(macOS, Windows, and Linux agents only) To add a
destination domain, click + in the
FQDNs table and enter the FQDN for
the destination domain. You can optionally add a port. If you
don't specify a port, all ports for the specified domain are
subjected to the forwarding rule. You can add one or more
domains for traffic management.You can enter alphanumeric characters for the FQDN. You
can also specify a wildcard domain by including a
wildcard character (*) in the FQDN. However, the
wildcard must appear only once and must be the first
character of the string, and a period must follow the
wildcard.
The following are valid FQDN examples:
The following FQDN examples are not valid:
Prisma Agent will check whether your FQDN entry is
valid or not. For invalid domain inputs, the
"Invalid FQDN format"
message appears.
If you add a port, the port can only contain positive
numbers. The range is 1-65535.
You
will select these destinations when setting up the
forwarding rules in a forwarding profile. To exclude traffic
based on the domain name, select
Direct connectivity when
configuring the forwarding rule. Prisma Agent
will send traffic from the domain through the physical
adapter on the endpoints rather than the tunnel (the virtual
adapter). If you choose to include traffic based on the
domain name, select the Best Available - Fail
Safe
(macOS, Windows, and Linux agents only), Best Available - Fail Open, or
your own configured connectivity option when configuring the
forwarding rule. Traffic from the domain is routed to Prisma
Access, even if it meets the excluded traffic criteria.
To add an access route, click + in the
IP Addresses table and enter a
destination subnet. You can add one or more access routes for
traffic management. (macOS, Windows, and iOS agents only) For IPv6 addresses, you can enter:
For IPv4 addresses, you can a wildcard character (*) in
the IP address, but the wildcard must not appear in the
middle of the IP address. Once a wildcard is used, all
the following octets must also be wildcards.
The following are some examples of valid IPv4
addresses:
The following are examples of an invalid IPv4 address:
Prisma Agent will check whether your IP address
entry is valid or not. For invalid inputs, a message
appears indicating that the IP address is not valid.
In some cases (such as
1.2.*.4 and
7.7.7.7/33), the
configuration validator will allow the entry, but the
agent will ultimately reject it because the entry does
not adhere to a supported format. In this case, the
agent will reject the forwarding profile rule and fall
back to the fail-safe mode, forwarding all traffic to
the
tunnel.
If
you don't include or exclude routes or applications, every
request is routed through the tunnel (without a split
tunnel). Also, all traffic is inspected and subjected to
policy enforcement whenever users connect to Prisma
Access.
When you define split tunnel traffic to
exclude access routes (by selecting
Direct connectivity in the
forwarding rule), Prisma Agent sends these
routes through the physical adapter on the endpoint instead
of being sent through the tunnel via the virtual adapter
(the tunnel). By excluding split tunnel traffic by access
routes, you can send latency-sensitive or high-bandwidth
traffic outside of the tunnel, while all other traffic is
routed through the tunnel for inspection and policy
enforcement by the gateway.
When you define split
tunnel traffic to include access routes (by selecting
Best Available - Fail Safe
(macOS, Windows, and Linux agents only), Best Available - Fail Open, or
your own configured connectivity option in the forwarding
rule), the gateway pushes these routes to the remote users’
endpoints to specify what traffic these endpoints can send
through the tunnel.
Specify exclude routes that are
more specific than include routes; otherwise, you might
exclude more traffic than intended. For example: