This is how you use Explicit Proxy to access resources in your data
center.
| Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Strata Cloud Manager)
- Prisma Access (Managed by Panorama)
|
- (For ZTNA Connector and Colo-Connect) Prisma Access
5.2.1 version
- (For service connections) Prisma Access 5.0 version
- (For private and partner app access) GlobalProtect
app
version 6.2 for Windows or macOS
|
Following RFC 6598 IP addresses aren't supported for Private application access
through Explicit Proxy via service connections, Colo-Connect, or ZTNA
Connector:
- 100.64.0.0/15
- 100.88.0.0/15
- 100.72.0.0/15
The existing ZTNA Connectors using these IP addresses in ZTNA Connector
Application IP blocks or Connector IP blocks are disabled from using Prisma Access Browser or GlobalProtect Agent in Proxy Mode through Explicit Proxy. You must
Reach out to your Palo Alto Networks representative to migrate your IP addresses
to a different block.
Private app access is not supported when traffic is coming from the IP address
that is a part of Trusted source IP address list.
Skip auth-bypass is not supported for private application domains. Hence, the
custom URL used for authentication flows must not contain private application
FQDNs.
Access Your Data Center Using Explicit Proxy (Strata Cloud Manager)
This is how you access your data center using Prisma Access Explicit Proxy in Strata Cloud Manager.
Configure a service connection,
Colo-Connect or
ZTNA Connector in
Prisma Access
based on your requirement.
Configure DNS settings. Ensure that the
DESTINATION
Zones for internet-bound traffic is set to
untrust instead of
any.
Failure to perform this step could
result in unintended access to your data center.
Go to , set the
Configuration Scope to , then select .
Open a rule for internet-bound traffic.
Ensure
Zones under
DESTINATION is set to
untrust.
Repeat for all of your internet-bound traffic rules.
Enable private application access.
- Enable private application access using Prisma Browser.
- Select and Enable
Prisma Browser. Under Proxy URL Settings,
select Enable Private App Access for Explicit
Proxy.
- Enable private application access using a regular browser.
- Select .
Create security policy rules for the data center resources you want to
access.
Go to , set the
Configuration Scope to , then select .
Create security policy
rules.
In rules for data center access, ensure
Zones under
DESTINATION is set to
trust.
If you enable Private Application Access under Explicit Proxy, Push
Config to save your configuration changes after onboarding the
ZTNA Connector.
Access Your Data Center Using Explicit Proxy (Panorama)
Access resources hosted in your data center using Prisma Access Explicit
Proxy.
Configure a service connection,
Colo-Connect or
ZTNA Connector in
Prisma Access
based on your requirement.
Configure DNS settings. Configure
zone mappings.
Select
Add the zones that you will use to access your data center resources to
Trusted Zones.
Ensure that the
Destination ZONE in policy rules
for internet-bound traffic is set to an untrust zone instead of
any.
Failure to perform this step could
result in unintended access to your data center.
Select .
Set the
Device Group to
Explicit_Proxy_Device_Group.
Change the
Destination ZONE from
any to one of the untrust zones you
configured in an earlier step.
Enable private application access.
- Enable private application access using Prisma Browser.
- Go to
- Enable private application access using a regular browser.
- Go to
Create security policy rules for the data center resources you want to
access.
Select .
Set the
Device Group to
Explicit_Proxy_Device_Group.
-