Prisma Access
Private IP Address Visibility and Enforcement for Agent Based Proxy Traffic
Table of Contents
Expand All
|
Collapse All
Prisma Access Docs
-
-
- Prisma Access China
- 4.0 & Later
- 3.2 Preferred and Innovation
- 3.1 Preferred and Innovation
- 3.0 Preferred and Innovation
- 2.2 Preferred
-
-
-
- 5.2 Preferred and Innovation
- 5.1 Preferred and Innovation
- 5.0 Preferred and Innovation
- 4.2 Preferred
- 4.1 Preferred
- 4.0 Preferred
- 3.2 Preferred and Innovation
- 3.1 Preferred and Innovation
- 3.0 Preferred and Innovation
- 2.2 Preferred
Private IP Address Visibility and Enforcement for Agent Based Proxy Traffic
Learn how to enable private IP address visibility and enforcement for GlobalProtect
proxy mode and GlobalProtect tunnel and proxy mode.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Users who connect to Prisma Access Explicit Proxy through GlobalProtect agent
from branches, can leverage Private IP addresses of endpoints for logging or to apply IP
address based enforcement.
Private IP Address Visibility and Enforcement for Agent Based Proxy Traffic (Strata Cloud Manager)
Configure private IP address visibility in GlobalProtect Proxy mode.
- Enable the Agent-based Proxy functionality (Proxy mode or Tunnel and Proxy mode) for mobile users.Navigate to WorkflowsPrisma Access SetupExplicit ProxyAdvanced Security Settings, and click the settings icon. Under Trusted Source Address, add the branch egress IP address.Navigate to WorkflowsPrisma Access Setup Explicit ProxyInfrastructure Settings. Under Proxy URL Settings, enable Enable Source IP based visibility and enforcement, and click Save.(Optional) Configure the security rules with the source IP address of the endpoint.Push Config to Explicit Proxy.
Private IP Address Visibility and Enforcement for Agent Based Proxy Traffic (Panorama)
Configure the private IP visibility and enforcement for GlobalProtect in Proxy mode for panorama.- Enable the Agent-based Proxy functionality (Proxy mode and Tunnel and Proxy mode) for mobile users.Navigate to Cloud ServicesConfiguration Mobile UsersExplicit ProxySettingsAuthentication Settings and add the branch egress IP address under Known Source IP Address.Navigate to Cloud ServicesConfiguration Mobile Users-Explicit Proxy. Under Agent, enable Enable Source IP based Visibility and Enforcement from Sites, and click OK.(Optional) Configure the security rules with the source IP address of the endpoint.Commit and push to the Explicit_Proxy_Device_Group.