1. Home
Location
    Techdocs Logo Techdocs Logo
    • Documentation Home
    • Palo Alto Networks
    • Support
    • Live Community
    • Knowledge Base
    1. Home
    2. Prisma Access
    3. Prisma Access Administration
    4. Prisma Access ZTNA Connector
    5. Configure ZTNA Connector
    Download PDF
    Last Updated:
    May 22, 2023
    Current Version:
    4.0 Preferred
    • Version 4.0 Preferred

    Table of Contents


    Filter icon
    Filter
    Prisma Access Overview
    How To Manage Prisma Access
    How To Manage Prisma Access (Cloud Management)
    How to Manage Prisma Access (Panorama)
    Visibility Features in the Prisma Access App
    Prisma Access Locations
    Prisma Access Locations by Compute Location
    Prisma Access Locations by Theater and Location Group
    Prisma Access Locations by Region
    Map of North America Prisma Access Locations
    Explicit Proxy Locations
    Prisma Access Infrastructure Management
    Prisma Access APIs
    Prisma Access APIs (Cloud Management)
    Prisma Access APIs (Panorama)
    Your Prisma Access License
    Validate Your License
    Validate Your Prisma Access License (Cloud Management)
    Validate Your Prisma Access License (Panorama)
    All Available Apps and Services
    Cheat Sheet: ADEM with Prisma Access
    Cheat Sheet: IoT with Prisma Access
    Cheat Sheet: Enterprise DLP with Prisma Access
    Cheat Sheet: Enterprise DLP with Prisma Access (Cloud Management)
    Cheat Sheet: Enterprise DLP with Prisma Access (Panorama)
    Cheat Sheet: SaaS Security with Prisma Access
    Cheat Sheet: SaaS Security with Prisma Access (Cloud Management)
    Cheat Sheet: SaaS Security with Prisma Access (Panorama)
    Cheat Sheet: URL Filtering with Prisma Access
    Make Changes To Your License
    Reset Your Prisma Access License
    Transfer Or Update Your License
    Verify Your Prisma Access Account
    Prisma Access Releases and Upgrades
    Prisma Access Release Types
    Prisma Access Release Types (Cloud Management)
    Prisma Access Release Types (Panorama)
    Prisma Access Upgrade Types
    Prisma Access Upgrade Types (Cloud Management)
    Prisma Access Upgrade Types (Panorama)
    Cadence for Software and Content Updates for Prisma Access
    Cadence for Software and Content Updates for Prisma Access (Cloud Management)
    Cadence for Software and Content Updates for Prisma Access (Panorama)
    Prisma Access Dataplane Upgrades
    Get Upgrade Alerts and Updates
    View Prisma Access Software Versions
    View Prisma Access Software Versions (Cloud Management)
    View Prisma Access Software Versions (Panorama)
    Activate Your Prisma Access License
    Activate Your Prisma Access License (Cloud Management)
    Activate Your Prisma Access License (Panorama)
    Prisma Access Setup
    Set Up Prisma Access
    Set Up Prisma Access (Cloud Management)
    Set Up Prisma Access (Panorama)
    Prisma Access Infrastructure Subnet Requirements
    Configure the Prisma Access Service Infrastructure
    Prisma Access Service Infrastructure (Cloud Management)
    Prisma Access Service Infrastructure (Panorama)
    Mobile Users: IP Address Allocation
    Example: Public IP Address Scaling Examples (Mobile Users)
    Loopback IP Address Allocation (Mobile Users)
    Remote Networks: IPSec Termination Nodes and Service IP Addresses
    Remote Networks: IP Address Changes Related To Bandwidth Allocation
    Remote Networks: Service IP and Egress IP Address Allocation
    Retrieve the IP Addresses for Prisma Access
    Retrieve the IP Addresses for Prisma Access (Cloud Management)
    Retrieve the IP Addresses for Prisma Access (Panorama)
    API Examples for Retrieving Prisma Access IP Addresses
    Get Notifications When Prisma Access IP Addresses Change
    Use Legacy Scripts to Retrieve IP Addresses
