Learn about the prerequisites for Prisma Access Secure Enterprise Browser (Prisma Access Browser),
including: system requirements, domains to allow, and IdP proxy requirements,.
Where Can I Use This?
What Do I Need?
Strata Cloud Manager
Standalone Prisma Access Browser
Prisma Access with Prisma Access Browser bundle license or
Prisma Access Browser standalone license
All the services listed below use SSL Pinning. These domains
must be excluded from SSL decryption on your gateway or proxy to ensure they
function correctly.
The Prisma Access Browser communicates with the following domains:
If your organization is not able to use an all-encompassing URL, enter the
following URLs:
Palo Alto Networks highly recommends that the
https://*.talon-sec.com entry be used as a network
requirement.
There is no guarantee that this list will not change. URLs may be modified and
additional services may be added in the future.
Policy service
https://gateway.talon-sec.com
Device service
https://gateway.talon-sec.com
Event ingestion service
https://gateway.talon-sec.com
Login service
https://login.talon-sec.com
Login proxy service
https://ext-proxy.talon-sec.com
Sync service
https://gateway.talon-sec.com
Vault service
https://gateway.talon-sec.com
Static assets service
https://assets.talon-sec.com
Onboarding service
https://auth.talon-sec.com
User requests service
https://gateway.talon-sec.com
Malware protection
https://riskapi.talon-sec.com
Updates service
https://bfe078e7921507bb.talon-sec.com
https://updates.talon-sec.com
Crash reporting
https://gateway.talon-sec.com
Browser Engine
https://extensions.talon-sec.com
IdP Proxy Requirements
The IdP Proxy prevents applications from using the Prisma Access Browser.
To enable the proxy to function, your firewall/proxy must allow access to the
following IP addresses.
Ingress IP addresses - traffic will flow into the proxy through:
https://idp-proxy.talon-sec.com
This FQDN resolves to the following IP addresses:
13.248.159.237
76.223.24.47
Egress IP addresses- Traffic will flow out of the proxy through:
If your Prisma Access Browser tenant is located in the
US:
If your Prisma Access Browser tenant is located in the
EU: