Prerequisites to setting up and deploying the App-ID
Cloud Engine (ACE).
| Where Can I Use This? | What Do I Need? |
Prisma Access Next-Generation Firewall
|
|
There are several prerequisite onboarding
tasks to do before the firewall can use the App-ID Cloud Engine
(ACE). You can deploy ACE on standalone firewalls or use Panorama
to deploy ACE on managed firewalls.
Before a firewall can
use ACE to provide specific App-IDs for traffic previously identified
as ssl or web-browsing traffic, the PAN-OS administrator and the
SaaS Security administrator must work together to:
Install
a valid device certificate on each appliance that will use ACE,
including Panorama appliances that manage ACE firewalls. (PAN-OS
administrator.)
(Explicit Proxy Deployments [requires PAN-OS 11.2.3 and later or PAN-OS
11.1.5 and later]) Enable firewalls using a proxy server to access servers
that facilitate requests generated by various features using inline cloud
services.
Activate SaaS Security Inline on each firewall that will
use ACE. Panorama doesn’t require a license. (SaaS Security administrator.)
Configure a service route for communication between the firewall
and ACE. (PAN-OS administrator.)
Enable ACE on Panorama appliances which manage firewalls
that will use ACE. (PAN-OS administrator.)
On firewalls,
ACE is enabled by default after activating SaaS Security Inline.
Create Security policy rule that allows ACE traffic. (PAN-OS
administrator.)
Configure Log Forwarding from the firewall to the Strata Logging Service. (PAN-OS
administrator.)
At
the appropriate step in the following procedure, the PAN-OS administrator
should notify the SaaS Security administrator that the deployment
is ready for SaaS Security Inline activation. After activating SaaS
Security Inline, the SaaS Security Inline administrator should notify the
PAN-OS administrator that the deployment is ready to complete on
the PAN-OS devices. Communication between the administrators is
essential to achieving a smooth deployment.
Requirements:
Standalone firewalls, Panorama appliances, and managed firewalls
must run PAN-OS 11.1 or later.
All ACE firewalls must have purchased a SaaS Security Inline
license. Panorama does not require a license to manage ACE firewalls or
push ACE configurations to managed firewalls.
All ACE appliances must be able to connect to the US, APAC, or EU GCP region, depending on your
location (the region is selected automatically based on your Strata Logging Service region).
Verify that the firewall uses the
correct Content Cloud FQDN () for
your region and change the FQDN if necessary:
US—hawkeye.services-edge.paloaltonetworks.com
EU—eu.hawkeye.services-edge.paloaltonetworks.com
APAC—apac.hawkeye.services-edge.paloaltonetworks.com
ACE
data, including traffic payloads, is sent to the servers in the
selected region. If you specify a Content Cloud FQDN that is outside
of your region (for example, if you are in the EU region but you
specify the APAC region FQDN), you may violate your country’s or
your organization’s privacy and legal regulations.
The
PAN-OS administrator completes the first two steps of the procedure
and then hands it off to the SaaS Security Inline administrator
for activation (
Step 3). After
activation, the SaaS Security Inline administrator hands the rest
of the procedure back to the PAN-OS administrator to complete on
the PAN-OS devices.