    Retrieve Mobile User IP Addresses
    Retrieve Public, Loopback, and Egress IP Addresses
    Prisma Access Zones
    DNS for Prisma Access
    DNS for Prisma Access (Cloud Management)
    DNS for Prisma Access (Panorama)
    High Availability for Prisma Access
    Predefined Templates: Onboard a Service Connection or Remote Network
    Supported IKE and IPSec Cryptographic Profiles for Common SD-WAN Devices
    Prisma Access Service Connections
    Plan a Service Connection
    Configure a Service Connection
    Configure a Service Connection (Cloud Management)
    Configure a Service Connection (Panorama)
    Verify Service Connection Status
    Verify Service Connection Status (Cloud Management)
    Verify Service Connection Status (Panorama)
    Use a Service Connection to Enable Access between Mobile Users and Remote Networks
    Dynamic Routing Considerations for Service Connections
    Prisma Access Colo-Connect (Preview)
    Prisma Access Mobile Users
    Mobile Users: GlobalProtect
    Planning Checklist for GlobalProtect on Prisma Access
    Set Up GlobalProtect Mobile Users
    Set Up GlobalProtect Mobile Users (Cloud Management)
    Set Up GlobalProtect Mobile Users (Panorama)
    GlobalProtect Features for Prisma Access
    GlobalProtect — Customize Tunnel Settings
    Ticket Request to Disable GlobalProtect
    GlobalProtect Pre-Logon
    GlobalProtect — Customize App Settings
    Monitor GlobalProtect Mobile Users
    Monitor GlobalProtect Mobile Users (Cloud Management)
    Monitor GlobalProtect Mobile Users (Panorama)
    IP Address Pools for a GlobalProtect Mobile Users Deployment
    How the GlobalProtect App Selects Prisma Access Locations for Mobile Users
    Allow Listing GlobalProtect Mobile Users
    Allow Listing GlobalProtect Mobile Users (Cloud Management)
    Allow Listing GlobalProtect Mobile Users (Panorama)
    GlobalProtect App Upgrades
    Select the Active GlobalProtect App Version for Prisma Access
    Select the Active GlobalProtect App Version for Prisma Access (Cloud Management)
    Select the Active GlobalProtect App Version for Prisma Access (Panorama)
    Allow Users to Upgrade the GlobalProtect App
    Allow Users to Upgrade the GlobalProtect App (Cloud Management)
    Allow Users to Upgrade the GlobalProtect App (Panorama)
    Stagger GlobalProtect App Updates
    Integrate Prisma Access with On-Premises GlobalProtect Gateways
    Setting Priority for Prisma Access and On-Premises Gateways
    Mobile Users: Explicit Proxy
    How Explicit Proxy Works
    Explicit Proxy — Guidelines
    Set Up Explicit Proxy
    Set Up Explicit Proxy (Cloud Management)
    Set Up Explicit Proxy (Panorama)
    Cloud Identity Engine Authentication for Explicit Proxy Deployments
    Cloud Identity Engine Authentication for Explicit Proxy Deployments (Cloud Management)
    Cloud Identity Engine Authentication for Explicit Proxy Deployments (Panorama)
    Monitor and Troubleshoot Explicit Proxy
    Monitor and Troubleshoot Explicit Proxy (Cloud Management)
    Monitor and Troubleshoot Explicit Proxy (Panorama)
    Block Settings for Explicit Proxy
    Use Special Objects to Restrict Explicit Proxy Internet Traffic to Specific IP Addresses
    Use Explicit Proxy with GlobalProtect (or a Third-Party VPN)
    Requirements for Using Explicit Proxy with GlobalProtect or a Third-Party VPN
    Explicit Proxy and GlobalProtect: How It Works
    Explicit Proxy and GlobalProtect: Set It Up
    Explicit Proxy and GlobalProtect: Set It Up (Cloud Management)
    Explicit Proxy and GlobalProtect: Set It Up (Panorama)
    Explicit Proxy with Third Party VPNs
    Secure Users and Devices at Remote Networks With an Explicit Proxy
    Secure Users and Devices at Remote Networks With an Explicit Proxy (Cloud Management)
    Secure Users and Devices at Remote Networks With an Explicit Proxy (Panorama)
