Deploy a VM-series firewall (either a VM-300 or VM-500 model instance)
or a next-generation firewall to use as
Router 1
in
the VPC located in China, configure it as a GlobalProtect gateway,
add this gateway to Prisma Access’ GlobalProtect portal, and configure
a VM-series firewall to establish an IPSec site-to-site tunnel to
the private IP address of Router 2.