The following diagram illustrates a typical use case for the Prisma Access
DDNS solution. In this example, you want to update GlobalProtect endpoints using
MECM or would like the IT help desk to be able to log in to the GlobalProtect
endpoint remotely for troubleshooting.
- GlobalProtect establishes an SSL tunnel between the GlobalProtect endpoint
the Prisma Access gateway.
- GlobalProtect sends the mobile user device’s hostname, domain name, and
tunnel IP address information through the tunnel to the on-premises or Prisma Access gateway.
- Prisma Access provides DDNS updates of A and PTR records using nsupdate
to the DNS server. Prisma Access provides these secure updates in
real-time when it processes login and logout events.
- The IT administrator or an enterprise software uses these records through a
DNS or RDNS lookup and resolves the endpoint name or IP address.
- The IT administrator or the endpoint management software uses this
information to manage the endpoint or push software updates.