Managed Cloud WAN—NCC Gateway Integration
Focus
Focus
Prisma Access

Managed Cloud WAN—NCC Gateway Integration

Table of Contents

Managed Cloud WAN—NCC Gateway Integration

Integrate Prisma Access with GCP's Network Connectivity Center (NCC).
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
Palo Alto Networks Managed Cloud WAN (MCW)—Network Connectivity Center (NCC) Gateway integration brings high bandwidth, secure, and reliable connectivity to public and private apps for mobile users and users at remote offices or branch sites. The MCW—NCC Gateway integration reduces operational complexity by integrating Prisma Access with a Google Cloud Platform (GCP) that you manage. Benefits include:
  • Simplifying high-speed connectivity between GCP interconnected infrastructures and the Prisma Access Secure Services Edge (SSE), using direct peering interconnects instead of IPSec VPNs.
  • Centralizing security controls to maintain consistent security policy enforcement across all environments.
  • Fulfilling your organization's requirements to have a high-bandwidth (more than 10 Gbps) connection between branch offices, your Colocation (CoLo) facilities, and cloud environments.
Prisma Access integrates with the NCC Gateway to provide security inspection for:
  • Internet-bound traffic
  • Private app access control and inspection for mobile users accessing applications and resources hosted in GCP and locations interconnected with the customers GCP infrastructure
  • East-west traffic inspection and policy controls for app to app traffic and also branch user to app access.
With this integrated solution, Prisma Access works as an SSE that centralizes security inspection, while your GCP environment acts as the network aggregator for your complex enterprise networks.
Using an NCC Gateway gives you:
  • High-bandwidth capability for secure app access (up to 10 Gbps).
  • Lower network connectivity costs and simplified Colo development and maintenance using the NCC Gateway.
  • A reduction in app latency, because your apps and users are hosted on a high-performance, high-bandwidth backbone.
  • No requirement to configure IPSec tunnels for remote networks or service connections.
  • Prisma Access integration provides a consistent security posture, a common policy framework, and a unified security stack for all users to all private, internet, and SaaS apps.
Prisma Access secures apps that you host:
  • In GCP
  • In your premises
  • In a third-party cloud supported by the NCC Gateway

Solution Use Cases

The Prisma Access—NCC Gateway solution provides data inspection and security policy controls across diverse cloud environments, as shown in the following use cases.
To access the internet from Prisma Access, deploy an MCW Remote Network secure processing node (MCW RN SPN). To access private apps hosted in a data center from Prisma Access, deploy an MCW Service Connection SPN (MCW SC ).
This integration supports two deployment types, on-ramp and off-ramp.
  • Mobile Users Accessing Private Apps Using the MCW-SC Off-Ramp—Provides secure app access for agent-based mobile users (Prisma Access, GlobalProtect and also Prisma Browser). Traffic flows from mobile users through the MCW service connection (MCW SC) and to the NCC Gateway which connects to the GCP infrastructure and interconnects where the private apps are hosted.
    You write security policies for mobile users in the mobile users configuration scope in Strata Cloud Manager and Prisma Access applies the policies at the gateway.
    The following graphic shows the network travel path. The dashed lines are internal Prisma Access connections and don’t require any configuration.
  • Users at Remote Branch Offices Accessing Public and Private Apps Access Using the MCW-RN On-Ramp—Provides secure private app access for user traffic originating from remote offices and campuses, and for remote users from a third-party VPN solution via a Colo facility to the NCC Gateway. The NCC Gateway service routes the customer traffic from these sources to Prisma Access for security inspection for both private app access and internet bound traffic.
    You write security policies for users in branch offices in the Remote Networks configuration scope. Security policies apply data, application and full inspection controls to determine whether to allow or block the connections. You can write additional policies to block other traffic (such as traffic to and from a bitcoin server) and send an alert if malicious traffic is detected.
    • Internet-Based AppsPrisma Access inspects traffic requests to the internet from the NCC Gateway.
    • East-West Traffic Inspection for Apps Hosted in Regional VPCs—Users at the branch access the app after Prisma Access secures the app through the MCW RN. Policy enforcement is at the MCW RN and you write policies in the Remote Network configuration scope.
  • Users Accessing Apps that Require an Update Using the On-Ramp—Allows apps to update if the update site requires access to the internet. In this example, a headless app operating on Google Compute Engine (GCE) in VPC A requires an update from the internet. In this use case, security policy rules are applied that allow the app access to the internet apps and services so that the app can retrieve and download the needed updates
    You can also write additional policies to block other traffic (such as traffic to and from a bitcoin server) and send an alert if malicious traffic is detected. You write security policies for the users in the remote branch remote network configuration scope and Prisma Access applies the policy at the MCW RN.
    To update an app in a VPC, traffic takes the following path.

