Prisma Access Agent
Configure Gateways for the Prisma Access Agent (NGFW Deployment)
Table of Contents
Expand All
|
Collapse All
Prisma Access Agent Docs
-
-
- Configure the Prisma Access Agent (Coexistence Tenant)
- Set Up the Infrastructure for Prisma Access Agents
- Configure General Global Settings for the Prisma Access Agent
- Configure a Certificate to Decrypt the Authentication Override Cookie (Panorama Managed NGFW)
- Export the Authentication Override Cookie for Connecting to an On-Premises NGFW Gateway (Coexistence Tenant)
- Push the Prisma Access Agent Configuration
-
- Prisma Access Agent Overview
-
- Install the Prisma Access Agent
- Log in to the Prisma Access Agent
- Change Prisma Access Agent App Settings
- Connect the Prisma Access Agent to a Different Location
- Connect the Prisma Access Agent to a Different Server
- View Prisma Access Agent Notifications
- Disconnect the Prisma Access Agent from a Location
- Disable the Prisma Access Agent
- Log out of the Prisma Access Agent
- Get Help for Prisma Access Agent Issues
- Switch Between the Prisma Access Agent and GlobalProtect App
- Prisma Access Agent Commands
Configure Gateways for the Prisma Access Agent (NGFW Deployment)
Configure gateways to provide security enforcement for traffic from
Prisma Access Agents in NGFW deployments.
You can add external and external gateways for Prisma Access Agent by selecting the
external and internal gateways that you configured in the Infrastructure tab.
The following procedure applies to NGFW (Managed by Panorama) deployments.
- Navigate to the Prisma Access Agent setup.
- Log in to Strata Cloud Manager as the administrator.
- Select WorkflowsPrisma Access AgentSetup.
- Select Prisma Access Agent.
- Select an existing agent configuration or Add Agent Settings to create a new configuration.
- If you need to create or update an app configuration rule, follow the instructions in Configure Agent Settings for the Prisma Access Agent (NGFW Deployment). Otherwise, go to the next step.
- Add an external gateway.
- Select a gateway. The gateways on the list are the same gateways that you added in the Infrastructure settings.You can’t enter the FQDN or IPv4 settings here, since the gateway is managed on the Infrastructure tab.
- (Optional) Click the + sign to add one or more Source Regions for the gateway, or select Any to make the gateway available to all regions. When users connect, the Prisma Access Agent recognizes the region, and only allows users to connect to gateways that are configured for that region. For gateway selection, the source region is considered first, then gateway priority.
- (Optional) Set the Priority of the gateway by clicking the field and selecting one of the following values:
- If you have only one external gateway, leave the value as Highest (the default).
- If you have multiple external gateways, you can modify the priority values (ranging from Highest to Lowest) to indicate a preference for the specific user group to which this configuration applies. For example, if you prefer that the user group connects to a local gateway, you would set the priority higher than that of more geographically distant gateways. The priority value is then used to weight the agent’s gateway selection algorithm.
- If you don't want apps to automatically establish connections with the gateway, select Manual only. This setting is useful in testing environments.
- (Optional) Select Manual to identify the external gateway as a manual gateway.A manual external gateway resides outside of the corporate network and provides security enforcement, tunnel access, or both for your remote users. The difference between the autodiscovery external gateway and the manual external gateway is that the Prisma Access Agent only connects to a manual external gateway when the user initiates a connection. You can also configure different authentication requirements for manual external gateways.
- Add the gateway settings.
- Add an internal gateway. Follow the steps for adding an external gateway. The steps are similar.