Here's how you can configure downstream proxy chaining with third-party proxy using
Prisma Access explicit proxy.
| Where Can I Use This? | What Do I Need? |
Prisma Access proxy chaining feature enables you to securely integrate your Prisma Access explicit proxy setup with another proxy in a seamless and
sequential manner. Enterprises utilize proxy chaining to integrate their current
proxy infrastructure or to meet compliance requirements. Here, the Prisma Access
explicit proxy functions as a downstream proxy to the other proxies. To configure
proxy chaining, you create profiles with the upstream proxy server’s IPv4 address or
FQDN that resolve to a IPv4 address and create rules to define the criteria to route
traffic through upstream proxy servers.
With proxy chaining feature you can route traffic to another proxy based on the users
source IP address, users or user-groups, and URL category. You can also share
X-Forwarded-For (XFF) and X-Authenticated-User (XAU) headers with upstream proxy
servers.
When you want to proxy chain the traffic from Prisma Access explicit proxy to
another proxy, Prisma Access explicit proxy authenticates users and passes the
username to another proxy using XAU header insertion (username in base64 format) and
the source IP address using the XFF header insertion. To chain to a proxy located
inside the data center, GlobalProtect agent and connectivity from Prisma Access
to the data center is needed.
Supported Methods to Connect
Prerequisites