    App-Based Office 365 Integration with Explicit Proxy
    App-Based Office 365 Integration with Explicit Proxy (Cloud Management)
    App-Based Office 365 Integration with Explicit Proxy (Panorama)
    Kerberos Authentication for Explicit Proxy Deployments
    Requirements and Recommendations for Deploying Kerberos for Explicit Proxy Deployments
    Create a Kerberos Keytab
    Configure Kerberos Authentication for Explicit Proxy Deployments
    Cloud Management
    Panorama
    GlobalProtect in Proxy Mode
    GlobalProtect in Proxy Mode (Cloud Management)
    GlobalProtect in Proxy Mode (Panorama)
    GlobalProtect in Tunnel and Proxy Mode
    GlobalProtect in Tunnel and Proxy Mode (Cloud Management)
    GlobalProtect in Tunnel and Proxy Mode (Panorama)
    Report Mobile User Site Access Issues
    Enable Mobile Users to Authenticate to Prisma Access
    Authentication Support and Features
    Set Up Authentication
    Prisma Access Remote Networks
    Planning Checklist for Remote Networks
    Allocate Remote Network Bandwidth
    Allocate Remote Network Bandwidth (Cloud Management)
    Allocate Remote Network Bandwidth (Panorama)
    Plan Your Migration to the New Model
    Migrate Your Bandwidth Management Settings
    Migrate Your Bandwidth Management Settings (Cloud Management)
    Migrate Your Bandwidth Management Settings (Panorama)
    Onboard a Remote Network
    Onboard a Remote Network (Cloud Management)
    Onboard a Remote Network (Panorama)
    Connect a Remote Network Site to Prisma Access
    Enable Routing for Your Remote Network
    Onboard Multiple Remote Networks
    Verify if Remote Network Site is Connected to Prisma Access
    Verify a Remote Network Site is Connected to Prisma Access (Cloud Management)
    Verify a Remote Network Site is Connected to Prisma Access (Panorama)
    Verify Remote Connection BGP Status
    Configure Remote Network and Service Connection Connected with a WAN Link
    QoS for Remote Networks
    Configure QoS (Cloud Management)
    Configure QoS (Panorama)
    Change the Guaranteed Bandwidth
    Integrate a Shared Desktop VDI with Prisma Access Using Terminal Server
    Prisma Access ZTNA Connector
    ZTNA Connector Requirements and Guidelines
    Certificate Management
    Enable ZTNA Connector
    Cloud Management
    Panorama
    Configure ZTNA Connector
    Set Up Auto Discovery of Applications Using Cloud Identity Engine
    Security Policy for Apps Enabled with ZTNA Connector
    Cloud Management
    Panorama
    Onboard the ZTNA Connector VM in Your Data Center
    Microsoft Azure Deployments Supported by ZTNA Connector
    Onboard a ZTNA Connector in Microsoft Azure
    Google Cloud Platform Deployments Supported by ZTNA Connector
    Onboard a ZTNA Connector in Google Cloud Platform
    Amazon Web Services Deployments Supported by ZTNA Connector
    Onboard a ZTNA Connector in Amazon Web Services
    VMware ESXi Deployment Supported by Prisma Access ZTNA Connector
    Onboard a ZTNA Connector in VMware ESXi
    Monitor ZTNA Connector
    ZTNA Connector Logs
    ZTNA Connector Audit Logs
    ZTNA Connector Traffic Logs
    ZTNA Connector Config Logs
    View ZTNA Connector Logs
    View ZTNA Connector Logs (Cloud Managed)
    View ZTNA Connector Logs (Panorama Managed)
    Prisma Access Monitoring and Visibility
    Prisma Access Logs
    Prisma Access Logs (Cloud Management)
    Prisma Access Logs (Panorama)
    Prisma Access Activity Dashboards and Reports
    Prisma Access Insights
    Prisma Access and Autonomous DEM
    Prisma Access User-Based Policy
    Integrate Cloud Identity Engine with Prisma Access
    Integrate Cloud Identity Engine with Prisma Access (Cloud Management)
    Integrate Cloud Identity Engine with Prisma Access (Panorama)
    Configure User-Based Policy for Prisma Access
