Dynamic Location-Based Steering in Prisma Access Agent
Focus
Focus
What's New in the NetSec Platform

Dynamic Location-Based Steering in Prisma Access Agent

Table of Contents

Dynamic Location-Based Steering in Prisma Access Agent

Route traffic based on user location to optimize performance, manage infrastructure costs, and maintain compliance across office locations and remote work environments.
Managing diverse infrastructure needs across corporate offices and remote work environments requires flexible traffic routing. Dynamic location-based steering addresses this challenge by enabling you to route traffic based on user physical location or network. When you deploy Prisma® Access Agent with this feature, the agent detects user location through Internal Host Detection or source IP address matching and applies the appropriate forwarding profile rules automatically.
You can configure different traffic steering behaviors for each office location in your forwarding profiles by adding user location as a matching criterion. This allows you to optimize traffic routing based on where users connect from, ensuring that security policies remain enforced while respecting local network infrastructure. The agent evaluates forwarding profile rules in priority order, matching traffic to the first rule where all criteria including user location are satisfied.
You might use this feature if your organization operates offices with varying network infrastructure or if you need to route traffic differently when users work from branch offices. You configure user locations in Strata Cloud Manager by defining detection criteria using either of the two supported methods, Internal Host Detection or source IP address lists, then reference those locations in your forwarding profile rules alongside existing criteria such as destination addresses and source applications.