| Where Can I Use
This? | What Do I Need? |
Virtual Desktop Infrastructure (VDI) is a
technology that uses virtual machines to provision and manage virtual
desktops. VDI deploys desktop environments using a managed server
and deploys them to end-users on request. End-users access the resources
they need, such as public apps and resources that are internet-based
or private apps and resources available from an FTP connection,
from their provisioned VDI desktops.
A VDI topology can be
implemented using either shared or dedicated desktops. If the desktops
are shared, multiple users are behind a single IP address and ports
are used to differentiate the users.
If your
VDI deployment uses a shared desktop implementation,
Prisma Access
offers a solution that allows end users to securely access internet
and FTP resources using a single login, while protecting your organization’s
VDI users and internal and external resources. This solution uses
the Palo Alto Networks TS Agent that you
install on the VDI servers.
The
TS Agent is a User-ID software installed to solve the challenge
associated with identifying username-to-IP address mappings when
users share IP addresses. After the TS Agent is installed, all logged-on
users are monitored and individual users are assigned with a specific
set of ports. When Prisma Access receives this VDI network traffic
from the VDI, it identifies the user based on the User's source
port. This deployment provides you with a cloud-based solution that
allows administrators to create security policy rules for VDI end
users to control their access to internet and internal sites.
If
your network has a default route, you can onboard one or more remote
networks and implement the TS agent to easily and simply protect
the users and resources in your organization.
In this deployment:
You specify a port range on the TS agent to identify specific
users on Windows-based terminal servers. The TS agent notifies Prisma Access
of the allocated port ranges, so that Prisma Access can enforce
policy based on users and user groups.
The Remote Network enforces security and access control for
FTP and internet-based resources.
You
cannot redistribute user mapping information collected from a TS
Agent.
To integrate a VDI using the TS Agent and a Prisma Access remote network in Cloud
Managed Prisma Access, complete the following steps.