    Configure User-Based Policy for Prisma Access (Cloud Management)
    Configure User-Based Policy for Prisma Access (Panorama)
    Retrieve User-ID Group Mappings for Prisma Access
    Populate User Group Names in Security Policy Rules Using the Cloud Identity Engine
    Populate User Group Names in Security Policy Rules Using a Master Device
    Use Long-Form DN Entries to Implement User- and Group-Based Policy
    Identity Redistribution
    Redistribute Identity Data (Cloud Management)
    Redistribute Identity Data (Panorama)
    Prisma Access Multi-Tenancy
    Multitenancy Configuration Overview
    Plan Your Multitenant Deployment
    Create an All-New Multitenant Deployment
    Enable Multitenancy and Migrate the First Tenant
    Add Tenants to Prisma Access
    Delete a Tenant
    Create a Tenant-Level Administrative User
    Control Role-Based Access for Tenant-Level Administrative Users
    Remove Plugin Access for a Tenant-Level Administrative User
    Sort Logs by Device Group ID in a Multitenant Deployment
    Prisma Access in a FedRAMP Environment
    Prisma Access FedRAMP Requirements
    Configure Prisma Access in a FedRAMP Environment
    Prisma Access Advanced Deployments
    Add a New Compute Location for a Deployed Prisma Access Location
    IPv6 Support for Private App Access
    Enable and Configure IPv6 Networking and IP Pools in Your Prisma Access Infrastructure
    Enable IPv6 Networking for a Mobile Users—GlobalProtect Deployment
    Enable IPv6 Networking for Service Connections
    Enable IPv6 Networking for Remote Networks
    DNS Resolution for Mobile Users—GlobalProtect and Remote Network Deployments
    DNS Resolution for Mobile Users—GlobalProtect Deployments
    DNS Resolution for Remote Networks
    How BGP Advertises Mobile User IP Address Pools for Service Connections and Remote Network Connections
    Proxy Support for Prisma Access and Cortex Data Lake
    Prisma Access Service Connection Advanced Deployments
    Service Connection Multi-Cloud Redundancy
    Configure and Activate Service Connection Cloud Provider Redundancy
    Supported In-Country Active and Backup Cloud Provider Redundancy Locations
    Use Traffic Steering to Forward Internet-Bound Traffic to Service Connections
    Default Routes With Prisma Access Traffic Steering
    Traffic Steering in Prisma Access
    Traffic Steering Requirements
    Default Routes with Traffic Steering Example
    Default Routes with Traffic Steering Direct to Internet Example
    Default Routes with Traffic Steering and Dedicated Service Connection Example
    Prisma Access Traffic Steering Rule Guidelines
    Configure Zone Mapping and Security Policies for Traffic Steering Dedicated Connections
    Configure Traffic Steering in Prisma Access
    Routing for Service Connection Traffic
    Mobile User and Remote Network Routing to Service Connections
    Prisma Access Default Routing
    Prisma Access Hot Potato Routing
    Configure Routing Preferences
    Create a High-Bandwidth Network Using Multiple Service Connections
    Create a High-Bandwidth Connection to a Headquarters or Data Center Location
    Configure More than Two Service Connections to a Headquarters or Data Center Location
    Prisma Access Mobile Users—GlobalProtect Advanced Deployments
    Configure Multiple Portals in Prisma Access
    Configure Multiple Portals in Prisma Access (Cloud Management)
    Configure Multiple Portals in Prisma Access (Panorama)
    Dynamic DNS Registration Support for Mobile Users—GlobalProtect
    Enable DDNS for Mobile Users—GlobalProtect
    Verify Dynamic DNS Configuration
    Identification and Quarantine of Compromised Devices in a Prisma Access GlobalProtect Deployment
    Use Cases for Quarantine List Redistribution
    Configure Quarantine List Redistribution in Prisma Access
