To onboard the AWS VPC, you need to enable
secure communication between the AWS VPC and Prisma Access using
a VPN gateway (VGW). The following workflow begins the configuration
of the VPN tunnel.
AWS requires a static, routable IP address before you can configure the customer gateway in AWS.
Therefore, you must first create configuration on the Prisma Access side of the
connection to retrieve the
Service IP Address for the
remote network connection and enter that information in AWS when you
configure the
VPN connection in AWS. The initial Prisma Access configuration
requires that you set placeholder values in Panorama for the IKE gateway and
tunnel monitor values. After you configure the VPC in AWS, you then
complete the
Prisma Access configuration in Panorama by changing the placeholder
values you specified.
Start this process by defining a dynamic
IPSec tunnel in Prisma Access.