-Based Security for SASE: Solution Guide—Provides design and deployment
guidance for obtaining and applying identity-based and posture-based policies in Palo Alto Networks SASE platform.
• Securing Internet Access by Using Explicit Proxy: Solution Guide—Provides design and deployment guidance for
securing internet access by using Palo Alto Networks Prisma Access explicit proxy solution.
• AI-Powered Autonomous Digital Experience Management: Solution Guide—Provides design, deployment, and
operational guidance for integrating ADEM and AI-Powered ADEM with the Palo Alto Networks Prisma SASE solution.
Introduction
As organizations shift towards new operational frameworks, they often encounter difficulties in providing network and security
services efficiently. Users demand quick and easy access to products and services. They want to use a diverse array of
devices to connect to applications from virtually any location. Additionally, companies are embracing digital technologies
across their operations in order to enhance efficiency, execution speed, and cost savings. This process is known as digital
transformation.
Historically, a sizable portion of employees would be based at a main office or a remote site, where IT organizations could
effectively manage network and security provisions. Employees increasingly demand the freedom to be productive from
anywhere while using any device and accessing any application. Homes, coffee shops, and mobile phones have become
seamless extensions of the corporate network. Many organizations also need to allow contractors or other third parties
access to applications or network resources.
The changing work locations of an organization's workforce highly influences the delivery of network and security services.
To support this, companies have turned to multiple secure access tools, network sensors, and management panes in place.
This creates challenges in maintaining operational efficiency, ensuring consistent security policy, and achieving a unified
view of your network security. The consequence of all these shifts is that they still often fail to offer satisfactory application
performance.
Data traffic from users at branch offices destined to private applications or the internet was once straightforward to secure
and manage with a centralized arrangement of security appliances and a hub-and-spoke network topology that used
either a private MPLS WAN or a VPN WAN over public internet. Private WAN networks excel at providing access to private
applications. However, in most cases, using a private WAN network to provide centralized internet access does not provide
the best user experience.
Properly overcoming these challenges requires a different approach. For optimal performance in accessing both private
applications and the internet, a decentralized model is necessary. This involves providing localized service access and placing
security enforcement points near both mobile users and branch offices, ensuring consistent security policies for all users.
This strategy is also pertinent for hybrid workers who split their time between mobile work and on-site. The solution must be
easy to manage and scale, provide cost-effective and pervasive coverage, and deliver the best performance for applications,
regardless of their location.
• Cloud-native, cloud-based delivery—Uses many points of presence to reduce latency, with support of in-country or
in-region resources and regulatory requirements.
• Converged WAN edge and network security—Provides true integration of services, not service chains, with
combined services and visibility for all locations, mobile users, and the cloud.
• Broad network-edge support—Takes you beyond box-based access support with agent-based capability managed
as a cloud service.
• Identity and network location—Provides policy enforcement beyond IP address by using identity-based policy
enforcement with real-time conditions like device-type, posture, and location.
Organizations moving to a SASE-based deployment should look for integration across the following essential components of
the solution:
• Cloud secure web gateway (SWG)—Provides URL filtering, application control, and threat detection and prevention
for users' web sessions.
• Firewall as a Service (FWaaS)—Provides a cloud-native NGFW that allows advanced Layer 7 inspection, access
control, threat detection and prevention, and other security services.
• Cloud access security broker (CASB)—Monitors the use of sanctioned and unsanctioned SaaS applications,
provides malware and threat detection in SaaS applications, and provides sensitive-data visibility and control in order
to detect improperly-stored data in SaaS file repositories.
• Software-defined WAN (SD-WAN)—Provides an overlay network decoupled from the underlying hardware in order
to provide flexible, secure routes between sites.
Several security and network vendors deliver one or more components of a SASE solution. The challenge organizations
face is integrating those vendors and components. The key to an optimal SASE-based network and security deployment is
tight feature-and-service integration that improves operational efficiency. Such integration creates a solution that removes
performance-degrading bottlenecks and improves operational efficiency by reducing the number of vendors, systems, and
products that your IT staff must manage.
WAN provides secure WAN transport between offices, on-premises data centers, cloud-based data centers, and SaaS
applications. Prisma SD-WAN has fully orchestrated connectivity to Prisma Access in order to provide a secure transport to
SaaS applications.
Prisma SASE 3.0 enhances SASE by providing security, visibility, and control from any device to any application. With new
innovations such as Prisma Access Browser, AI-powered data security, and App Acceleration, Prisma SASE 3.0 offers a fully
integrated SASE solution with unified management and uncompromised application performance for both managed and
unmanaged devices.
• Least-privileged access—Granting users the minimum access they require in order to perform their tasks. You
achieve this by identifying applications at Layer 7, enabling precise access control at the app and sub-app levels,
independent of network constructs like IP and port numbers.
• Continuous trust verification—After access to an app is granted, trust is continually assessed based on changes in
device posture, user behavior, and app behavior.
• Continuous security inspection—Providing deep and ongoing inspection of all traffic, even for allowed connections,
to prevent all threats including zero-day threats.
• Protection of all data—Providing consistent control of data across all apps used in the enterprise, including private
apps and SaaS, with a single data-loss prevention (DLP) policy.
• Security for all apps—Safeguarding all applications used across the enterprise, including modern cloud-native apps,
legacy private apps and SaaS apps. This includes apps that use dynamic ports and apps that leverage server-initiated
connections.
To implement least-privileged access, you can use App-ID™, User-ID™, and Device-ID, all of which deliver rich context
and a granular approach to allowing access to applications. By enforcing least-privileged access, the organization can limit
authorization to individual applications and to specific user communities. Through continuous trust verification and continuous
inspection, the organization detects any change in security posture, user behavior, or application behavior. By combining
these techniques, your security infrastructure can make better security decisions and quickly react to changes.
Continuous monitoring includes a broad set of capabilities such as WildFire®, advanced URL security, advanced threat
prevention, SaaS security, and other cloud-delivered security services. When combined, these perform deep inspection for all
connections and can protect against both known and unknown threats, by leveraging AI and ML-powered threat-prevention
technologies.
Prisma Access
Powered by Palo Alto Networks operating system, PAN-OS®, Prisma Access is a cloud service that provides secure access
to internet and business applications hosted in SaaS, as well as access to corporate HQ or data center, or a public cloud.
Both managed and unmanaged devices can reach Prisma Access through multiple access methods. The FWaaS capabilities
of Prisma Access inspect all traffic, not just HTTP and HTTPS, in order to identify applications, threats, and content. As an
example, DNS security makes sure that malicious payloads aren't hidden within DNS transactions, and if you do attempt
to download an infected document that has not been previously identified as malicious, unknown files can be sent to
WildFire, the largest sandbox utility in the industry, for threat and malware scanning. Prisma Access offers the industry's most
comprehensive SASE solution, enabling your organization to connect and secure any user, device, or application.
Because Prisma Access is a cloud service, it avoids the challenges of sizing firewalls and compute resource allocation and
minimizing coverage gaps or inconsistencies associated with your distributed organization. The elasticity of the cloud scales
as demand shifts and traffic patterns change. The cloud service operationalizes security deployment to remote networks and
mobile users by leveraging a cloud-based security infrastructure delivered by Palo Alto Networks.
There are two options available as part of Prisma Access: Prisma Access for users and Prisma Access for networks.
Prisma Access for users provides security services, including App-ID, URL filtering, DLP, and threat prevention for mobile
users, as a service in the cloud, providing an alternative to the traditional on-premises deployment of GlobalProtect.
This cloud-delivered approach is well-suited for both new deployments across one or more global regions or as a hybrid
deployment with security provided by a combination of Prisma Access and on-premises firewalls.
Prisma Access provides two mobile-user access connection methods for users with IT-managed endpoints:
• GlobalProtect—Extends Prisma Access's visibility and control of all network traffic, applications, ports, and protocols
to the user for secure access to internet or data center-based applications
• Explicit proxy—Allows SWG access to internet-based SaaS applications using HTTP and HTTPS protocols
For unmanaged devices, Prisma Access Clientless VPN allows endpoints to access secured on-premises applications.
Prisma Access uniquely provides an integrated security solution for web and non-web traffic that aligns with the SASE
industry architecture.
Prisma Access for networks provides security services, such as App-ID, URL filtering, and threat prevention, for your remote
networks, safely enabling commonly used applications and web access. You connect remote sites to Prisma Access via
Prisma SD-WAN or an industry-standard IPSec VPN-capable device. This deployment model is suitable for remote sites with
one or more WAN links (or public WAN transports) and provides direct internet access through Prisma Access without the
requirement to backhaul traffic to the central site.
Prisma SD-WAN
To enable simplified deployment across your organization, Prisma SD-WAN provides next-generation, software-defined wide-
area networking combined with cloud-orchestration. The Prisma SD-WAN cloud-controller automatically provisions a secure,
encrypted transport between your sites, seamlessly connecting your remote offices to on-premises data centers, remote
sites, the public cloud, and to SaaS applications.
At the core of the system, Prisma SD-WAN uses built-in Layer 7 intelligence, providing application-aware networking, traffic
steering, and security policies in addition to the more traditional measures of jitter, latency, and packet loss. Prisma SD-
WAN also allows for complete visibility into the application health across all locations and collects granular application-driven
analytics, which you can use for monitoring and troubleshooting.
You enable the SD-WAN service by using Prisma SD-WAN Instant-On Network (ION) devices. Available as both hardware
devices or virtual software devices, the ION devices allow you to enforce policies based on business intent, enable dynamic
path selection, and provide visibility into performance and availability for applications and networks. You manage the ION
hardware and software devices from the multi-tenant cloud management portal, thereby eliminating the need to individually
configure devices at each location. The ION devices are pre-configured to authenticate to the portal and support zero-touch
provisioning and deployment.
