.
In order to push configuration—such as security policy,
authentication policy, server profiles, security profiles, address
objects, and application groups—to Prisma Access, you must either
create new templates and device groups with the configuration settings
you want to push to Prisma Access, or leverage your existing device
groups and templates by adding them to the template stacks and device
group hierarchies that Prisma Access creates when you onboard the
service.
Prisma Access creates the following templates and
device groups, depending on what you have purchased (for example,
if you do not purchase an Explicit Proxy license, you will not see
the Explicit Proxy templates and device groups):
Templates:
Explicit_Proxy_Template
Explicit_Proxy_Template_Stack
Mobile_User_Template
Mobile_User_Template_Stack
Remote_Network_Template
Remote_Network_Template_Stack
Service_Conn_Template
Service_Conn_Template_Stack
Device Groups:
Explicit_Proxy_Device_Group
Mobile_User_Device_Group
Remote_Network_Device_Group
Service_Conn_Device_Group
Configuration
is simplified in Prisma Access because you do not have to configure
any of the infrastructure settings, such as interfaces and routing protocols.
This configuration is automated and pushed from Panorama in the
templates and device groups that the service creates automatically.
You can configure any infrastructure settings that are required
by the service, such as settings required to create IPSec VPN tunnels
to the IPSec-capable devices at your remote network locations, directly
from the plugin. Optionally, you can add templates and device group
hierarchies to the configuration to simplify the service setup.
To simplify the service setup, create or import the
templates and
device groups you need before you
begin the setup tasks for using
Prisma Access.
When creating templates
and device groups for Prisma Access, you do not need to assign managed
devices to it. Instead, you will add them to the template stacks
and device group hierarchies that Prisma Access creates. Do not
add any of the templates or device groups created by Prisma Access
to any other template stacks or device groups.