| Where Can I Use
This? | What Do I Need? |
To enable Prisma Access for users to enable
internet access only you do not need to set up any networking services
because Prisma Access provides a default IP address pool and a cloud
default DNS server.
However, if you want your mobile users
to be able to access internal resources at your headquarters, data
centers, or at remote network sites you have onboarded to Prisma
Access, you will need to:
define
the IP address pools Prisma Accesses uses to assign IP addresses
to your mobile users,
set up the Prisma Access service infrastructure,
and, to allow access to your headquarters or data centers,
onboard service connections.
If you want your mobile
users to connect to remote network sites, you must configure at
least one service connection, even if you do not plan on using the
connection to provide access to your data center or HQ locations.
Though all branches are fully meshed, mobile user connections are
not. Creating a service connection establishes the hub-and-spoke
architecture required to enable mobile user traffic to route to
your branch networks. In this case, you can minimally configure
the service connection as follows:
When you set up the primary IPSec tunnel for the service
connection, configure the IPSec peer authentication and tunnel settings
using placeholder values.
When you enable routing and QoS for the service connection,add
placeholder IP subnets.
Because Prisma Access does not route
any traffic through this tunnel, just make sure the IP subnet you
use doesn’t conflict or overlap with other configured subnets connected
to Prisma Access.