After you deploy the Prisma SD-WAN ION devices at your sites, the devices automatically establish a VPN to the data centers
over every internet circuit. Additionally, the ION devices establish VPNs over private WAN circuits that share a common
service provider. You can then define application policies for performance, security, and compliance that are aligned with your
organization’s business intent. ION devices automatically choose the best WAN path for your applications. ION devices use
the business policy and real-time analysis of the application performance metrics and WAN links in order to determine the
appropriate path.
When Prisma SD-WAN remote sites require secure internet access, you attain the most consistent and comprehensive
security for your organization by using Prisma Access. Using the Prisma SD-WAN easy onboarding process, Prisma SD-WAN
automates the remote site connectivity to Prisma Access for cloud-based protection. Prisma SD-WAN uses application-
aware policies to route traffic that is not destined for an internal site to Prisma Access, which then inspects the traffic,
performs threat detection, and enforces security policies.
Using both API-based and inline services, the Palo Alto Networks SaaS Security portfolio of services provides visibility and
control of your SaaS applications. Without reconfiguring your network, adding probes, and without any configuration on
endpoints, SaaS Security provides complete CASB services, with visibility across all users accessing a SaaS application.
A key part of Prisma Access and SaaS Security is Strata Logging Service (formerly known as Cortex Data Lake). Prisma
Access logs traffic-flow information on every application connection to Strata Logging Service (SLS), and when enabled on
your account, the SaaS Security application control engine is scanning the traffic logs for SaaS application access in your
Prisma Access tenant. The Prisma SaaS database contains over 15,000 SaaS application IDs. When SaaS Security sees
new or unknown SaaS applications, it uses machine learning to classify them. The benefit to every SaaS Security customer
is that as new SaaS applications are discovered and classified, they are added to the shared App-ID database. This gives
you enhanced visibility of the applications, the risk ratings of the applications, traffic volumes, and the identities of the users or
groups accessing the applications.
Prisma Access uses PAN-OS to deliver a robust application identification (App-ID) engine, which is shared across all PAN-OS-
based next-generation firewall (NGFW) platforms. App-IDs identify the applications flowing across Prisma Access—regardless
of port or protocol—even if the traffic is encrypted or tunneled. Because Prisma Access is inline with the user traffic, you can
configure security policies to control access to SaaS applications by using App-IDs, URL matches, and IP address ranges in
order to identify the application, as well as User-ID to control which users can access on-premises and SaaS applications.
SaaS Security Inline visibility is delivered as a SaaS service, so no footprint is required in the data center. The single SaaS
Security management application monitors and controls both in-line and API-based SaaS visibility and control. Because SaaS
Security provides visibility into stored data and historical activities, you can explore and investigate them on-demand. The
SaaS Security API (formerly known as Prisma SaaS) is licensed separately from SaaS Security Inline for Prisma Access.
Prisma Access and SaaS Security both use the DLP cloud service to discover, and conditionally stop, data from being leaked
to unsanctioned web applications, or uploaded to sanctioned corporate apps through an advanced inline analysis. Prisma
Access DLP and SaaS Security add-on services are part of a cloud-delivered enterprise solution that provides a common
approach to preventing data loss with unified data policies and faster remediation.
RBI works by creating a no-code execution isolation channel between users and the browser, which mitigates zero-day
web threats by never allowing malicious files to execute on a user’s machine. Unlike other isolation solutions, the Palo Alto
Networks RBI solution uses next-generation isolation technologies to deliver near-native experiences for users accessing
websites—without compromising on security.
App Acceleration
App Acceleration improves the user experience by mitigating the effects of poor network conditions for TCP-
based applications. App Acceleration can provide an up to five times better performance for TCP-based applications as
compared to direct-to-internet traffic without the need for changes to the end-user client or application.
To do this, App Acceleration forecasts the user's next actions and computes the required dynamic content. This foresight
allows the system to preemptively request the content needed for that user session, initiating the loading and security
processing ahead of time. When the user makes the request, the content is already prepared. App Acceleration also
performs aggressive tuning of the TCP window to boost initial throughput for all connections. It then creates a custom packet
flow profile for every user session and updates it in real time. To mitigate the effects of conditions like packet loss, packet
corruption and jitter. App Acceleration takes into account network, device, and app context when it creates the profile,
enabling it to send the maximum amount of data to the user at all times,.
• ADEM for mobile users—ADEM is integrated into the GlobalProtect app, and you do not need to deploy any
additional appliances or software. When your GlobalProtect app authenticates to the Prisma Access portal, the ADEM
service is enabled on the app according to the policies you have configured in Prisma Access.
• ADEM for remote networks—ADEM is integrated into the operating system of the remote site Prisma SD-WAN ION
device. ADEM for Remote Networks is available when a Prisma SD-WAN remote site is connected to Prisma Access
for internet access security.
ADEM continuously monitors each segment from the endpoint to the application and identifies baseline metrics for each
application. In addition, ADEM provides visibility into any deviations or events that degrade the user experience across each
segment between the end user and the application, whether it’s the endpoint, Wi-Fi, LAN, router, ISP, Prisma Access, or the
application (SaaS, IaaS, or data center). ADEM continuously monitors every segment in the service delivery path and provides
insights that help you quickly isolate the segment that is causing digital experience problems and simplify remediation,
including providing the user with recommendations to allow for self-remediation.
To determine baseline performance levels and alert you to changes in performance that might lead to a degraded user
experience, ADEM uses a variety of monitoring techniques:
• User traffic visibility—ADEM continuously provides visibility into real traffic usage between your users and the
applications they are accessing, including traffic to SaaS applications, Infrastructure as a Service applications, or other
internet-based applications, as well as traffic to applications in your own data center.
• Synthetic monitoring—ADEM uses synthetic tests to collect network performance metrics (availability, latency,
jitter, and loss) for each segment (LAN, internet, Prisma Access, and application), as well as end-to-end application
performance metrics (DNS resolution time, HTTP connect, SSL connect, HTTP latency, time to first byte, and time to
last byte).
• Endpoint monitoring—Available on ADEM for Mobile Users, the GlobalProtect app gathers health telemetry about
the device and its Wi-Fi connectivity in order to help determine whether the device or the Wi-Fi is the cause of any
performance issues.
Additionally, AI-Powered ADEM runs several in-built data models built by Palo Alto Networks, enabling it to find the best-fit
model for your remote and data center sites. Using this data model, AI-Powered ADEM forecasts bandwidth requirements for
your remote sites. All details about AI-Powered ADEM capabilities apply to both mobile users and remote networks.
AI-Powered ADEM uses ADEM as a foundation, and it enriches the data collected by ADEM by using AI/ ML models built by
Palo Alto Networks. You don’t need to configure anything for this capability, as it is enabled by default once it is activated. You
only need to configure ADEM and activate the AIOps license for this capability to function.
• Proactively monitor your application health—AI-Powered ADEM performs synthetic tests to your mobile users and
remote sites to configure SaaS applications and determines health of users, applications, and remote sites.
• Detect anomalies in your network—AI-Powered ADEM collects baseline data and detects anomalies in your
network.
• Manage capacity forecasting in your network—AI-Powered ADEM generates reports that assist you in forecasting
your remote network capacity.
• Troubleshoot complex network problems—AI-Powered ADEM can make complex queries using Access Analyzer
to assist you with identifying complex problems. For instance, it can create a query for a particular user accessing a
specific application and give a verdict.
Traffic Replication
On-premises network recorders have been a powerful tool when organizations perform forensic and breach analysis. It
is common in on-premises topologies to implement a parallel infrastructure of TAP ports, SPAN ports, or packet brokers
that would deliver a copy of the traffic to be used for such out-of-band analysis. Prisma Access Traffic Replication brings
this functionality to SASE. The Traffic Replication add-on is licensed on a per-user basis for both mobile users and remote
networks.
Traffic Replication uses the Prisma Access cloud to replicate traffic from Prisma Access and forward them to Google Cloud
storage buckets that you or third-party nodes can access for analysis. To reduce risk and keep your organization safe, Traffic
Replication provides access to packet captures of users' real-world traffic, thereby enabling the detection and remediation of
threats that could span multiple sessions or the identification and response to anomalous behaviors.
Design Details
This section discusses the Prisma Access and Prisma SD-WAN components that you use to secure internet traffic for mobile
users, remote-site users, and hybrid workers. Prisma Access and Prisma SD-WAN support additional capabilities that secure
access to private applications. This section introduces some of these additional capabilities for completeness but does not
discuss them in-depth.
Beyond securing internet access, Prisma Access can also provide secure, enterprise-wide transport between remote offices,
mobile users, and private or public data center-based applications. The Prisma Access backbone interconnects a global
network of more than 100 secure access locations and uses this transport to carry traffic between your mobile users and
enterprise locations. Prisma Access licensing options allow the organization to choose how much enterprise traffic they want
to transport over the Prisma Access backbone. The Prisma Access backbone uses VPN technology to keep your enterprise
traffic secure and separated from other customers.
Prisma Access provides security services, such as App-ID and threat prevention, to your mobile and remote-site users. Data
Centers connect to Prisma Access by using an IPSec VPN tunnel over the internet from an on-premises device, such as a
firewall, VPN router, or SD-WAN appliance. Prisma Access is a service that Palo Alto Networks deploys and manages.