Prepare the GCP Environment For the Prisma Access Integration

Summary Steps: To integrate an NCC Gateway with Prisma Access, prepare the GCP environment by completing the following workflow.
Before you begin, make sure that you have these prerequisites in place:
  • Google Cloud Prerequisites:
    • Have a working knowledge of GCP VPC network design.
    • Have a working knowledge of Cloud Router, NCC services, and BGP routing.
    • Create a Google Cloud account or have an active GCP project with the NCC service available.
    • Have access to the Google Cloud Console and gcloud CLI commands.
    • Create a Google Cloud customer project.
    • Create an NCC hub.
    • Create NCC Gateway Spoke, including provisioning an NCC gateway-specific cloud router and VLAN attachments.
      Use the HYBRID_INSPECTION spoke topology. Creating a default NCC hub will not support the NCC gateway.
    • Create a SAC realm.
      To use an NCC Gateway with Prisma Access, you need to set up network communication between them. To do this, create a SAC realm and set up a SAC attachment, which provides secure, authenticated, end-to-end access between the NCC Gateway, Prisma Access, and the public or private apps your users need to access.
      The SAC realm is a global GCP resource for NCC Gateway. You associate the SAC realm with a set of networks and user groups who share a Security policy space. NCC Gateway uses the realm to provide identification to Prisma Access, enabling you to apply common Security policy rules to that entire space.
  • Prisma Access Prerequisites:

Enable the Managed Cloud WAN integration in Prisma Access with your GCP project

After you create the SAC Realm in GCP and receive the pairing key, initiate the integration of an NCC Gateway with Prisma Access by creating a managed cloud WAN connection.
  1. From Strata Cloud Manager, go to System SettingsIntegrations and Connect to the Google NCCGW Service.
  2. Enter the GCP Pairing API Key you received from the SAC realm; then Confirm your selection.
    To find the pairing key, enter the gcloud network-security secure-access-connect realms describe $REALM_NAME --project $PROJECT_ID) and find the pairing key field.
    A message displays that the enablement process has started.
  3. Check the status of the managed cloud WAN.
    Approximately five minutes after you enter the pairing key, the managed cloud WAN status changes from Connecting to Connected and Prisma Access is connected to your project. This page auto refreshes every 30 seconds.
  4. (Optional) From Cloud Shell, check the status of the SSE by entering the following CLI command:
    $ gcloud network-security secure-access-connect realms describe $REALM_NAME 
    ––project=$PROJECT_ID
    After you have added the pairing key in Prisma Access, the state of the SAC realm changes from UNATTACHED to ATTACHED, as shown in the following output:
    Realm name: sac-realm
    Customer realm: REALM_NAME 
    SAC service: Palo Alto
    Prisma Access state: ATTACHED
    

Create and Activate the SAC Attachment

The SAC attachment inserts the Prisma Access service into the NCC Gateway. After you have associated the SAC realm with Prisma Access, create the SAC attachment, including creating a Cloud Router and connecting a remote network hybrid connection.
For details and configuration procedures, see the GCP documentation.
After you complete and activate the SAC attachment, set up an off-ramp deployment by deploying a MCW SC in Prisma Access, an on-ramp deployment, by deploying an MCW RN in Prisma Access, or both.

