Configure Third-Party Agent Coexistence via Tunnel Adapter Routing Priority
Focus
Focus
Prisma Agent

Configure Third-Party Agent Coexistence via Tunnel Adapter Routing Priority

Table of Contents

Configure Third-Party Agent Coexistence via Tunnel Adapter Routing Priority

Configure forwarding profiles to enable third-party agent coexistence by lowering Prisma Agent's tunnel adapter routing priority.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Check the prerequisites for your deployment
  • Prisma Agent 26.3 or later
  • macOS or Windows endpoints
Third-party agent coexistence using the Third Party Co-Existence forwarding profile option enables Prisma Agent to run alongside a third-party remote access agent without claiming the default network route. By default, Prisma Agent's tunnel adapter takes over the default route when it connects, which can disrupt traffic from other agents running on the same endpoint. Enabling Third Party Co-Existence in the forwarding profile resolves this by making Prisma Agent a lower-priority route at the OS routing-table level.

How It Works

When Enable is selected under Third Party Co-Existence in a forwarding profile, Prisma Agent adjusts how its tunnel adapter participates in the OS routing table:
  • Windows: Prisma Agent raises the routing metric on its tunnel adapter to a high value. The physical interface retains its lower metric and becomes the preferred path for traffic that reaches the routing table.
  • macOS: Prisma Agent uses interface-scoped routing on its tunnel interface rather than claiming the default route. The physical interface remains the default route.
Despite these routing-table changes, Prisma Agent continues to enforce TCP and UDP traffic according to your forwarding profile rules. TCP and UDP traffic matched by forwarding profile rules is still sent through the Prisma Agent tunnel for security inspection and policy enforcement. Traffic that is not subject to forwarding profile enforcement, such as non-TCP and non-UDP protocols, is not routed through the Prisma Agent tunnel. How that traffic is handled depends on the third-party agent and the OS routing table.
Traffic Behavior
Traffic TypeBehavior with Third Party Co-Existence Enabled
TCP / UDP matched by forwarding profile rulesEnforced by Prisma Agent and sent through the tunnel
TCP / UDP with a Bypass forwarding ruleBypassed by Prisma Agent; exits via the physical interface or third-party VPN adapter based on the routing table
Non-TCP / Non-UDP (ICMP, GRE, IPsec, and similar)Not subject to forwarding profile enforcement; exits via the physical interface
Comparison with Bypass Rules
Bypass rules let you specify individual applications or destinations whose TCP/UDP traffic should be sent directly rather than through the Prisma Agent tunnel. The Third Party Co-Existence option is a complementary, routing-level change that affects all traffic that reaches the OS routing table. You can use both together: bypass rules to route specific TCP/UDP traffic to the physical interface, and Third Party Co-Existence to ensure all other traffic uses the physical-interface path.
Mutual Exclusivity with Block Non-TCP and Non-UDP Traffic
The Third Party Co-Existence and Block Non-TCP and Non-UDP Based Traffic When Connected to Tunnel options cannot both be enabled in the same forwarding profile. Enabling Third Party Co-Existence means non-TCP/non-UDP traffic exits via the physical interface; selecting Block Non-TCP/Non-UDP would then block all such traffic entirely. The interface automatically grays out Block Non-TCP/Non-UDP when Third Party Co-Existence is enabled.

Configure Third-Party Agent Coexistence via Tunnel Adapter Routing Priority (Strata Cloud Manager)

Enable the Third Party Co-Existence option in a Strata Cloud Manager forwarding profile to lower Prisma Agent's tunnel adapter routing priority.
To enable third-party agent coexistence by lowering the tunnel adapter routing priority in Strata Cloud Manager Managed Prisma Access deployments, select Enable under Third Party Co-Existence in a forwarding profile:
  1. Go to the forwarding profiles setup page:
    1. Select ConfigurationNGFW and Prisma AccessConfiguration ScopeMobile Users ContainerMobile Users.
    2. Select the gear icon in the Forwarding Profiles Setup section.
  2. Select an existing Prisma Agent forwarding profile to modify, or add a forwarding profile.
  3. Under Third Party Co-Existence, select Enable.
    By default, this option is not selected. Enabling it allows Prisma Agent to use lower-priority routing so the third-party VPN agent can retain the default route.
    Enabling Third Party Co-Existence automatically grays out Block Non-TCP and Non-UDP Based Traffic When Connected to Tunnel in the Traffic Enforcement section. The two options are mutually exclusive.
  4. Save your forwarding profile settings.
  5. Push the configuration to deploy the setting to your Prisma Agent deployment.