Management Options
You have the following two options for provisioning and managing Prisma Access:
Because you cannot switch between them after you have activated your Prisma Access license, you must decide which
management interface you plan to use prior to provisioning your Prisma Access network. The two management interfaces
have different programming flows and different feature support matrices. Review the Palo Alto Networks compatibility matrix
to compare the two management interfaces. Regardless of which management interface you use, Prisma Access uses SLS
for log storage and Strata Cloud Manager for comprehensive monitoring, alerting and visibility.
Cloud Managed
You use Cloud Manager for cloud-based Prisma Access management. Cloud Manager uses task-driven workflows in order
to onboard mobile users and remote networks. Because the Cloud Manager provides a single user interface for your entire
SASE environment, you can easily navigate between Prisma Access, Prisma SD-WAN, and your cloud-delivered security
services. Inside Cloud Manager, you have direct access to several Prisma Access dashboards and log files from SLS.
The intuitive workflows make it easy to set up and test your environment and take little time to get operational. Cloud
Manager includes predefined options and workflows for the following:
• Internet access protection—Integrated security rules prevent access to and from known-malicious and high-risk
websites.
• Threat prevention—Tools such as anti-virus, WildFire, and anti-spyware are enabled by default in security rules and
configured with best practice-based settings.
• User-ID distribution—Prisma Access is configured to distribute User-ID information across the backbone and to
service connections for optional export to on-premises NGFWs.
• Directory services group sync—Easy, on-premises LDAP or cloud-based Microsoft Entra ID group maps via Cloud
Identity Engine integration allow for optimized security rules.
• IPSec setup—Default configurations match the most common IPSec devices that you would connect to your
network.
Panorama Managed
You manage Prisma Access through the Cloud Services plugin on Panorama. Panorama does not interact with Prisma
Access security-processing nodes in the same way it does with the next-generation and VM-Series firewalls in your
organization. The Cloud Services plugin provides an abstraction layer between Prisma Access and Panorama, decoupling
Panorama from the specifics and versions of the security-processing nodes within Prisma Access. When Palo Alto Networks
provides an update for Prisma Access, you might need to update the Cloud Services plugin to get the latest Prisma Access
features; however, Panorama itself typically doesn’t require a software update.
You configure network and security policies for Prisma Access by using the Cloud Services plugin for Panorama and Prisma
Access-specific templates and device groups. This method of configuration enables you to provide consistent security policy
enforcement that meets your organization's usage guidelines.
If you plan to use an existing Panorama platform in order to manage your Prisma Access
instance, Palo Alto Networks recommends that you engage Palo Alto Networks professional
services. Before you add Prisma Access management, they can help you prepare your
Panorama platform and ensure that you follow best practices for Panorama stability and that
system sizing is correct. Alternatively, you can dedicate a new Panorama platform to this
task.
Within Cloud Manager, Prisma Access dashboards provide visibility into the health and performance of your infrastructure.
Dashboards are automatically available for every Prisma Access instance that your organization owns. Even if using
Panorama to manage Prisma Access, you can still access the dashboards on Cloud Manager for comprehensive monitoring,
alerting, and visibility.
• Health and performance monitoring for Prisma Access instances, whether you configure and manage your instance
with Cloud Manager or with Panorama and the Cloud Services plugin.
• A summary overview screen of the health and performance of your entire Prisma Access environment.
• Customizable alerts notifications, so that you can pinpoint issues or events that require your attention.
• Multiple dashboards for focused views of your different deployments, the corresponding alerts, and the health status
of the infrastructure.
• Flexible user interfaces that allow you to toggle and adjust views and statistics to evaluate trends over different
timeframes.
• The ability to drill down for details on specific users, sites, connections, or Prisma Access infrastructure components.
• Important Prisma Access system messaging, for example, upcoming system updates.
Components
When a mobile or remote-site user connects to a Prisma Access gateway, internet-bound application traffic automatically
exits the Prisma Access network at the closest internet access point. You must decide how to provide access to internal and
on-premises resources for your mobile users. In Prisma Access, you provide this access by using service connections that
pair to an IPSec-capable device, such as a router or a Palo Alto Networks NGFW at your data center or headquarters. You
can configure service connections to as many as one hundred sites depending on the licensing you choose.
Prisma Access uses SLS to store logs. In addition to storing logs for Prisma Access, SLS can provide cloud-based,
centralized log storage and aggregation to the Cortex XDR® Agent management service and on-premises and virtual (private
cloud and public cloud) firewalls. SLS is secure, resilient, and fault-tolerant, and because Palo Alto Networks delivers it as a
cloud service, you can easily add additional capacity and integrate it to the hub.
SLS not only provides public-cloud scalability across multiple secure locations, it enables AI-based innovations to normalize,
analyze, and stitch together your enterprise's data in order to detect hard-to-find security issues. SLS can use cloud-scale
compute resources to run advanced AI and machine learning on data from multiple Prisma Access flows and many other
inputs. Cortex is a scalable ecosystem of security applications that can apply advanced analytics in concert with Palo Alto
Networks enforcement points in order to prevent the most advanced attacks. Palo Alto Networks analytics applications such
as Cortex XDR and AutoFocus®, as well as third-party analytics applications that you choose, use SLS as the primary data
repository for all Palo Alto Networks offerings.
Mobile-User Connections
Prisma Access provides multiple methods for organizations to connect users to their Prisma Access instance. There are three
ways to connect mobile users:
• GlobalProtect app—The mobile user has the GlobalProtect application on their endpoint and connects to the
GlobalProtect portal to access the Prisma Access instance for internal, SaaS, and internet applications.
• Explicit-proxy connection method—The mobile users' web browser is configured to connect to the organizations'
Prisma Access explicit-proxy instance for HTTP or HTTPS access to internet-based SaaS applications.
• Clientless VPN—An organization with unmanaged users who require secured access to selected applications can
use Prisma Access to provide secured and controlled access to internal applications.
This guide focuses on the GlobalProtect connection method for managed users, which provides access to internal and
internet-based applications.
GlobalProtect Portal
Prisma Access provides the GlobalProtect portal functionality through resilient security-processing nodes deployed globally.
The service uses global DNS load-balancing to direct clients to the nearest portal. GlobalProtect portal is a secure web
service that provides for the distribution and management of GlobalProtect apps. The portal provides an authenticated
SSL web service for the download of the GlobalProtect app to end users for self-service deployment. Once connected, the
GlobalProtect app receives configuration information from the portal, including a list of Prisma Access locations, external
and internal GlobalProtect gateways, required certificates, connection methods, and app behavior. In addition to app
configuration, the portal can also distribute the GlobalProtect app to both macOS and Windows endpoints.
Prisma Access uses gateways to connect mobile users to an organization's Prisma Access instance. GlobalProtect gateways
provide security enforcement for traffic from GlobalProtect apps. The endpoint app establishes a secure tunnel, using IPSec
or SSL, to the gateway.
• Internal gateway—An internal gateway is a next-generation or VM-Series firewall reachable from within the
organization's network. This gateway can be a dedicated device or collocated on a device serving other security
functions within the organization. When you use an internal gateway in conjunction with User-ID and/or host
information profile (HIP) checks, you can use the gateway to provide a secure, accurate method of identifying user-
to-IP mappings and the associated device state. You can share this information with other next-generation and VM-
Series firewalls in the organization so that they can enforce policy based on user and group information. You typically
configure internal gateways in non-tunnel mode, meaning they don’t terminate traffic but instead authenticate the user
and capture the user-to-IP mapping and HIP information.
• External gateway—An external gateway is reachable from outside of the organization's network and provides
security enforcement for mobile users. External gateways provide security for traffic from mobile users to the internet,
as well as remote access from mobile users to the organization's internal services and applications. The GlobalProtect
app tunnels traffic to the external gateways across IPSec or SSL.
Prisma Access provides the GlobalProtect external gateway functionality and distributes the functionality throughout the
world. You can choose the locations in which to enable the functionality, allowing you to distribute security close to your
mobile users. The configuration complexity of Prisma Access doesn't increase as you increase the number of locations
because you manage all Prisma Access locations through a single policy.
In some instances, such as when you have pre-existing GlobalProtect gateways at your data center, you might want mobile
users to connect to external gateways in addition to Prisma Access. You can configure the app with these external gateways
in Prisma Access, but you must deploy and manage additional gateways separately.
Although you cannot use Prisma Access as an internal gateway, you can configure the app to use internal host detection and
connect to internal gateways deployed outside Prisma Access. This way, when mobile users are on-site, they can bypass the
connection to Prisma Access while still providing the organization with their user-to-IP mappings.
GlobalProtect App
The GlobalProtect app runs on Windows, macOS, Linux, iOS, Android, and Chrome. The GlobalProtect app is responsible
for connecting to Prisma Access to obtain configuration information and then choosing a Prisma Access location to which it
authenticates and tunnels traffic. When users connect, the GlobalProtect app supplies User-IDs and device information .
Also, if required, the GlobalProtect app inventories the endpoint configuration and builds an HIP to share with Prisma Access
or an internal gateway. You can use this information to build HIP-based policies based on several attributes, including the
following:
Licensing
The Prisma Access licensing model allows you to use the capabilities of Prisma Access in a way that delivers the fastest
return on investment. Prisma Access license editions address organizational issues such as your applications are migrating to
the cloud, your users are now working from anywhere, or if you are looking to gain operational efficiencies.
License Editions
Prisma Access now offers three editions of licenses to choose from: Business, Business Premium, and Enterprise. This
reference architecture is based on using the full suite of features provided by the Enterprise license edition. Both the cloud-
managed and Panorama-managed options support these licensing editions.
Internet security √ √ √
Threat prevention — √ √
URL filtering √ √ √
DNS security √ √ √
WildFire — √ √
Number of service connections included 0 (add-on 0 (add-on only) 2 with Local Edition
only)
5 with Worldwide Edition
Table 1 (continued)
1For mobile users, ADEM is delivered with GlobalProtect network security for endpoints.
