Create Common Policies for App Acceleration and Private App Security
Focus
Focus
Prisma Access

Create Common Policies for App Acceleration and Private App Security

Table of Contents

Create Common Policies for App Acceleration and Private App Security

Use the Policies section in Application Settings to configure policies that are common to App Acceleration and Private App Security.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
App Acceleration requires:
  • A minimum Prisma Access version of 5.0 Innovation
  • A Prisma Access dataplane version of 11.2.7 or later
  • App Acceleration Add-on License
App Security requires:
App Acceleration and Private App Security utilize a shared policy framework that allows administrators to selectively accelerate and/or inspect traffic on a port and IP/subnet/port basis.
Using Network Policies, administrators have granular control over which traffic is accelerated or secured.
Network Policies are configurable in Strata Cloud Manager under the App Edge Configuration page.
To configure these common policies, complete the following workflow.
These policies apply to both Private App Security and App Acceleration functionality. The usage of these policies can prevent Private App Security inspection of traffic for the destinations you've configured and could lead to changes in the application security posture. However, any policies you've created for mobile users or remote networks at their respective Security Processing Nodes (SPNs) still apply to the traffic for which you've configured these policies.
  1. Go to ConfigurationApplication ServicesApp Edge ConfigurationPolicies.
  2. Confirm that you have read and acknowledged the disclaimer that enabling these policies might lead to changes in your application security posture for Private App Security.
  3. (Optional) Configure one or more one or more of the Network Policies.
    Selective Acceleration by Port will only be visible if your Prisma Access tenant has the App Acceleration license.
    • Selective Acceleration by Port—Specify the ports to include or exclude for App Acceleration.
      Selective Acceleration by Port lets you specify which network traffic applies for App Acceleration based on destination server ports. This granular control lets you boost application performance while leaving other traffic unaffected. By default, all traffic is enabled (for App Acceleration) and can be will be inspected when using Private App Security.
    When you use Selective Acceleration by port, make a note of the following guidelines:
    • If accelerating SaaS apps with App Acceleration, you must include port 443 in the accelerated ports in order to boost SaaS apps.
    • If you are using Private App Security with App Acceleration and have defined an app with custom ports, you must include those ports for the defined app traffic to be secured. When using App Security, destination ports (default 443, or custom ports) for configured applications must be included in the accelerated ports. Excluding ports from App Acceleration prevents Private App Security traffic inspection.
    • To select the ports to accelerate, enter a single port, multiple ports using commas between the ports, a range of ports using dashes, or any combination of the preceding entries. App Acceleration accelerates the traffic for those ports. The ports that App Acceleration excludes display in the Excluded Ports area.
    • To select the ports to exclude from acceleration, Switch to invert selection and enter the ports to exclude. App Acceleration accelerates every port you do not select.
    • To revert your changes to the last saved setting or the original default setting, select Revert.
      Policy Slots: Administrators have access to a maximum of 10 policy slots for Network Policies. The AWS FSx Multi-AZ Access Policy reserves one policy slot.
    • AWS FSx Multi-AZ Access Policy—If you use AWS FSx for Windows File Server using multiple Availability Zones (multi-AZ), move the slider to enable App Acceleration compatibility with the FSx round robin DNS behavior. Optionally, you can enter Destination Port(s) and a Destination IP / Subnet to apply scope the AWS FSx policy to only selected traffic.
      One policy slot is reserved for the AWS FSx Multi-AZ Access Policy. See the information about IP/Subnet/Port based Exclusion policies in this section for details.
    • Multipath TCP Bypass—If you use apps with multipath TCP (MPTCP), you can use this slider so that MPTCP traffic bypasses App Acceleration and/or Private App Security. Bypassed traffic will not be inspected by Private App Security.
    • IP/Subnet/Port based Exclusion Policies and Policy Slots—If you want to exclude traffic from App Acceleration and Private App Security based on destination ports, IP subnets, or both, specify the IP and/or subnets, ports, or both here. By default, all traffic is enabled (for App Acceleration) and configured private app traffic will be inspected by Private App Security.
      To add an exclusion, click Add to add a rule and give it a unique name and, optionally, the source port, IP subnets, and destination ports to exclude. Move the Status slider to the right to activate this rule.
      • A maximum of 9 exclusion policy slots are available to administrators. (The AWS FSx Multi-AZ policy reserves 1 network policy slot, for a total of 10 policies supported.)
      • Each exclusion policy supports a maximum of 25 Source Ports/ranges, 25 Destination IP/Subnets and 25 Destination Ports/ranges for a total of 75 entries per exclusion policy.
      • Exclusion policies are evaluated in order from top to bottom. Use the Move button to change the order of evaluation.
      • After activating/deactivating an exclusion policy, allow up to 15 minutes for the new settings to take effect on your Prisma Access.
      Any traffic you exclude here will also exclude apps from those ports and subnets from Private App Security app discovery and security inspection.