    Sinkhole IPv6 Traffic In Mobile Users—GlobalProtect Deployments
    Configure GlobalProtect to Disable Direct Access to the Local Network
    Set Up an IPv6 Sinkhole On the On-Premises Gateway
    Redistribute HIP Information with Prisma Access
    HIP Redistribution Overview
    Use Cases for HIP Redistribution
    Configure HIP Redistribution in Prisma Access
    Configure HIP Redistribution in Prisma Access (Cloud Management)
    Configure HIP Redistribution in Prisma Access (Panorama)
    View HIP Reports
    Support for Gzip Encoding in Clientless VPN
    Prisma Access Remote Network Advanced Deployments
    Provide Secure Inbound Access to Remote Network Locations
    Secure Inbound Access for Remote Network Sites
    Secure Inbound Access Examples
    Guidelines for Using Secure Inbound Access
    Configure Secure Inbound Access for Remote Network Sites
    Configure Secure Inbound Access for Remote Network Sites for Locations that Allocate Bandwidth by Location
    Configure Secure Inbound Access for Remote Network Sites
    Create a High-Bandwidth Network for a Remote Site
    Create a High-Bandwidth Remote Network Connection
    Prisma Access for Clean Pipe
    Prisma Access for Clean Pipe Overview
    Clean Pipe Use Cases
    Clean Pipe Examples
    Clean Pipe and Partner Interconnect Requirements
    Complete the Clean Pipe Configuration
    Enable Multitenancy and Create a Tenant
    • Prisma Access Overview
      • How To Manage Prisma Access
      • Visibility Features in the Prisma Access App
      • Prisma Access Locations
      • Prisma Access Infrastructure Management
      • Prisma Access APIs
    • Your Prisma Access License
      • Validate Your License
      • All Available Apps and Services
        • Cheat Sheet: ADEM with Prisma Access
        • Cheat Sheet: IoT with Prisma Access
        • Cheat Sheet: Enterprise DLP with Prisma Access
        • Cheat Sheet: SaaS Security with Prisma Access
        • Cheat Sheet: URL Filtering with Prisma Access
      • Make Changes To Your License
        • Reset Your Prisma Access License
        • Transfer Or Update Your License
      • Verify Your Prisma Access Account
    • Prisma Access Releases and Upgrades
      • Prisma Access Release Types
      • Prisma Access Upgrade Types
      • Cadence for Software and Content Updates for Prisma Access
      • Prisma Access Dataplane Upgrades
      • Get Upgrade Alerts and Updates
      • View Prisma Access Software Versions
    • Activate Your Prisma Access License
    • Prisma Access Setup
      • Set Up Prisma Access
      • Prisma Access Infrastructure Subnet Requirements
      • Configure the Prisma Access Service Infrastructure
      • Mobile Users: IP Address Allocation
        • Example: Public IP Address Scaling Examples (Mobile Users)
        • Loopback IP Address Allocation (Mobile Users)
      • Remote Networks: IPSec Termination Nodes and Service IP Addresses
      • Remote Networks: IP Address Changes Related To Bandwidth Allocation
      • Remote Networks: Service IP and Egress IP Address Allocation
      • Retrieve the IP Addresses for Prisma Access
      • API Examples for Retrieving Prisma Access IP Addresses
      • Get Notifications When Prisma Access IP Addresses Change
      • Use Legacy Scripts to Retrieve IP Addresses
        • Retrieve Mobile User IP Addresses
        • Retrieve Public, Loopback, and Egress IP Addresses
      • Prisma Access Zones
      • DNS for Prisma Access
      • High Availability for Prisma Access
      • Predefined Templates: Onboard a Service Connection or Remote Network
        • Supported IKE and IPSec Cryptographic Profiles for Common SD-WAN Devices
    • Prisma Access Service Connections
      • Plan a Service Connection
      • Configure a Service Connection
      • Verify Service Connection Status