2Every edition of Prisma Access provides up to 250 GB of data transfer per year, per unit purchased, averaged across the entire environment.
License Units
Prisma Access licenses mobile-user and remote-network capacity in units. A unit is either a mobile user in Prisma Access for
users or 1 Mbps bandwidth in Prisma Access for Networks. You can have a Prisma Access network of all mobile users, all
remote-network locations, or a combination of each. When you order a local or worldwide deployment edition, you license a
minimum number of units upon which you can build.
The mobile-user count requires 200 units in order to enable either GlobalProtect or explicit proxy access for local coverage;
enabling both simultaneously requires a minimum of 400 total licenses, 200 units each. GlobalProtect and explicit proxy share
the mobile-user unit pool.
Location Licensing
Prisma Access has more than 100 locations available to accommodate worldwide deployments and provide a localized
experience for the mobile user and the remote-network users. You select a Local or Worldwide edition based on your
organization's geographical spread. With a Local edition, you can choose any 5 locations worldwide. Some Prisma Access
locations share a common compute location. To increase resiliency and achieve optimal performance, you should choose
Prisma Access locations that use different compute locations. For more information, see the topic Prisma Access Locations
in the Prisma Access Administrator's Guide.
Local Worldwide
When you onboard Prisma Access mobile-user gateway locations, you select the region or regions that you wish to activate,
and then you select the locations within a region where you wish to have local gateways for mobile users to connect to
Prisma Access. When a mobile user connects to a location, their internet-bound application traffic has the source IP address
translated to an IP address for that local gateway.
The Prisma Access infrastructure is comprised of security-processing nodes, which are specialized virtual machines deployed
globally in the locations you specify. Prisma Access automatically provisions and configures the nodes with IP addressing,
routing, certificates, and DNS information.
There are types of nodes, each serving a specific role in Prisma Access:
• Mobile-user security-processing node—The MU-SPN functions as a GlobalProtect gateway and is the attachment
point for mobile users using the GlobalProtect app.
• Portal security-processing node—The PT-SPN functions as the GlobalProtect portal, providing the operational
configuration for GlobalProtect mobile users and serving as the attachment point for GlobalProtect clientless VPN
users.
• Corporate-access node—The CAN functions as the attachment point for IPSec-based service connections to the
organization's data center or other privately hosted applications and services.
• Remote network security-processing node—The RN-SPN functions as the attachment point for IPSec-based
connections to remote site or branch networks.
• Explicit proxy security-processing node—The EP-SPN functions as the attachment point for HTTP secure web
gateway connections.
Customers onboard locations in order to meet the customers' requirements for service type, resiliency, latency, and capacity.
When Prisma Access provisions the infrastructure, security processing nodes are automatically deployed, and standby nodes
are provisioned for high-availability node types. The RN-SPN and CAN instances use high-availability primary/standby node
deployments, whereas resiliency for the other node types is based on the GlobalProtect application's ability to select alternate
nodes.
Prisma Access for users who use the GlobalProtect app for connectivity connect as follows:
• To a MU-SPN at the mobile-user gateway closest to the user, and when there is a failure, they can reconnect to an
alternate MU-SPN.
• To the PT-SPN closest to the user, and when there is a primary failure, they can reconnect to an alternate PT-SPN.
Prisma Access for users also monitors the MU-SPNs so that high loads cause the automatic deployment of additional nodes
to that location and adds the additional nodes to the list in Prisma Access.
Service connections are IPSec tunnels between the Prisma Access infrastructure and central sites that contain resources to
which your remote-site users need access. These service connections are typically high-speed connections to a central site,
such as headquarters or a private data center, or to virtual networks that support workloads in the public cloud. Although
there are some advanced functions that might require service connections, for securing access to the internet, you do not
need service connections. For a more complete discussion of service connections, refer to SASE for Securing Private
Applications: Design Guide.
Remote-network connections are IPSec tunnels between an RN-SPN located at a Prisma Access compute location and the
IPSec-compliant remote-site device such as Prisma SD-WAN ION device. When onboarding remote sites, Prisma Access
deploys an RN-SPN at a compute location that has a configured remote-network connection and a minimum allocation of 50
Mbps bandwidth.
Prisma Access dynamically allocates the bandwidth based on load or demand per location by using an aggregate bandwidth
model. The remote-network connections on the RN-SPN are not rate-limited per connection. They are part of an aggregate
shared pool of bandwidth assigned to the compute location. For example, if you have four sites collectively assigned to a
compute location allocated 200 Mbps of bandwidth, if one or more sites are not using as much bandwidth as the other
sites, Prisma Access provides more bandwidth for the locations that are more in demand, giving you a more efficient use of
allocated bandwidth. In addition, if one of the sites goes down, Prisma Access reallocates the bandwidth between the other
sites that are still operational in that compute location. Bandwidth allocated to a compute location counts for traffic in both
directions; for example, 50 Mbps allocated to a location supports 50 Mbps from the remote site to Prisma Access and 50
Mbps from Prisma Access to the remote site.
Each RN-SPN can provide a maximum of 1 Gbps of egress bandwidth to remote networks (500 Mbps for Prisma Access
versions prior to 3.2) and is designed to perform at this rate with SSL decryption and threat prevention enabled. Depending
on the amount of bandwidth allocated to a compute location, Prisma Access deploys a single or multiple RN-SPNs in order
to adequately support the assigned bandwidth. As an example, with Prisma Access version 3.2, if you assign 1300 Mbps
to a remote-network's compute location, Prisma Access deploys two RN-SPNs in order to support the remote networks
assigned to that compute location (1 Gbps + 300 Mbps).
The RN-SPNs enforce security policies for all traffic initiated from the remote site, and there is a maximum of 250 sites (with
a single tunnel per-site) or a maximum of 250 total IPSec tunnels (if using ECMP with multiple IPSec tunnels per-site) that
you can assign to an RN-SPN. NAT is enabled by default for all internet-bound user traffic without the need for explicit NAT
policy rules. If you have both service connections and remote-network connections in the same location, they do not share a
common processing node; instead, Prisma Access deploys two separate nodes.
The IPSec tunnels for Prisma Access service connections and remote-site connections should use the strongest encryption
and authentication in common between Prisma Access and the on-premises device.
The RN-SPNs can also use the service connections when they need access to central-site resources, such as when an on-
premises device redistributes User-ID information to Prisma Access.
Infrastructure IP Addressing
To provision the Prisma Access infrastructure, you must supply an IP address subnet. Prisma Access assigns an IP address
from this range to every node, regardless of whether it is serving as a security or corporate-access node. The nodes use
these IP addresses for internal communication between nodes, as well as communication from the nodes to your internal
on-premises services. Prisma Access now supports IPv6 for mobile-user access to internal or on-premises applications.
Discussion of this capability is currently beyond the scope of this guide, and this guide uses IPv4 addressing.
Prisma Access typically assigns the addresses used in the infrastructure as a /32-bit host. The supplied IP address
range must be at least a /24-bit subnet, and we recommend a /23-bit subnet for medium to large networks to allow the
infrastructure to grow. Because Prisma Access uses the infrastructure IP addresses to communicate with your on-premises
services, such as LDAP, this subnet cannot overlap with IP addresses in use in your organization. Palo Alto Networks
recommends that you use an RFC 1918-compliant subnet. Although Prisma Access supports the use of non-RFC 1918-
compliant (public) IP addresses, this practice is not recommended, because of possible conflicts with internet public IP
address space. The infrastructure subnet cannot overlap with the IP address pools that you assign for your mobile-users
deployment.
Do not specify IP subnets for infrastructure or mobile network IP ranges that overlap with the
following IP addresses and subnets:
• [Link] and [Link]
• [Link]/10
• [Link]/24
• [Link]/24
Prisma Access reserves these IP addresses for internal use.
Prisma Access assigns each node any public IP addresses required for internet connections or tunnel establishment.
To define what IP addresses can access their partner's SaaS application, many organizations use a login IP allow-list. The
login IP allow-list acts as an additional layer of security in order to prevent an unauthorized IP address from accessing the
SaaS application. The SaaS application enforces the allow-list. However, the customer organization is typically responsible for
maintaining the IP addresses in the list.
When a mobile user connects to a Prisma Access GlobalProtect gateway SPN for protected access to an internet-based
SaaS application, the mobile user’s device source IP address is translated to the egress IP address of the MU-SPN. For a
SaaS application using the IP allow-list, the egress IP address of the MU-SPN must be included in the allow-list so that any
mobile user connected to the same MU-SPN would also be allowed access to the application.
Prisma Access assigns public IP addresses to a given tenant during onboarding of a new tenant, autoscale of gateway
nodes, or software upgrades. If you use a login IP allow-list on your SaaS applications, and new IP addresses are assigned
to GlobalProtect mobile-user gateway SPNs during an autoscale or software upgrade, the newly assigned IP addresses must
be added to the IP allow-list. To prevent SaaS application access disruption, the current list of MU-SPN IP addresses and the
pool reserved for autoscale or software upgrades must be added to the IP allow-list.
Prior releases of Prisma Access required a customer who was using IP allow-list to contact Palo Alto Networks and notify
them that no allocated IP addresses could be used as external IPs for network access until they had been confirmed as
IP allow-listed. You used an API script to download a comprehensive list of all Prisma Access GlobalProtect mobile-user
gateway egress IP addresses that are assigned to your tenant. After you have the list, you can update your application’s IP
allow-list.
