How Prisma Access Selects a Location for Mobile Users
Focus
Prisma Access

How Prisma Access Selects a Location for Mobile Users

Table of Contents

How Prisma Access Selects a Location for Mobile Users

Learn how the GlobalProtect app selects a location when Prisma Access mobile users log on.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
  • Prisma Access license
When a mobile user connects to a Prisma Access location, the app uses the following selection process to determine to which location it connects.
You enable the mobile user locations where you want Prisma Access to be present during mobile user onboarding. If you do not select the location during onboarding, Prisma Access does not use it in your deployment.
  • If the mobile user connects in a country that has a Prisma Access location, the user connects to a location in that country.
  • If the mobile user cannot connect to its preferred location, Prisma Access uses the following criteria in the following order to connect to another location:
    1. If you've onboarded another location in the same country as the user, Prisma Access connects to that location. For example, if you've onboarded the US East and US West locations and the US East location goes down, Prisma Access attempts to connect to the US West location.
    2. If Prisma Access cannot connect to another in-country location, it selects another location based on the same region as the user (Asia, Australia & Japan, Africa, Europe & Middle East, or North America & South America).
      Prisma Access uses the following locations as regional fallback locations. Palo Alto Networks recommends that you enable at least one of these locations in their respective regions during mobile user onboarding to provide redundancy.
      • Asia, Australia & Japan: Hong Kong, Japan Central, or Japan South
      • Africa, Europe & Middle East: Netherlands Central
      • North America & South America: US Northwest
    3. If Prisma Access cannot connect to any of the regional fallback locations, it uses one of the following locations that are known as global fallback locations. Palo Alto Networks recommends that you enable at least one of the global fallback locations to provide redundancy.
      • Bahrain
      • France North
      • Ireland
      • South Africa West
      • South Korea
  • Palo Alto Networks recommends that you enable locations in more than one compute location for redundancy purposes.
  • If you use on-premises gateways with Prisma Access locations, you can specify priorities in Prisma Access to let mobile users connect to either a specific on-premises GlobalProtect gateway or a Prisma Access location. See Manage Priorities for for details.
  • When mobile users connect, the GlobalProtect app does not use the following Prisma Access locations in the automatic gateway selection process, even if you selected the Prisma Access locations in the plugin during onboarding. However, mobile users can still manually select one of these locations and set it as a preferred location (gateway) as long as you allow them to manually select those locations during mobile user onboarding:
    • Australia: Australia East
    • Brazil: Brazil East and Brazil Central
    • France: France South
    • Germany: Germany North and Germany South
    • India: India South
    • Mexico: Mexico West
    • Netherlands: Netherlands South
    • Pakistan: Pakistan West
    • Russia: Russia Northwest
    • Spain: Spain East
    You might have to change your Connect Method to On-Demand for the mobile user to manually connect to a gateway.