Configuration Management Overview for NGFW Support for Prisma Agent
Focus
Focus
Prisma Agent

Configuration Management Overview for NGFW Support for Prisma Agent

Table of Contents

Configuration Management Overview for NGFW Support for Prisma Agent

Review the configuration management overview to understand the workflows for the different management platforms.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama)
  • Check the prerequisites for the supported PAN-OS versions
  • Prisma Agent license for NGFW deployments
NGFW support for Prisma Agent enables you to manage Prisma Agents alongside your existing NGFW infrastructure, enabling a gradual adoption strategy for Prisma Agents.
The following table illustrates the day 0 workflow for the different management platforms.
ManagementDay 0 Configuration Workflow
On Panorama or NGFW gateway
  1. Import certificates for authentication override cookie
  2. Onboard internal and external gateways
On Strata Cloud Manager
  1. Register the Prisma Agent domain
  2. Define internal and external gateways
  3. Import certificates
  4. Set Up Cloud Identity Engine for Prisma Agent User Authentication
  5. Create simplified forwarding profiles
  6. Create agent settings
  7. Define upgrade rings for staged rollout upgrades
  8. Provide the anti-tamper unlock password
  9. Select the authentication override cookie
Note the following for this workflow:
  • Manage the gateway configurations independently using your existing management platform (Panorama or the native web interface)
  • Use the Prisma Agent management plane on Strata Cloud Manager to manage Prisma Agent configurations
  • There is no configuration sync between the gateway and the agent management plane
  • When you add or delete a gateway and rotate the authentication override cookie certificate, you will need to manually update the cert on both the gateway and on the agent management plane