Allow Mobile Users to Access Private Apps Using the MCW SC Off-Ramp

To set up an NCC Gateway off-ramp deployment in Prisma Access, complete the following steps.
The result of following these steps will provision a Managed Cloud Wan Service Connection (MCW SC), which will be the off-ramp to access the private applications hosted in your GCP environment.
  1. Set up a managed cloud WAN service connection.
    1. Go to ConfigurationNGFW and Prisma AccessConfiguration ScopePrisma AccessService ConnectionsManaged Cloud WAN Connections and Add Managed Cloud WAN Site.
    2. Enter the parameters for the managed cloud WAN connection.
      • Site Name—Enter a unique name for the connection.
      • Service Type—Select Google NCC Gateway as the service type.
      • Connection Name—Select the GCP service location you created during NCC Gateway SAC attachment activation and creation.
      • Prisma Access Compute Location—Select the compute location where you want to deploy the NCC Gateway integration with Prisma Access.
      • Bandwidth (Mbps)—Select the bandwidth to allocate in Mbps.
        Enter a value between 1000 and 10000 Mbps.
  2. Save your configuration.
  3. Push Config to commit your changes.
  4. Check the status of the NCC Gateway service connection by refreshing ConfigurationNGFW and Prisma AccessConfiguration ScopePrisma AccessService ConnectionsManaged Cloud WAN Connections and viewing the status of the connection you created.
    • Site Name—The name of the NCC Gateway site.
    • Site Type—The type of site (Google NCC Gateway).
    • Imported Name—The name of the SAC attachment that you created in GCP.
    • Configuration Status—The status of the configuration push job for the NCC Gateway site in Prisma Access. You can check the status of the partner gateway creation in GCP and the orchestration status of the NCC Gateways and service connections.
      • Commit in Progress—The commit is in progress.
      • OK—The commit is complete and was successful.
    • Service Status—The status of the service (includes BGP status and tunnel status).
      • OK—BGP and tunnel status are operational.
    • Prisma Access Compute Location—The compute location where you created the partner SAC attachment.
    • EBGP Router—The route that Prisma Access uses for the SSE.
    • Peer Router—The IP address of the peer router.
    • Peer AS Number—The BGP AS number of the peer router.
    • BGP Status—Provides you with:
      • The aggregate status of the BGP session between the NCC Gateway service connections or SPNs to the SAC attachment.
      • The inter-firewall status between the NCC Gateways and the service connections.
      Click Details to get more information about the BGP status.
  5. Create security policy rules to allow or deny traffic through Prisma Access.
    Strata Cloud Manager has built-in best practice checks to get a live evaluation of your configuration and recommend and optimize security policies.

Allow Secure Internet Access for Branch Users and Hosted Applications using an On-Ramp Deployment

To set up an NCC Gateway on-ramp deployment in Prisma Access, complete the following steps.
The result of following these steps will provision a Managed Cloud Wan Remote Network (MCW RN), which will be the on-ramp for secure internet access for traffic originating from the GCP environments. This internet-bound traffic originates (on-ramps) from users located in branch offices or applications and servers hosted in GCP environment.
  1. Set up a remote managed Cloud WAN connection to use with NCC Gateway.
    1. Go to ConfigurationNGFW and Prisma AccessConfiguration ScopePrisma AccessRemote NetworksManaged Cloud WAN Connections and Add Managed Cloud WAN Site.
    2. Select the GCP service location you created during NCC Gateway SAC attachment activation and creation.
    3. Enter a unique Google NCCGW Site Name for this remote network Cloud Managed WAN.
      The bandwidth area displays after you select the site.
    4. Allocate bandwidth for the compute location in Mbps.
      The maximum you can allocate is 10000 Mbps (10 Gbps). View the remaining licensed bandwidth you can allocate in the Remote Networks area.
  2. Save your configuration.
  3. Push Config to push your configuration changes.
  4. Check the status of the NCC Gateway by refreshing ConfigurationNGFW and Prisma AccessConfiguration ScopePrisma AccessRemote NetworksManaged Cloud WAN Connections and viewing the status of the connection you created.
    • Site Name—The name of the NCC Gateway site.
    • Site Type—The type of site (GCP NCCGW).
    • Imported Name—The name of the SAC attachment that you created in GCP.
    • Configuration Status—The status of the configuration push job for the NCC Gateway site in Prisma Access. You can check the status of the partner gateway creation in GCP and the orchestration status of the NCC Gateways and service connections.
      • Commit in Progress—The commit is in progress.
      • OK—The commit is complete and was successful.
    • Service Status—The status of the service (includes BGP status and tunnel status).
      • OK—BGP and tunnel status are operational.
    • Prisma Access Compute Location—The compute location where you created the partner SAC attachment.
    • EBGP Router—The route that Prisma Access uses for the SSE.
    • Peer Router—The IP address of the peer router.
    • Peer AS Number—The BGP AS number of the peer router.
    • BGP Status—Provides you with:
      • The aggregate status of the BGP session between the NCC Gateway service connections or SPNs to the SAC attachment.
      • The inter-firewall status between the NCC Gateways and the service connections.
      Click Details to get more information about the BGP status.

Complete the NCC Gateway Configuration

To complete the NCC gateways configuration, create gateway advertised routes by following the steps in the GCP documentation.

Delete a SAC Attachment

You can clean up a GPC region by deleting the SAC attachment resource. To do this, follow the procedure in the Google Cloud documentation.