Prisma Access Service Connections
Focus
Focus
Prisma Access

Prisma Access Service Connections

Table of Contents

Prisma Access Service Connections

Learn how service connections work in a Prisma Access deployment.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
A service connection, also known as a Corporate Access Node (CAN), allows mobile users and users at remote networks access to private apps and resources and lets your mobile users and remote networks communicate with each other.
In addition to Service Connections, Palo Alto Networks provides you with other services you can use to access private apps:
  • ZTNA Connector—The Zero Trust Network Access (ZTNA) Connector lets you connect Prisma Access to your organization's private apps simply and securely. ZTNA Connector provides mobile users and users at branch locations access to your private apps using an automated secure tunnel. You can also automatically discover private apps for ZTNA to protect using the Cloud Identity Engine.
  • Prisma Access—Colo-Connect allows you to use Prisma Access to secure private apps using a cloud interconnect that can provide high-bandwidth service connections.
Palo Alto Networks recommends always creating a service connection in your Prisma Access deployment. All service connections have these characteristics:
    Expand all
    Collapse all
  • A service connection allows access to the resources in your HQ or data center.
  • A service connection allows remote networks and mobile users to communicate with each other.
  • Service connections do not support language localization because egress to the internet is not supported over service connections. Prisma Access allocates only one service IP sddress per service connection, and that IP address is geographically registered to the compute location that corresponds to the location you specify during onboarding.
The number of service connections you receive depends on your Prisma Access license.
    Expand all
    Collapse all
  • If you have a ZTNA or Enterprise license, the number of service connections depends on your License edition. If you have a Local edition, you can configure a maximum of two service connections; if you have a Worldwide edition, you can configure a maximum of five service connections.
  • If you manage multiple tenants and have a ZTNA or Enterprise license, the number of service connections per tenant depends on the number of units you allocate per tenant and the type of license you have.
Before you can start configuring your service connections, review what information you need to gather first.