Beginning with Prisma Access release 3.0, you can indicate that you use Prisma Access public IP addresses for IP allow-
list applications, via the Cloud Manager or Panorama UI. The management interface allows you to see which IP addresses
are assigned to GlobalProtect mobile-user gateways, as well as the IP addresses that are reserved for your use but still
unassigned. The reserved-but-unassigned IP addresses can be used for autoscaling events and during Prisma Access
infrastructure upgrade workflows. In the management app, you indicate which IP addresses have been added to your IP
allow-list and therefore are ready to be used for MU-SPNs. IP allow-list is disabled by default. For the mobile-user gateway
to be provisioned, a minimum of two IP addresses are required to be allow-listed for a gateway location. The management
application warns you if there are not enough IP addresses allow-listed in order to allow autoscale to happen for a mobile-
user gateway location.
All security-processing nodes include a public interface that supports VPN tunnel termination from the internet and provides
internet access for users and devices that connect to Prisma Access through a VPN tunnel to the security-processing node.
Prisma Access implements the security policy with two security zones:
• Trusted—Internal interfaces
• Untrusted—External interfaces
Security policies in Cloud Manager use only the trusted or untrusted security zones. If you use Panorama to manage NGFWs
and Prisma Access, you can configure your security policies with more than two zones. However, when you configure Prisma
Access, you must map the zones used in your policy to either the trusted or untrusted zone. Typically, you consider remote-
site networks to be trusted, and you consider the internet to be untrusted.
With Panorama-managed Prisma Access tenants, all zones are set to untrusted by default.
Application Deployment
There are a variety of ways you can install the GlobalProtect app on the endpoint. The simplest way to obtain the app on
Windows and macOS endpoints is to log into the Prisma Access portal and download the app directly. For iOS and Android
endpoints, you can download the app through their app stores. You can also deploy the app through systems management
software, such as Microsoft System Center Configuration Manager, and mobile-device management such as AirWatch.
When using systems management software, you can set parameters for the initial configuration, such as the hostname of the
portal, on Windows and macOS apps during the installation. After connecting to Prisma Access, the pushed configuration
overrides the initial configuration. Regardless of the installation method, Prisma Access can also transparently upgrade
Windows and macOS apps.
Obtaining Configuration
The primary function of the Prisma Access portal is to provide configuration information to the GlobalProtect app on the
endpoint. The app configuration that Prisma Access provides includes the following:
• Listing Prisma Access locations and external and internal GlobalProtect gateways
Before Prisma Access can provide a configuration to the app, the app must authenticate. The Prisma Access authentication
profile determines the authentication method that the app must use.
• RADIUS servers
• LDAP servers
• Kerberos servers
Prisma Access can provide differentiated authentication profiles and methods based on the endpoint operating system, which
Prisma Access determines through the information pushed from the GlobalProtect app. For example, Windows endpoints
can use an LDAP authentication method, while Android endpoints use SAML. However, Prisma Access cannot distinguish
between managed and unmanaged endpoints of the same operating system when determining an authentication method.
When authentication is complete, Prisma Access provides the app with its configuration. Prisma Access can have multiple
app configurations defined. Prisma Access assigns the configurations to the endpoints based on their operating system
or user/user group membership. When multiple configurations apply to an endpoint, Prisma Access applies the first
configuration that matches the endpoint in a top-down approach.
The app caches the configuration in case a situation arises where Prisma Access is unreachable when it initiates a
connection. The app does not use the cached configuration when Prisma Access is reachable but authentication is failing.
Authentication
Certificates
With the optional client certificate authentication, the user presents a client certificate along with a connection request to
Prisma Access. Prisma Access can use either a shared or unique client certificate to validate that the user or endpoint
belongs to your organization.
RADIUS
RADIUS is a client/server protocol and software that enables remote access servers to communicate with a central server to
authenticate dial-in users and authorize their access to the requested system or service. In simplest form, the client can send
one Access-Request, which includes username and password, and the RADIUS server can respond with Access-Accept or
Access-Reject. RADIUS can also send one or more Access-Challenge message in order to get additional data, such as a
one-time password (OTP), PIN, or similar.
SSO
When you enable single sign-on (SSO), the GlobalProtect app uses the user’s Windows login credentials to authenticate and
connect to Prisma Access automatically. SSO relies on Windows using the GlobalProtect credential provider. When the user
logs in using the GlobalProtect credential provider, login credentials are passed both to the GlobalProtect app and Windows
local system authority.
SAML
When a SAML profile is enabled, Prisma Access returns a SAML request as a part of the response to the GlobalProtect app’s
pre-login message. The app then redirects to the SAML IdP and opens a window for the user to enter their credentials. The
app keeps the existing connection to Prisma Access and uses a second session to connect to the IdP.
When the user authenticates with the IdP, the app redirects back to Prisma Access. Similarly to the connection to the IdP, the
app uses a new session to forward the SAML assertion to Prisma Access. When Prisma Access validates the IdP assertion,
it returns the extracted username, authentication status, and cookie to the app. The app then resumes the initial connection
with Prisma Access and uses the cookie as proof of authentication.
When configured for an always-on connection method, the GlobalProtect app can use internal host detection in order to
determine whether the network currently connected is external or internal to the organization. Without internal host detection,
the app tries to connect to the internal gateway(s) first and then moves to Prisma Access or an external gateway(s) if an
internal gateway(s) is not available. Internal host detection speeds up the process of connecting to Prisma Access.
Based on the internal host detection determination, the app connects to Prisma Access, an internal gateway, or none at
all (if the network is internal, but there is no internal gateway defined). The app uses a reverse DNS lookup for internal host
detection. If the DNS query for the configured host detection IP address does not return the correct PTR record (as defined in
the configuration), then the app assumes the network is external.
You can configure internal gateways with source IP address ranges that provide the app a way to determine which internal
gateways to authenticate and send HIP reports. Additionally, you can configure site-specific internal gateways through DHCP
Option 43.
Based on the combination of gateway priority and gateway SSL latency, the GlobalProtect app selects a Prisma Access
location to which to connect. Because of the large number of Prisma Access locations, a location might be close (have a low
response time) but provide a challenging user experience, specifically around languages presented by applications or have
regulatory concerns. To provide a deterministic experience, Prisma Access adjusts the location priority values based upon the
endpoint location.
The endpoint location is determined based on the IP address presented to Prisma Access, which has IP-to-country
mappings, and returns a region to the app during the initial communication between the app and the service. This location-
based priority ensures endpoints connecting from or in New York prefer a location in the United States versus one in Canada,
even when the location in Canada has a better response time.
Connection
You can configure the GlobalProtect app to initiate tunnel connections to Prisma Access in the following ways:
• On-demand (manual user-initiated connection)—User initiates the connection when needed (meant for Prisma
Access and external gateways only).
• User-logon (always on)—The app starts the connection when the user logs into the machine and tries to keep the
tunnel up (if disconnected for some reason).
• Pre-logon (always on)—The app starts the connection when the machine boots up (before the user logs in); it
renames the tunnel when the user logs in.
• Pre-logon then on-demand—The app starts the connection when the machine boots up. Depending on the settings
(tunnel rename timeout), when the user logs in, the tunnel is terminated or kept up/renamed. If the tunnel disconnects
for some reason, the client must manually reestablish the connection.
Tunnel connections from the app to Prisma Access can use IPSec or SSL. When enabled, IPSec is always the preferred
connection method. The app attempts IPSec connections as a UDP-encapsulated encapsulating security payload packet
on port 4501. If there is no response from Prisma Access (because of traffic filtering between the endpoint and the security-
processing node), the app falls back to an SSL connection. You cannot disable SSL tunnel fallback.
After the endpoint connects to Prisma Access, the MU-SPN assigns the endpoint an IP address from the MU-SPN's IP pool.
You define the IP pools when onboarding the mobile-user instance in Prisma Access. You can define the IP pools as either
worldwide or regional. As you provision mobile-user locations, the Prisma Access service deploys MU-SPNs and assigns a
subnet from the pool for each one.
Traffic Forwarding
There are two ways you can configure the GlobalProtect app to send the endpoints traffic to Prisma Access:
• Full tunnel—This method is the default and most secure method of forwarding traffic. This method ensures that the
endpoint forwards all WAN and internet-bound traffic to Prisma Access for inspection and policy enforcement.
• Split tunnel—The endpoint forwards latency sensitive or high bandwidth consuming traffic outside of the VPN tunnel
and routes all other traffic through the VPN for inspection and policy enforcement by Prisma Access.
In full tunnel mode, the GlobalProtect app installs on the endpoint a default route that forwards traffic across the tunnel. To
ensure traffic doesn't bounce once the GlobalProtect app establishes the tunnel, when the app chooses a Prisma Access
location, but before it connects to the tunnel, it adds a host route (/32) to the MU-SPN's IP address. The app also adds host
routes for the DNS servers Prisma Access pushes. To ensure the OS chooses the correct routes, the GlobalProtect app set
routes that it adds with a metric of "1".
Even in full tunnel mode, endpoints can still use more specific local routes. You can enable no direct access to local network
in the Windows and macOS GlobalProtect apps to prevent direct access to local networks. With this setting enabled, the app
masks local routes. The app also monitors the routing table for changes, so it can dynamically mask routes added outside of
the app.
Prisma Access does not charge for or limit bandwidth for individual mobile users, and every license edition of Prisma Access
provides up to 250 GB of data transfer per year, per user purchased, averaged across the entire environment. Additionally,
because of the distributed and global nature of the service, the application user-experience should be high even when
the mobile users are distributed around the world. However, you might still have a business requirement that requires split
tunneling. Prisma Access supports split tunneling in addition to full tunneling.
