Prisma Access Agent
Export the Authentication Override Cookie for Connecting to an On-Premises NGFW Gateway (Coexistence Tenant)
Table of Contents
Export the Authentication Override Cookie for Connecting to an On-Premises NGFW Gateway (Coexistence Tenant)
For the Prisma Access Agent to connect to an NGFW on-premises gateway, export
the authentication override cookie from Strata Cloud Manager and import it to Panorama.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
In a deployment that uses the authentication override certificate on a
coexistence-enabled tenant, for the Prisma Access Agent to use an on-premises
NFGW gateway as an external gateway, you need to export the Prisma Access Agent authentication override cookie (certificate) from Strata Cloud Manager and
import it to Panorama.
- Export the authentication override certificate from Strata Cloud Manager.
- In Strata Cloud Manager, select ConfigurationNGFW and Prisma AccessConfiguration ScopeAccess AgentSetupPrisma Access Agent.Edit the Global Agent Settings.In the Authentication Override section, note the name of the Certificate to Encrypt/Decrypt cookie and Cancel out of the Global Agent Settings.In the example below, the authentication override certificate is called custom-cookie-cert.Select ConfigurationNGFW and Prisma AccessConfiguration ScopeAccess AgentObjectsCertificate Management.Select the check box for the custom certificate that matches the one used in the Authentication Override settings and Export Certificate. In our example, select custom-cookie-cert.Select the Encrypted Private Key and Certificate (PKCS12) format.Enter a Passphrase for the certificate and Confirm Passphrase.Save the export settings. The certificate is downloaded to your computer.Import the authentication override certificate to Panorama.
- Log in to Panorama as the administrator and click Panorama.Select DeviceCertificate ManagementCertificatesDevice Certificates.Click Import Certificate.Enter the Certificate Name for the authentication override certificate that you exported from Strata Cloud Manager.In our example, the certificate name is custom-cookie-cert.Browse to the location where you downloaded the certificate. Select the certificate and click Open to upload it.The certificate filename must begin with a letter or number, and can have alphanumeric characters, spaces, commas, dashes, and underscores. If the filename has other characters, rename it to include only the valid characters and upload the file again.Ensure that the file format is Encrypted Private Key and Certificate (PKCS12).Enter the same Passphrase that you used for the authentication override certificate that you imported and Confirm Passphrase.Click OK and wait for the certificate to upload.Configure the external gateway that you want the Prisma Access Agent to access with the authentication override certificate.
- In Panorama, select NetworkGlobalProtectGateways.Select the gateway for which you want to configure the authentication override.Select AgentClient Settings<gateway configuration>.Select Authentication Override, and in Certificate to Encrypt/Decrypt Cookie, select the certificate that you uploaded to Panorama.Click OK to save the configuration and then click OK to save the GlobalProtect gateway configuration settings.Commit and push your configuration by selecting CommitCommit and Push.Click Commit and Push.