Explicit Proxy Configuration Guidelines
Describes the software and network requirements you need to successfully deploy
Prisma Access Explicit Proxy.
| Where Can I Use
This? | What Do I Need? |
System Requirements and Supported Features
These are the system requirements and supported features for the different connection
methods you can use with explicit proxy.
| License | Mobile User Unit per user | Mobile User Unit per user | Mobile User Unit per user | Mobile User unit per user and NET units for bandwidth for remote
networks and/or Site-based licensing for headless devices | Prisma Access enterprise license. Prisma Access business
premium license or ZTNA license with add-on Prisma Browser
license |
| Applications and OS
Support |
| Traffic Type | Internet and public SaaS traffic only | Internet and public SaaS traffic only | Internet and public SaaS traffic, and private application
traffic | Internet and public SaaS traffic only | Internet and public SaaS traffic, and private application
traffic |
| Protocol Supports | Proxy aware HTTP or HTTPS | Proxy aware HTTP or HTTPS | Proxy aware HTTP or HTTPS (All TCP traffic with
GlobalProtect 6.3.1) | Proxy aware HTTP or HTTPS | Proxy aware HTTP or HTTPS |
| Transport Channel to Prisma Access | HTTP Connect | HTTP Connect | HTTP Connect inside TLS | HTTP Connect inside IPSec from branch to Prisma Access | HTTP Connect inside TLS |
| Environments Supported | Windows, Mac, Linux, ChromeOS, VDI |
Windows, Mac, Linux,
ChromeOS, VDI
| Windows and Mac |
All HTTP proxy devices with skip authentication
| Windows, Mac, Android, iOS |
| App Support | Proxy aware HTTP(s) apps | Any app that honors a PAC file or system proxy setting and
supports Kerberos | Proxy aware HTTP(s) apps | Proxy aware HTTP(s) apps | Proxy aware HTTP(s) apps |
| Browser Support | Chrome⁂, Edge, Firefox versions 115 or later | Chrome⁂, Edge, Firefox versions 115 or later | Chrome⁂, Edge, Firefox versions 115 or later* | Chrome⁂, Edge, Firefox versions 115 or later | Not Applicable |
| O365 Support† | Browser and client apps | Browser and client apps | Browser and client apps | Browser and client apps | Browser |
| Identity |
| User-ID‡ | Decrypted and non-HTTP CORS traffic | All Supported Traffic | All Supported Traffic | Depending on whether you're using SAML or Kerberos:
decrypted/non-CORS X-Authenticated-User traffic | All browser supported traffic based on the users authenticated by the
browser. |
| Auth Supported | SAML (Any SAML 2.0 IDPs or through CIE) | Kerberos | All GlobalProtect Supported Auth | SAML, Kerberos, X-Authenticated-User-based | Prisma Browser supported authentication |
| Skip Auth« | By Domain and by Source IP | By Domain and by Source IP | By Domain | By Domain and by Source IP | Not Supported |
| Management |
| Multitenant Cloud Management | Supported | Supported | Supported | Supported | Supported |
| Security
Services |
| SaaS Inline | Supported | Supported | Supported | Supported | Supported |
| DLP | Supported | Supported | Supported | Supported | Supported |
| DNS Security§ | Supported | Supported | Supported | Supported | Supported |
| Advanced URL Filtering | Supported | Supported | Supported | Supported | Supported |
| Advanced WildFire | Supported | Supported | Supported | Supported | Supported |
| Advanced Threat Prevention | Supported | Supported | Supported | Supported | Supported |
| HIP Support | Not Supported | Not Supported | Supported (Tunnel and Proxy mode) | Not Supported | Not Supported |
| Infrastructure
Services |
| Private IP Visibility and Enforcement | Not Supported | Not Supported | Supported for known sites or branches | Supported | Not Supported |
| Egress NAT | Supported | Supported | Supported | Supported | Supported |
| ZTNA Connector | Not Supported | Not Supported | Supported | Not Supported | Supported |
| Colo Connect | Not Supported | Not Supported | Supported | Not Supported | Supported |
| Service Connections¤ | Supported | Supported | Supported | Supported | Supported |
| DNS Proxy | Supported | Supported | Supported | Supported | Supported |
| License |
| Site-Based License | Not Supported | Not Supported | Not Supported | Supported | Not Supported |
⁂ For the Chrome browser, follow the instructions listed below to disable TLS 1.3 Kyber,
if decryption is enabled:
- Open the Chrome browser.
- Add chrome://flags/#enable-tls13-kyber in the address bar and
disable it.
- Click Relaunch.
If you need to disable Kyber in Prisma Browser use
the management console.
* For Proxy Mode on Agent, Firefox requires a manual policy rule pushed through
Mobile Device Management that instructs it to
honor the system proxy
† Explicit proxy supports only HTTP traffic, not UDP. With SAML, explicit proxy
does not provide User-ID for client apps flows. For agent proxy, you need to use a PAC
file to send client app authentication flows to the cloud proxy.
‡ No User-ID is available for auth bypass.
фExplicit proxy in AWS locations support Remote Browser Isolation from Prisma Access
release 6.0 and later.
¤Service Connections is supported for DNS Proxy and Proxy Chaining only.
«Skip auth-bypass for private apps is not supported.
App Support Considerations- Explicit proxy does not support apps that need IP address affinity. The app must
support traffic coming from multiple IP addresses for a given user session.
- Explicit proxy downgrades decrypted HTTP/2 Flows to HTTP/1.
- Explicit proxy does not fetch on-premises external dynamic lists.
- Agentless SAML only:
- Configure an SSL decryption policy to allow auth bypass by domain for
agentless PAC-based explicit proxy with SAML Auth
Decryption is required for Prisma Access to read the authentication state cookie set up by
Prisma Access on the mobile user's browser. Failing to
enforce decryption enables the abuse of explicit proxy as an open
proxy that can attackers can use as a forwarding service for
denial-of-service attacks.
In traffic logs, explicit proxy will show undecrypted and
HTTP-CORS mobile user traffic logs as SWG-authenticated users.
Make a note of the following browser requirements and usage
guidelines:
If you use explicit proxy, don't disable cookies in
your browser; if you do, you can't browse any webpages.
If you're using explicit proxy with Microsoft Edge,
be sure to set to Basic.
Connectivity Requirements
If mobile users are connecting from remote sites or headquarters or data center locations
using an explicit proxy, the mobile user endpoint must be able to reach and route to the
IdP, ACS FQDN, explicit proxy URL, and URL of the PAC file hosted by Prisma Access.
PAC File Requirements and Guidelines—Follow the
PAC File Guidelines when you set up the PAC file to use with explicit
proxy.
Proxy Chaining Guidelines On-Premises Support—Explicit Proxy is a cloud-based proxy solution and not an
on-premises product. For an on-premises proxy solution,
configure a PAN-OS web proxy.