• To specific IP subnets.
• To destination domains.
Resiliency
Prisma Access is a cloud-based secure-access service, designed with redundancy and resilience in order to provide a highly
available service. This section provides options for increasing the resilience of how you connect to your Prisma Access
instance.
The Prisma Access GlobalProtect mobile-user connection method consists of three major components: the GlobalProtect
app running on your endpoint, the Prisma Access GlobalProtect portal, and the Prisma Access GlobalProtect gateway
location. The Prisma Access GlobalProtect connection method has resilience built into the design, some of which you can
customize for your environment. Prisma Access offers more than one hundred GlobalProtect mobile-user gateway locations
that you can enable based on your mobile-user locations and licensing. For the purposes of providing primary and fallback
services, the GlobalProtect connect locations are divided into three geographic regions.
MU Portal Redundancy
The Prisma Access GlobalProtect portal is a secure web service that provides for the distribution of the configuration and
management information for the GlobalProtect app on a mobile-user device. Prisma Access provides the GlobalProtect portal
functionality through multiple portal security processing nodes deployed regionally or globally. To direct clients to the nearest
portal, Prisma Access uses global DNS load-balancing.
• If all your Prisma Access mobile-user gateway locations are deployed in a single region, you have two portals
deployed in that region.
• If you have Prisma Access mobile-user gateways deployed in two regions, you have one portal deployed in each
region.
• If you have Prisma Access mobile-user gateways deployed across three regions, you have one portal deployed in
each region.
Because Prisma Access is a cloud-native service, you do not need to control the portal deployment. Prisma Access
automation pre-determines portal deployment. Global DNS load balancing determines the portal to which the GlobalProtect
mobile user connects, based on lowest-latency metrics of the mobile user's location relative to the portals. A single portal
hostname (FQDN) allows you to reach any of the portals in your Prisma Access instance. If a portal fails, a watchdog process
removes that portal from the DNS resolution list, and the client then connects to an alternate portal in your instance. After
the GlobalProtect app is connected, it receives configuration information from the portal, including a list of Prisma Access
locations
For secure connectivity to internet-based and internal applications, the Prisma Access GlobalProtect mobile user connects to
a MU-SPN at a gateway location. The MU-SPN gateway locations are deployed in cloud provider compute locations, based
on which of the 100+ Prisma Access gateway edge locations you choose to onboard. Prisma Access deploys a single MU-
SPN at a compute location in order to accommodate connections from Prisma Access gateway locations that are mapped
to that compute location. If additional MU-SPNs are required at a compute location in order to handle an increased user-
connection load, Prisma Access automatically adds new MU-SPNs in order to provide horizontal scaling in the compute
location.
MU-SPNs are not deployed in pairs for redundancy. Instead, if the primary choice is unavailable, the GlobalProtect app fails
over to the next best gateway. You do not need to program individual connections on the GlobalProtect app. The Prisma
Access portal passes the list of mobile-user gateway locations that you have enabled, and the GlobalProtect app connects
to the most appropriate gateway available. Based on the observed mobile user's source IP address, the portal passes a
prioritized list of GlobalProtect locations to which the connecting mobile user is eligible to connect.
In the topic How the GlobalProtect App Selects a Prisma Access Location for Mobile
Users in the Prisma Access Administrator's Guide, you can find up-to-date lists for:
• Available GlobalProtect mobile-user gateway locations by region and by compute location.
• Fallback (alternative) locations and manual-select-only locations.
The automatic Prisma Access GlobalProtect client gateway-selection process is as follows, top-to-bottom flow:
• If the mobile user connects in a country that has a Prisma Access location, the user connects to the location in that
country. Location is determined by the device's source IP address.
• If no in-country location is available, the client selects a location based on the Prisma Access region in which it is
connecting:
For redundancy purposes, Palo Alto Networks recommends that during the Prisma Access
GlobalProtect mobile user onboarding, you add these locations in their respective regions.
• If none of the gateway locations above are programmed for your tenant and available, your client attempts to connect
to one of the following fallback gateway locations: Bahrain, France North, Ireland, South Africa West, or South Korea.
Palo Alto Networks strongly recommends that you enable at least one of the fallback
gateway locations during the Prisma Access GlobalProtect mobile-user onboarding.
For redundancy purposes, Palo Alto Networks recommends that you enable locations in
more than one compute location.
If no gateways are available through automatic gateway-selection, and if manual gateway selection is enabled for your
user account, you can manually select a gateway in the GlobalProtect app client. Certain Prisma Access locations are not
included in the automatic gateway selection process, even if you selected the Prisma Access locations in the plugin during
onboarding. However, mobile users can still manually select one of these locations and set it as a preferred location (gateway)
as long as you allow them to manually select those locations during mobile-user onboarding. For more information about
setting a preferred location, see Support for Preferred Gateways in the GlobalProtect App New Features Guide.
If you use on-premises GlobalProtect gateways with Prisma Access locations, you can specify priorities in Prisma Access in
order to let mobile users connect to either a specific on-premises GlobalProtect gateway or a Prisma Access location.
Routing
You configure Prisma Access to route traffic to and from a remote site by using static routing, BGP dynamic routing, or a
combination of both. When making your decision, be sure to consider both directions of the network traffic flow.
You typically use static routing when you have only a single path to a site and the site has only a limited number of prefixes.
Additionally, you can use static routing if you don't anticipate many modifications in the IP address space that would
require a manual update to the routing tables. The primary benefit of static routing is that it is easy to configure and has a
simple, predictable behavior. The drawback of static routing is that you must perform all routing changes manually, which is
cumbersome and error prone if the changes apply to multiple remote sites.
For each statically routed remote site on Prisma Access, you must configure a full list of prefixes. To support direct internet
access (DIA) from the remote site, the remote site typically has a static default route directing internet-bound traffic to Prisma
Access. In the single-path remote-site scenario, the static default route is enough to direct traffic to the internet and your
Prisma Access-connected data centers and to other remote sites for enterprise-based connectivity.
The static routing option is compatible with resilient primary and secondary IPSec tunnels. By using tunnel monitoring, Prisma
Access handles failover transparently. The remote-site device has a corresponding pair of tunnels for primary and secondary.
On your remote-site device, you need to configure two static default routes with different routing metrics. The primary tunnel's
static default route should use a more preferred routing metric, and the secondary tunnel's static default route should use a
less preferred routing metric. To improve failure detection, you should enable tunnel monitoring or an equivalent feature.
Use BGP routing when the remote site uses a large number of prefixes or when you anticipate multiple modifications in the IP
address space. The primary benefits of dynamic BGP routing are automatic prefix learning and support for multiple paths. In
a single-path network, the BGP configuration is simple. In larger, multi-path designs, the BGP configuration can be somewhat
more complex. The BGP principles for connecting remote sites to RN-SPNs, or data centers to corporate-access nodes, are
the same. However, data center connections can be more complex and use more BGP routing features.
The VPN tunnel from the remote site to Prisma Access uses a point-to-point IP subnet with a /31 subnet mask. When
you are onboarding the remote site, you use the VPN tunnel IP addresses as BGP peer addresses, and then Prisma
Access automatically configures a route to your remote-site or service-connection BGP peer address. In the Prisma Access
onboarding for the remote site, you do not have to explicitly add the peer address as a remote-site IP subnet.
The Prisma Access infrastructure uses a single BGP AS with a default assignment of 65534. Prisma Access supports
external BGP only for dynamic routing over service connections and remote-network connections. You assign a unique BGP
AS to each of your remote sites if you require the remote site to communicate with other remote sites, data centers, or mobile
users. BGP loop prevention ensures that sites do not accept routing updates that contain their own AS number. If you reuse
the same AS number for remote sites, those sites can support DIA traffic. However, they are unable to communicate with
each other over the Prisma Access network.
After you configure BGP peering between your remote site and Prisma Access, your remote-site device learns all routes.
These routes include both BGP and static routes from service connections and remote-network connections. You can filter all
routes from Prisma Access to be blocked and send only a default route to the remote site.
Prisma Access configures the default BGP timers for keep alive (30 seconds) and hold time (90 seconds). If you configure
more aggressive timers on the customer BGP peer for faster convergence, for example keep alive (10 seconds) and hold time
(30 seconds), the Prisma Access RN-SPN or corporate-access node adopts the faster timer settings.
The BGP routing option is compatible with resilient primary and secondary IPSec tunnels. Prisma Access handles failover
transparently by using tunnel monitoring. The remote-site device has a corresponding pair of tunnels for primary and
secondary, and each VPN tunnel from the remote site to Prisma Access uses a point-to-point IP subnet with a /30 subnet
mask. You configure two BGP peers, one on each of the primary and secondary tunnels, and then Prisma Access advertises
routes to the remote site with a BGP AS prepend over the secondary tunnel so that traffic uses the primary tunnel. To
improve failure detection, you should enable tunnel monitoring or an equivalent feature.
When routing to remote networks, you can enable Prisma Access to advertise the default route to the remote site in the BGP
setup. You can make your default route path to Prisma Access more resilient with primary and secondary tunnels and tunnel
monitoring or an equivalent feature.
You can configure Prisma Access to advertise a default route by using BGP over a remote-
network link to a remote site. If you advertise a default route to your remote site, ensure that
your remote network does not have a way to pass on the default route beyond the site and
potentially create a routing loop.
To determine the health of their peers, IPSec endpoints configured with IKEv2 use a liveness check. Prisma Access uses
the IKEv2 default settings for the liveness check, and if the link is idle, Prisma Access sends informational packets every 5
seconds. If Prisma Access receives no response, it repeats the liveness check up to 10 times. If you rely on the liveness
check, you can expect to wait 50 seconds in order to determine that a tunnel is down.
