Simplify Coffee Shop Deployment Policies for Prisma Access Traffic
Focus
Focus
Prisma SD-WAN

Simplify Coffee Shop Deployment Policies for Prisma Access Traffic

Table of Contents

Simplify Coffee Shop Deployment Policies for Prisma Access Traffic

Simplify coffee shop deployment policies for Prisma access traffic.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN (Managed by Strata Cloud Manager)
  • Prisma Access
  • Prisma SD-WAN
The automated Coffee Shop deployment policy simplifies how Prisma SD-WAN branches connect to Prisma Access Mobile Users (MU) and Explicit Proxy (EP) Users. These policies ensure that MU and EP traffic from an SD-WAN branch is automatically redirected directly to the internet path, bypassing the Remote Network (RN) tunnel to use your Mobile User license effectively and remove the need to manually track gateway IP addresses as they change. Prisma Access automatically pushes service IP addresses of spawned mobile user (MU) and explicit proxy (EP) instances to the SD-WAN controller, which then creates automatic prefix lists and path policies to direct traffic directly to the internet.
The automated routing feature is exclusively supported on RN-HP (Remote Network - High Performance) infrastructure, which is designed to onboard branch sites requiring high bandwidth, providing robust security and simplified management. Coffeeshop deployment policies requires both Prisma Access and SD-WAN licenses. It is managed via Strata Cloud Manager (SCM). This functionality is not supported on standalone SD-WAN deployments.
Performance Policies are not supported for Coffeeshop deployments policies.
Mobile User prefix lists support both IPv4 and IPv6, while Explicit Proxy prefix lists support IPv4 only.
Learn how to configure Coffeeshop deployment policies for Prisma Access traffic.