| Where Can I Use
This? | What Do I Need? |
To redistribute quarantine list information, complete the following steps.
For Prisma Access (Managed by Strata Cloud Manager) deployments:
View the redistribution diagram and, if required, Edit
it in Strata Cloud Manager by going to and setting the Configuration Scope to
Prisma Access.
To change the mobile user-to-service connection redistribution and
the remote networks-to-service connection redistribution, click
Edit to edit the default changes.
The changes you make here apply to both mobile user-to-service
connection and remote network-to-service connection redistribution.
Be sure not to configure any redistribution
loops during configuration. For example, the service connection
redistributes quarantined device information to the mobile users; if
you configure quarantine list information to be sent from mobile
users to service connections; you introduce a loop that could cause
memory issues and slowness in the Prisma Access infrastructure.
- For Prisma Access (Managed by Panorama) deployments:
- Make sure that the Panorama management IP address is able to communicate
with the User-ID agent address for all service connections to which you
want to redistribute quarantine list information.
Communication
between the User-ID Agent address of the service connection and the
management IP address of Panorama is required for Prisma Access
to send and receive quarantine list information between Panorama and
the service connections.
To find the User-ID Agent Address,
select .
To find the management IP address of the Panorama that
manages Prisma Access, note the IP address that displays
in the web browser when you access Panorama.
- Allow Prisma Access to redistribute quarantine list information.
- In Panorama, select .
- Click the gear icon to edit the settings.
- In the Advanced tab, select
Enable Quarantine List
Redistribution.
Enabling quarantine list
redistribution allows Prisma Access to redistribute the
quarantine list information received from one or more mobile
user locations (gateways) to service connections.
- Commit and Push your
changes.
- Configure Panorama to receive quarantine list information from Prisma Access by configuring management interface settings.
- In the Panorama that manages Prisma Access, select .
- Select the Management interface.
- Select User-ID.
- Configure a data redistribution agent that redistributes quarantine list
information from the service connections to Panorama.
- From the Panorama that manages Prisma Access, select .
- Make a note of the User-ID Agent Address () for each service connection.
- Select .
- Add a Data Redistribution agent, give it
a Name and select
Enabled.
- Enter the User-ID Agent Address of the
service connection as the Host and 5007
as the Port.
Make sure that your network does not block access to this
port between Panorama and Prisma Access.
- (Optional) If you have configured this service
connection as a Collector (), enter the Collector Name
and Collector Pre-Shared Key.
- Select Quarantine List; then, click
OK.
- Repeat the previous step for all the service connections in your
Prisma Access deployment.
- Select to save your changes locally on the Panorama that manages
Prisma Access.
- Configure a data redistribution agent that redistributes quarantine list
information from Panorama to the service connections.
- Find the management IP address of the Panorama that manages Prisma Access.
This address displays by in the web browser
address bar when you access Panorama.
- Make sure that you are in the
Service_Conn_Template template, then
select .
- Add a Data Redistribution agent, give it
a Name and select
Enabled.
- Enter the management IP address of the Panorama appliance as the
Host and 5007 as the
Port.
- Select Quarantine List; then, click
OK.
- Configure a data redistribution agent that redistributes quarantine list
information from the service connections to mobile user gateways.
- From the Panorama that manages Prisma Access, select .
- Make a note of the User-ID Agent Address
of the service connection from which you want to redistribute
quarantine list information.
Since all service connections
have the same redistributed quarantine list information,
choose any service connection. You can also configure more
than one service connection.
- Make sure that you are in the
Mobile_User_Template, then select .
- Add a Data Redistribution agent, give it
a Name, and select
Enabled.
- Enter the User-ID Agent Address of the
service connection as the Host and 5007
as the Port.
Make sure that your network does not block access to this
port between Panorama and Prisma Access.
- (Optional) If you have configured this service
connection as a Collector (), enter the Collector Name
and Collector Pre-Shared Key.
- Select Quarantine List; then, click
OK.
- Commit and Push your changes.
- View your quarantine list information by selecting .