To increase bandwidth and link resilience, you can use multiple links between a remote site and a Prisma Access location.
The resilience provided by primary and secondary IPSec tunnels to a single location leaves half of your bandwidth unused.
When you have multiple links with equal bandwidth capabilities, you can use all the links to actively forward traffic to and
from Prisma Access. Equal-cost multi-path routing (ECMP) is a routing strategy where next-hop packet forwarding to a single
destination can occur over multiple "best paths" which tie for top place in routing metric calculations. Prisma Access designs
support two ECMP use cases:
• Large remote network high DIA-only bandwidth scale—This use case is for DIA traffic only and can scale up to 2
Gbps of DIA traffic from the remote site.
• Remote network with resilience and bandwidth scale—This use case is for DIA and private traffic up to 500 Mbps
over ECMP links to a single RN-SPN.
Some large remote-network locations require more bandwidth for DIA-only traffic than a single link to an RN-SPN can
provide. In this use case, you can connect up to four 500 Mbps links, one link per Prisma Access RN-SPN, for a total of 2
Gbps of DIA traffic from the remote site. The RN-SPNs that terminate the links can be in the same location and should be in
the same region for language considerations and link latency.
Figure 15 Equal-cost load-balancing of DIA traffic from the high-bandwidth remote site
To make sure that the user-count and session-count at the location are within current Prisma
Access guidelines, you must review (with a Prisma Access SE specialist) this use case for
each large site for which you would like to use this design.
To support this use case, you must enable overlapped subnets on Prisma Access remote-
networks settings.
ECMP is configured on the remote-network device and not on Prisma Access, and ECMP must perform load-balancing at
the session level, not at the packet level. At the start of a new session, the remote-network device's ECMP process chooses
an equal-cost path. The return path of a traffic flow from Prisma Access to the remote is symmetric because source NAT
(SNAT) is performed on internet traffic and each SPN has a unique IP address for SNAT. This design uses BGP routing
between the remote-site device and each Prisma Access SPN. Prisma Access uses the default BGP HoldTime value of 90
seconds, as defined by RFC 4271. If you configure a lower hold-time for the BGP CPE in the remote-network site, the Prisma
Access BGP peer uses the lower hold-time value. To detect a VPN link outage in the ECMP group faster, set a KeepAlive
value of 10 seconds and a HoldTime value of 30 seconds on your remote device.
The ECMP load-balancing feature that you provision on Prisma Access for remote networks supports up to four links
between the remote-site network device and the Prisma Access RN-SPN at a compute location. All IPSec tunnel links in
an ECMP bundle must terminate at the same location on the same RN-SPN. If you terminate a remote network with four
ECMP links on an RN-SPN, there are no other remote networks assigned to that RN-SPN. The aggregate bandwidth for
that compute location allocates 500 Mbps to that RN-SPN, and then each ECMP link could transmit traffic at 25% of the
RN-SPN total bandwidth (for example 125 Mbps per ECMP link). With security and threat prevention enabled, the RN-
SPN can support up to 500 Mbps of SSL traffic. Prisma Access does not rate-limit or shape per ECMP link or the ECMP
bundle currently. When using Prisma SD-WAN to connect to Prisma Access with multiple links, you must use an ECMP
configuration.
To make sure that your user and session counts at the location is within current Prisma
Access guidelines, you should review (with your Prisma Access SE specialist) remote sites
with high user counts. Prisma Access is constantly improving and optimizing security
network performance.
ECMP performs load-balancing at the session level, not at the packet level. In this use case, you configure ECMP on the
Prisma Access RN-SPN and on the remote-site device. The network device chooses an equal-cost path at the start of
a new session. Equal-cost paths to a single destination are considered ECMP path members or ECMP group members.
ECMP determines which one of the multiple paths to a destination in the forwarding information base (FIB) table to use for an
ECMP flow. The RN-SPN uses a round robin load-balancing algorithm. The Prisma Access RN-SPN maintains a traffic flow
on the same link, and for more effective load-balancing, symmetric return on the same link is preferred. If a link fails, ECMP
rebalances the sessions across the remaining links in the group.
When using ECMP on Prisma Access, you must use BGP routing. Prisma Access automatically configures routes to your
BGP peer address.
For the BGP peer for each IPSec tunnel in the ECMP group, the Prisma Access user
interface requires a unique IP address.
As discussed earlier, Prisma Access uses PAN-OS to deliver a robust App-ID engine, which is shared across all PAN-OS-
based NGFW platforms. Through continuous trust verification and continuous inspection, Prisma Access detects any change
in security posture and any behavioral change by the user or application.
All security-processing nodes used to connect remote sites to Prisma Access use an identical security policy. This policy
includes the zones, address objects, and security policy rules. The value of this approach is that you guarantee that all
locations always have a consistent policy. You cannot customize the policy for any specific remote-network node or remote-
network connection.
Security-policy rules in Prisma Access are always in effect by default, for all dates and times.
If you create a security policy with a schedule-based object to enable and disable a Prisma
Access security policy at recurring times, the time in the policy schedule is based on the
local time at each Prisma Access compute location.
The security-processing nodes used to connect the mobile user or remote site to Prisma Access protect the flows listed in
Table 4. Security-processing nodes protect only flows initiated from the mobile users or remote sites. For completeness, this
table includes all possible destinations, but this guide is primarily focused on flows to the internet.
Table 4 Traffic flows from the remote site secured by Prisma Access
Destination Source zone Destination zone Rule type Connection flow sequence
Corporate-access node
(same node)
Corporate-access node
Security-processing node
Outbound network traffic from a mobile user destined for the internet uses source-based NAT on the MU-SPN. The source
address for internet-bound traffic from the mobile user uses dynamic IP and port translation to the MU-SPN's service IP
address. Prisma Access configures the NAT policy rule for this translation automatically, and you cannot modify the policy.
You have full control of all other security policies for this traffic flow.
Outbound network traffic from the remote site destined for the internet uses source-based NAT on the RN-SPN. The source
address for internet-bound traffic from the remote site uses dynamic IP and port translation to the RN-SPN's service IP
address. Prisma Access configures the NAT policy rule for this translation automatically, and you cannot modify the policy.
You have full control of all other security policies for this traffic flow.
SD-WAN overcomes the limitations of MPLS VPN and internet VPN by providing ubiquitous data encryption, simplified
configuration, active utilization of all links, and rapid convergence while also reducing cost through the expanded usage of
low-cost WAN transports.
In addition to the basic SD-WAN functions previously mentioned, Prisma SD-WAN provides next-generation software-defined
wide-area networking by using built-in Layer 7 intelligence, providing application-aware networking, while also monitoring
for and mitigating jitter, latency, and packet loss. Prisma SD-WAN also provides complete visibility into the application health
across all locations and collects granular, application-driven analytics that you can use for monitoring and troubleshooting.
The Prisma SD-WAN devices include an embedded, application-aware zone-based firewall (ZBFW) that enables you to
enforce security policy rules across your remote sites.
Successful design and deployment of Prisma SD-WAN requires an introduction to the key design elements and constructs.
For a complete discussion of the components of Prisma SD-WAN, see the SASE for Securing Private Applications:
Design Guide. That guide describes their functions and highlights the primary linkages between the components.
This section introduces additional components of the solution that are specific to securing access to the internet.
The Prisma SD-WAN easy onboarding process is not compatible with Panorama-managed
Prisma Access tenants.
Before connecting to Prisma Access, you must configure the following SASE Connectivity settings.
• BGP Local AS Number—This is used for the BGP local AS number of the branch sites. Choose your BGP AS
number from the 16-bit private AS range specified in RFC 6996 (64512-65535). Do not choose the same BGP AS
that you use for your Prisma Access tenant.
• Tunnel Inner IP Pool—Each tunnel will use a /31 subnet from this pool. Specify an IP pool using IP/Mask
notation. This IP Pool should be unused or unique across the entire network and not used by the Palo Alto Service
Infrastructure Subnet.
ION 3000 25 Mbps, 50 Mbps, 150 Mbps, 250 Mbps, 500 Mbps
ION 7000 25 Mbps, 50 Mbps, 150 Mbps, 250 Mbps, 500 Mbps, 1 Gbps
ION 9000 25 Mbps, 50 Mbps, 150 Mbps, 250 Mbps, 500 Mbps, 1 Gbps, 2.5 Gbps
In addition to the bandwidth-based licenses, there are three optional software licenses available for remote-site bandwidth
subscriptions:
• Zone-based firewall—Application-aware, stateful, zone-based firewall that creates, manages, and enforces security
policies that protect internet connections in the remote site and propagate those policies to all remote sites.
• Prisma SD-WAN DVR license (Clarity Network DVR)—Provides a comprehensive real-time and historical view of
your network and application performance. You can gain better insight into traffic outliers and network anomalies,
which helps with better capacity planning, speeds troubleshooting, and improves compliance posture with access to
up to 90 days of statistics, policy, configuration, alarm, and alerts.
• Prisma SD-WAN Report license (WAN Clarity Reports)—Provides an auto-generated report that allows
administrators a deep understanding of how the circuits in the WAN application layer are being used from the
perspective of an entire fabric, site, circuit, application, or user. The report provides actionable insights you can use
for capacity planning, path policy adjustments, QoS policy adjustments, and enforcement of proper use of network
resources by the end-user community.
Prisma SD-WAN DVR and Prisma SD-WAN Report licenses are features enabled at the
customer level but must be purchased for every remote-site device.
Prisma ZBFW is licensed per remote-site device.
Design Model
This design model focuses on securing access to the internet for mobile users, remote-site users, and hybrid workers.
