Focus

New Features - Prisma Access Agent - 25.1


Automatic Tunnel Restoration

Release Date: April 2025 | Last Updated: May 2026

Automatic tunnel restoration in Prisma® Access Agents automatically restores secure connections after interruptions like network disruptions or system sleep modes. This feature operates in both Always On and On Demand connectivity modes. In Always On mode, the Prisma Access Agent continuously attempts to maintain a connection, while On Demand mode allows your users to control when to connect or disconnect. The secure tunnel restoration process efficiently decides whether to reconnect to the last known Prisma Access location or use the best location. This feature is useful for mobile workers, remote employees, and organizations requiring secure and stable network access. It helps maintain productivity by reducing manual reconnection efforts and minimizing downtime across various network conditions and device states.

Disable the Prisma Access Agent

Release Date: April 2025 | Last Updated: May 2026

You can give your end users the flexibility to temporarily disable the Prisma® Access Agent when necessary. You can configure this feature on a per-user or user group basis, giving you granular control over who has the ability to disable the agent. When configured, users can conveniently disable and re-enable the agent through the Prisma Access Agent app .

This feature is useful in environments where other secure access solutions coexist, such as the GlobalProtect® app. After disabling the Prisma Access Agent, your users will be able to switch to the GlobalProtect app without interference. This feature is compatible with various connection methods, including Always On and On Demand modes, and is compatible with the anti-tamper feature, which prevents an unauthorized user from tampering with the agent. By enabling this feature, you allow your users to manage their secure access connections more effectively while maintaining overall security and control.

Forwarding Profiles Configuration Validator

Release Date: April 2025 | Last Updated: May 2026

The Forwarding Profiles Setup page provides a forwarding profiles configuration validator for destination domains, which can validate the FQDN and IP address that you enter. This ensures that the values you enter are valid and follows predefined standards, and is essential for preventing misconfigurations that could lead to system failures, security vulnerabilities, or degraded performance.

NGFW Support for Prisma Access Agent

Release Date: April 2025 | Last Updated: May 2026

NGFW Support for Prisma® Access Agent enables organizations that use NGFW to adopt and manage Prisma Access Agents. This feature enhances secure access management while maintaining compatibility with existing authentication methods and NGFW setups, offering a smooth transition path to advanced Prisma Access Agent capabilities.

Optimized Prisma Access Agent MTU

Release Date: April 2025 | Last Updated: May 2026

Your organization might face challenges with agent connections traversing multiple ISPs and network hops, resulting in varying MTU values lower than the standard 1500 bytes. This situation can lead to excessive fragmentation, additional overhead, lower throughput, and dropped packets, ultimately causing poor performance and user frustration. Manual configuration of optimal MTU in such diverse environments is time-consuming, repetitive, and not scalable.

The optimized Prisma® Access Agent MTU feature addresses these pain points by automatically determining and applying the optimal maximum transmission unit (MTU) size for agent connections. Optimized MTU is enabled by default in Prisma Access Agent to help improve connection stability and performance without manual intervention across various network conditions. This feature supports IPv4 tunnels and is compatible with IPSec and SSL tunnel protocols. It's valuable for organizations with remote users connecting through different ISPs or those frequently encountering MTU-related connectivity issues. By utilizing this feature, you can expect improved network throughput, reduced packet fragmentation, fewer retransmissions, enhanced end-user experience, increased productivity, and a decrease in support escalations related to connection performance issues.

Although optimized MTU is enabled by default for all Prisma Access Agents, you can manually configure and override the PMTU value if needed.

Panorama Support for Prisma Access Agent

Release Date: April 2025 | Last Updated: May 2026

Panorama® Support for Prisma® Access Agent enables you to manage and configure Prisma Access Agents on Strata™ Cloud Manager while continuing to use Panorama® for your Prisma Access deployment. This feature allows Panorama Managed Prisma Access customers to utilize Prisma Access Agents without migrating to the Strata Cloud Manager management interface. You can configure agent behavior, forwarding profiles, authentication methods, and infrastructure settings specific to Prisma Access Agents through Strata Cloud Manager. The feature supports both Prisma Access gateways and on-premises gateways, allowing you to manage Prisma Access Agent configurations across your hybrid deployments. You can take advantage of the advanced security capabilities of the Prisma Access Agent while maintaining your current Panorama-based management approach. By using this feature, you can enhance your security posture with Prisma Access Agents while preserving your investment in Panorama and maintaining operational continuity.