Prisma Access Internal Gateway (Panorama)
Focus
Focus
Prisma Access

Prisma Access Internal Gateway (Panorama)

Table of Contents


Prisma Access
Internal Gateway (
Panorama
)

  1. Notice that there are no internal host detection and internal gateway configurations at present.
  2. Go to
    Panorama
    Cloud Services
    Configuration
    Remote Networks
    Settings
    .
  3. Enable Internal Gateway
    and save the changes.
    (
    Optional
    )
    Enable Prisma Access Internal Host Detection
    for IPv4 if you don't want to use your own DNS server. You can enable the internal host detection only after you select
    Enable Internal Gateway
    .
    Prisma Access
    supports internal host detection only for the
    Always On
    connect method.
    When you enable the internal gateway, the remote network instances act as internal gateways. When you enable the internal host detection,
    Prisma Access
    creates PTR records on the remote network DNS proxy servers for the internal host detection process.
    When you enable the internal gateway,
    Prisma Access
    creates an internal gateway configuration in a remote network template.
  4. Go to
    Templates
    Network
    GlobalProtect
    Gateways
    and select
    Remote_Network_Template
    .
    You will find the
    GlobalProtect_Internal_Gateway
    template created for the internal gateway.
  5. Create an authentication profile for this remote network template similar to the authentication profile in the mobile user template.
    1. Select the remote network template,
      GlobalProtect_Internal_Gateway
      template, hyperlink.
    2. Go to
      Authentication
      Client Authentication
      .
    3. Edit the authentication profile details of the
      DEFAULT
      client authentication.
      Create an authentication profile same as the one in the mobile user template. You can find the authentication profile used in the mobile user template under
      Template
      Device
      Authentication Profile
      . Ensure to select
      Mobile_User_Template
      .
      You can also view the authentication profile for the remote network template by selecting
      Templates
      Device
      Authentication Profile
      . Select
      Remote_Network_Template
      .
  6. Create a device certificate for the remote network template similar to the device certificate in the mobile user template.
    1. Select the remote network template,
      GlobalProtect_Internal_Gateway
      , hyperlink.
    2. Go to
      Agent
      Client Settings
      .
    3. Select the
      DEFAULT
      configuration, and go to
      Authentication Override
      settings.
    4. Edit the
      Certificate to Encrypt/Decrypt Cookie
      settings, and create a new device certificate.
      Create a device certificate same as the one in the mobile user template. You can find the device certificate used in the mobile user template under
      Template
      Device
      Certificate Management
      Certificates
      Device Certificates
      . Ensure to select
      Mobile_User_Template
      . The
      DEFAULT
      configuration references the
      Authentication Cookie CA
      certificate. Follow the same hierarchy as the one in
      Mobile_User_Template
      for successful authentication.
      You can also view the device certificate for the remote network template by selecting
      Template
      Device
      Certificate Management
      Certificates
      Device Certificates
      . Select
      Remote_Network_Template
      .
  7. Push
    the changes to mobile users and remote networks at the same time.


Recommended For You