Configure Remote Networks in Strata Cloud Manager
Focus
Focus
Remote Browser Isolation

Configure Remote Networks in Strata Cloud Manager

Table of Contents

Configure Remote Networks in Strata Cloud Manager

Configure Prisma Access to accept the IPSec tunnel from your NGFW by setting up a Remote Networks connection in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by PAN-OS or Panorama)
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access license with Remote Networks license subscription
  • Remote Browser Isolation license
  • Strata Cloud Manager Pro license
Configure Prisma® Access before configuring the NGFW. Strata Cloud Manager assigns an IPSec Termination Node when you create the Remote Network — this is the IP address you enter while configuring the NGFW IPSec tunnel.
  1. Add a Remote Network and configure the IPSec tunnel.
    1. In Strata Cloud Manager, select ConfigurationNGFW and Prisma Access, click the Setup tab, and select Remote Networks.
    2. Click Add Remote Networks.
    3. Enter a Site Name for this location.
    4. Select the Prisma Access Location (region) closest to your NGFW.
      Strata Cloud Manager automatically populates the IPSec Termination Node field. Note this value — it is the Service IP address you enter while configuring the NGFW.
    5. Under Primary Tunnel, click Set Up.
    6. Enter a Tunnel Name.
    7. Select the Branch Device Type as Palo Alto Networks NGFW.
    8. Under IKE Gateway, configure the following settings:
      FieldValue
      Branch Device IP AddressDynamic
      AuthenticationPre-Shared Key
      Pre-Shared KeyA strong shared secret — you enter the same value on the NGFW in the next step
      IKE Peer IdentificationSelect IP address and enter the public IP address of the NGFW untrust interface
    9. Click IKE Advanced Options and configure the following:
      • IKE Protocol Version — IKEv2 only mode
      • Enable IKE NAT Traversal.
    10. Save the tunnel configuration.
    11. Under Routing, click Set Up and add the subnets behind your NGFW that you want Prisma Access to recognize (for example, 192.168.10.0/24).
    12. Click Save to save the Remote Network.
  2. Allocate bandwidth for the Remote Networks region.
    1. In Strata Cloud Manager, select ConfigurationNGFW and Prisma Access, click the Setup tab, and select Remote Networks.
    2. Click Bandwidth Management and allocate bandwidth for the compute location closest to your NGFW.
  3. Push the Remote Networks configuration.
    1. Click Push Config in the page header and push to Remote Networks.
    2. Wait for the push to complete.
      SPN infrastructure provisioning takes approximately 20 minutes. Verify that the tunnel shows as active before proceeding to configure the NGFW.