The design uses Prisma SD-WAN to connect remote sites to Prisma Access, and Prisma Access to secure and extend
protection to mobile and remote-site users, as well as to hybrid-worker traffic destined for the internet and cloud-delivered
SaaS applications.
Figure 19 Securing the internet for mobile users and remote sites
Prisma Access provides both visibility into the use of applications on the network and the ability to control user access to
those applications. Key to both visibility and control is the service's App-ID capability. By inspecting the session and payload
information of the traffic traversing the service, App-ID identifies applications and granular application functionality.
If you want to leverage additional ZTNA 2.0 capabilities by integrating user identity and combining user, content, and
application inspection features to enable multi-mode cloud access security broker functions, you can follow the details in
Identity-Based and Posture-Based Security for SASE.
IP Address Assignment
When you configure Prisma Access for mobile-user gateways, you assign a block of IP addresses per region and a worldwide
pool for overflow. Prisma Access allocates a /24 subnet to each mobile-user gateway location that you enable, and then it
advertises each /24 subnet block in BGP individually (example: [Link]/24) to the customer network. For growth and
flexibility, the typical allocation of IP address aggregate pools per region assigns twice the number of IP addresses. For
example, a worldwide deployment of 10,000 users, with a sizing guidance of 20,000 IP addresses, will begin with an example
subnet of [Link] with a /17 address mask for a contiguous block of up to 32,000 IP addresses. Instead of assigning the
entire block to a single worldwide pool, you divide it into three regional blocks and one worldwide block.
• Worldwide—[Link]/19
DNS Resilience
When you configure the GlobalProtect mobile-user DNS configuration, we recommend that you configure the internal
domains to be resolved by an internal DNS server and all external domains to be resolved by the Prisma Access default
DNS servers. With this configuration, an external DNS request is proxied to the Prisma Access default servers by using the
address of the mobile user's location gateway as the source. This ensures that in the event of a loss of connectivity to the
internal DNS, mobile users are still able to access the internet.
For a detailed explanation of the various deployment options for DNS resolution for mobile
users, see the Prisma Access Administrator's Guide.
Prisma Access authenticates all users and endpoints against a SAML provider, such as Okta or Azure Active Directory.
Prisma Access redirects the app to the SAML provider and opens a window for authentication. After authentication is
complete, including optional OTP support within the SAML authentication flow, the app sends the authentication status
cookie to Prisma Access. Prisma Access is unaware of the number of authentication factors the SAML provider uses.
The configuration at the SAML provider decides how long the SAML cookie is valid. While the SAML cookie persists and is
valid, the user experiences transparent authentication to Prisma Access.
When connected to Prisma Access, the GlobalProtect app obtains its configuration, which defines several things, including
the following:
• External gateways—Pre-populates the list of Prisma Access locations deployed as part of the service. You can also
add gateways that you deployed on-premises at your locations.
• Connection method—Sets the user-login (Always On) so that once the user logs on to the endpoint, a tunnel
connects to one of the locations. This connection method ensures that Prisma Access is always protecting the
endpoint when the user is mobile.
When the GlobalProtect app receives its configuration from Prisma Access, it authenticates and builds a VPN tunnel to the
nearest location. The MU-SPN associated with the location uses the same SAML provider as the portal, and if the cookie
obtained when authenticating to the portal hasn't expired, the node authenticates the client transparently. If the cookie has
expired because there has been a significant amount of time since the original authentication, then the node authenticates the
user through the SAML provider in the same way as the portal.
During the connection, the node provides the endpoint an IP address obtained from the IP pool that Prisma Access assigned
it during deployment. The node also generates an IP-to-user mapping.
Policies to control sanctioned and unsanctioned applications are straightforward. In a positive security control configuration,
you add sanctioned applications to the security policy. Because sanctioned applications are allowed without restrictions,
the easiest way to allow-list the application is by adding the container App-ID to the security policy, with an action of Allow.
This container ensures that new functional App-IDs associated with that application are added to the security policy as they
become available. You do not need to add unsanctioned applications to the security policy as the default action of Deny
applies to those applications.
Importantly, in a positive security environment, SaaS applications use SSL/TLS connections in order to communicate
between the client and the server. For SaaS applications, the security-processing node might initially identify traffic by the
SSL or web-browsing App-IDs, and then, as further traffic is available for analysis, might apply another App-ID. Because of
this shift in application identification, the App-IDs for SaaS applications almost universally depend on you allowing SSL and
web-browsing in the security policy. To ensure the node allows only the SaaS application and denies regular web-browsing,
apply an external dynamic list to the rule that uses IP or domain information to limit web-browsing traffic. Many SaaS vendors
publish this information publicly. Palo Alto Networks Cortex XSOAR® can use a threat intel management playbook in order to
periodically pull this information from the SaaS vendor, transform it into a format Prisma Access can use, and publish it so the
nodes can dynamically update their security policy.
Security policy rules in Prisma Access are always in effect by default, for all dates and times.
If you create a security policy with a schedule-based object in order to enable and disable a
Prisma Access security policy at recurring times, the time in the policy schedule is based on
the local time at each Prisma Access compute location.
In a negative security control configuration, the policy allows sanctioned applications by default. To deny their access, add
unsanctioned applications to the security policy. Because a negative security policy denies unsanctioned applications without
exception, the easiest way to deny-list those applications is to add the container App-ID to the security policy, with an action
of Deny.
Prisma Access Enterprise edition includes services for which you should enable security profiles to prevent known malware,
vulnerabilities, and threats in traffic allowed by the security policy. Security profiles enabled in Prisma Access policies should
include the following:
• Anti-spyware—Prevent infected endpoints from sending malicious traffic to command and control systems.
When you use the Cloud Manager to configure security policies for Prisma Access, we recommend that you use the
predefined "Best-practice" security profiles or clone the predefined rule and customize it to your requirements.
This design model assumes you have followed the design guidance for securing private apps for remote sites as shown in the
SASE for Securing Private Applications: Design Guide.
• Prisma SD-WAN interconnects your central-site and remote-site locations, secures your data traffic across public and
private WAN links, enables application-aware path selection, and provides visibility into application health.
• Prisma Access provides protection with deep visibility, secure access, and threat prevention for DIA traffic from the
remote sites.
• Prisma SD-WAN zone-based firewall provides Layer 7 control of remote-site-to-data-center and remote-site-to-
remote-site traffic.
After you deploy the design from that guide, you integrate your existing Prisma SD-WAN environment with Prisma Access.
The Prisma SD-WAN easy onboarding process automates the remote-site interconnections to Prisma Access and allows you
to direct internet and cloud-based applications to Prisma Access.
Prisma SD-WAN protects your internal user traffic by using secure fabric links, which use IPSec tunnels over the public
networks to ensure data privacy through strong encryption. ION devices automatically choose the best WAN path for your
applications based on business policy and real-time analysis of the application performance metrics and WAN links. Prisma
Access provides secure access to the internet and to business applications hosted in SaaS and the public cloud. Prisma
Access inspects all traffic in order to identify applications, threats, and content. Prisma Access provides the same security,
visibility, and control that you would achieve with a NGFW at the remote site.
Palo Alto Networks recommends this design if you require zero-touch provisioning and deployment for your remote-site
devices and pervasive security for DIA and cloud-based applications is a high priority for your organization. This design also
provides deep visibility into the performance of applications running across the SD-WAN.
Through Cloud Manager, you manage the configuration of Prisma SD-WAN and Prisma Access. You manage all policy and
monitoring centrally, and Palo Alto Networks manages the Prisma Access infrastructure.
To manage the integration from Prisma SD-WAN to Prisma Access, you automate the configuration of both components
using the easy onboarding process. This process allows you to automatically configure Prisma SD-WAN, the ION devices,
and Prisma Access. The onboarding process also automates all VPN configuration, which makes this method highly scalable.
As described in the "Prisma SD-WAN Easy Onboarding" section, before connecting to Prisma Access, you must configure
two SASE connectivity settings: BGP Local AS Number and Tunnel Inner IP Pool.
This design includes two options for connecting remote sites to Prisma Access:
• Site with single public WAN link—Connect this site type with a non-ECMP configuration and use static routing.
• Site with multiple public WAN links—Connect this site type with an ECMP configuration to load share up to four
links and use BGP dynamic routing.
After you use the onboarding process to create the standard VPN connections, you use Cloud Manager in order to configure
the associated SD-WAN policy to direct internet and cloud-based applications to Prisma Access. You must also configure
security policy rules on Prisma Access for the associated applications.
Summary
Prisma Access is a major part of the Palo Alto Networks SASE offering and combines with other Prisma offerings to create
the most comprehensive and integrated SASE solution in the industry. Prisma Access provides a scalable and secure method
for extending security to your mobile users. Prisma Access provides full inline traffic inspection with the security features
you use on your on-premises NGFW appliances and VM-Series firewalls. You can achieve consistent security regardless of
location throughout your entire organization.
Integrating Prisma SD-WAN with Prisma Access creates the industry's most extensive SASE architecture. This integration
enables you to route DIA and SaaS application traffic from your branch sites via Prisma Access, so that you can benefit from
Prisma Access full inline traffic inspection and security.
Because Prisma Access is a service, Palo Alto Networks manages the deployment and maintenance of the infrastructure,
and all you must do is manage the policies. Using Cloud Manager, you can centrally manage Prisma Access, SLS, and
Prisma SD-WAN.
Feedback
You can use the feedback form to send comments about this guide.
©2024 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be
found at [Link] All other marks mentioned herein may be trademarks of their
respective companies. Palo Alto Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice.
P-2141P-24062024