Configure Quarantine List Redistribution in Prisma Access
Focus
Focus

Prisma Access

Configure Quarantine List Redistribution in Prisma Access

Table of Contents

Configure Quarantine List Redistribution in Prisma Access

Configure the quarantine list feature for Panorama Managed Prisma Access mobile user (GlobalProtect) deployments.
Where Can I Use This?
What Do I Need?
  • Prisma Access (Panorama Managed)
  • Prisma Access (Cloud Management)
To redistribute quarantine information to and from service connections, the Panorama that manages Prisma Access, and next-generation firewalls, complete the following steps.
  1. Make sure that the Panorama management IP address is able to communicate with the User-ID agent address for all service connections to which you want to redistribute quarantine list information.
    Communication between the User-ID Agent address of the service connection and the management IP address of Panorama is required for Prisma Access to send and receive quarantine list information between Panorama and the service connections.
    • To find the
      User-ID Agent Address
      , select
      Panorama
      Cloud Services
      Status
      Network Details
      Service Connection
      User-ID Agent Address
      .
    • To find the management IP address of the Panorama that manages Prisma Access, note the IP address that displays in the web browser when you access Panorama.
  2. Allow Prisma Access to redistribute quarantine list information.
    1. In Panorama, select
      Panorama
      Cloud Services
      Configuration
      Service Setup
      .
    2. Click the gear icon to edit the settings.
    3. In the
      Advanced
      tab, select
      Enable Quarantine List Redistribution
      .
      Enabling quarantine list redistribution allows Prisma Access to redistribute the quarantine list information received from one or more mobile user locations (gateways) to service connections.
  3. Commit
    and
    Push
    your changes.
  4. Configure Panorama to receive quarantine list information from Prisma Access by configuring management interface settings.
    1. In the Panorama that manages Prisma Access, select
      Panorama
      Setup
      Interfaces
      .
    2. Select the
      Management
      interface.
    3. Select
      User-ID
      .
  5. Configure a data redistribution agent that redistributes quarantine list information from the service connections to Panorama.
    1. From the Panorama that manages Prisma Access, select
      Panorama
      Cloud Services
      Status
      Network Details
      Service Connection
      .
    2. Make a note of the
      User-ID Agent Address
      (
      Panorama
      Cloud Services
      Status
      Network Details
      Service Connection
      User-ID Agent Address
      ) for each service connection.
    3. Select
      Panorama
      Data Redistribution
      Agents
      .
    4. Add
      a Data Redistribution agent, give it a
      Name
      and select
      Enabled
      .
    5. Enter the
      User-ID Agent Address
      of the service connection as the
      Host
      and 5007 as the
      Port
      .
      Make sure that your network does not block access to this port between Panorama and Prisma Access.
    6. (
      Optional
      ) If you have configured this service connection as a Collector (
      Device
      Data Redistribution
      Collector Settings
      ), enter the
      Collector Name
      and
      Collector Pre-Shared Key
    7. Select
      Quarantine List
      ; then, click
      OK
      .
    8. Repeat Step 5 for all the service connections in your Prisma Access deployment.
  6. Select
    Commit
    Commit to Panorama
    to save your changes locally on the Panorama that manages Prisma Access.
  7. Configure a data redistribution agent that redistributes quarantine list information from Panorama to the service connections.
    1. Find the management IP address of the Panorama that manages Prisma Access.
      This address displays by in the web browser address bar when you access Panorama.
    2. Make sure that you are in the
      Service_Conn_Template
      template, then select
      Device
      Data Redistribution
      Agents
      .
    3. Add
      a Data Redistribution agent, give it a
      Name
      and select
      Enabled
      .
    4. Enter the management IP address of the Panorama appliance. as the
      Host
      and 5007 as the
      Port
      .
    5. Select
      Quarantine List
      ; then, click
      OK
      .
  8. Configure a data redistribution agent that redistributes quarantine list information from the service connections to mobile user gateways.
    1. From the Panorama that manages Prisma Access, select
      Panorama
      Cloud Services
      Status
      Network Details
      Service Connection
      .
    2. Make a note of the
      User-ID Agent Address
      of the service connection from which you want to redistribute quarantine list information.
      Since all service connections have the same redistributed quarantine list information, choose any service connection. You can also configure more than one service connection.
    3. Make sure that you are in the
      Mobile_User_Template
      , then select
      Device
      Data Redistribution
      Agents
      .
    4. Add
      a Data Redistribution agent, give it a
      Name
      , and select
      Enabled
      .
    5. Enter the
      User-ID Agent Address
      of the service connection as the Host and
      5007
      as the Port.
      Make sure that your network does not block access to this port between Panorama and Prisma Access.
    6. (
      Optional
      ) If you have configured this service connection as a Collector (
      Device
      Data Redistribution
      Collector Settings
      ), enter the
      Collector Name
      and
      Collector Pre-Shared Key
      .
    7. Select
      Quarantine List
      ; then, click
      OK
      .
    8. Commit and Push
      your changes.
  9. View your quarantine list information by selecting
    Panorama
    Device Quarantine
    .

Recommended For You