      • Use a Service Connection to Enable Access between Mobile Users and Remote Networks
      • Dynamic Routing Considerations for Service Connections
      • Prisma Access Colo-Connect (Preview)
    • Prisma Access Mobile Users
      • Mobile Users: GlobalProtect
        • Planning Checklist for GlobalProtect on Prisma Access
        • Set Up GlobalProtect Mobile Users
        • GlobalProtect Features for Prisma Access
          • GlobalProtect — Customize Tunnel Settings
          • Ticket Request to Disable GlobalProtect
        • GlobalProtect Pre-Logon
        • GlobalProtect — Customize App Settings
        • Monitor GlobalProtect Mobile Users
        • IP Address Pools for a GlobalProtect Mobile Users Deployment
        • How the GlobalProtect App Selects Prisma Access Locations for Mobile Users
        • Allow Listing GlobalProtect Mobile Users
        • GlobalProtect App Upgrades
          • Select the Active GlobalProtect App Version for Prisma Access
          • Allow Users to Upgrade the GlobalProtect App
          • Stagger GlobalProtect App Updates
        • Integrate Prisma Access with On-Premises GlobalProtect Gateways
          • Setting Priority for Prisma Access and On-Premises Gateways
      • Mobile Users: Explicit Proxy
        • How Explicit Proxy Works
        • Explicit Proxy — Guidelines
        • Set Up Explicit Proxy
        • Cloud Identity Engine Authentication for Explicit Proxy Deployments
        • Monitor and Troubleshoot Explicit Proxy
        • Block Settings for Explicit Proxy
        • Use Special Objects to Restrict Explicit Proxy Internet Traffic to Specific IP Addresses
        • Use Explicit Proxy with GlobalProtect (or a Third-Party VPN)
          • Requirements for Using Explicit Proxy with GlobalProtect or a Third-Party VPN
          • Explicit Proxy and GlobalProtect: How It Works
          • Explicit Proxy and GlobalProtect: Set It Up
          • Explicit Proxy with Third Party VPNs
        • Secure Users and Devices at Remote Networks With an Explicit Proxy
        • App-Based Office 365 Integration with Explicit Proxy
        • Kerberos Authentication for Explicit Proxy Deployments
          • Requirements and Recommendations for Deploying Kerberos for Explicit Proxy Deployments
          • Create a Kerberos Keytab
          • Configure Kerberos Authentication for Explicit Proxy Deployments
        • GlobalProtect in Proxy Mode
        • GlobalProtect in Tunnel and Proxy Mode
      • Report Mobile User Site Access Issues
      • Enable Mobile Users to Authenticate to Prisma Access
        • Authentication Support and Features
        • Set Up Authentication
    • Prisma Access Remote Networks
      • Planning Checklist for Remote Networks
      • Allocate Remote Network Bandwidth
      • Plan Your Migration to the New Model
        • Migrate Your Bandwidth Management Settings
      • Onboard a Remote Network
      • Connect a Remote Network Site to Prisma Access
      • Enable Routing for Your Remote Network
      • Onboard Multiple Remote Networks
      • Verify if Remote Network Site is Connected to Prisma Access
        • Verify Remote Connection BGP Status
      • Configure Remote Network and Service Connection Connected with a WAN Link
      • QoS for Remote Networks
        • Change the Guaranteed Bandwidth
      • Integrate a Shared Desktop VDI with Prisma Access Using Terminal Server
    • Prisma Access ZTNA Connector
      • ZTNA Connector Requirements and Guidelines
        • Certificate Management
      • Enable ZTNA Connector
      • Configure ZTNA Connector
      • Set Up Auto Discovery of Applications Using Cloud Identity Engine
      • Security Policy for Apps Enabled with ZTNA Connector
      • Onboard the ZTNA Connector VM in Your Data Center
        • Microsoft Azure Deployments Supported by ZTNA Connector
          • Onboard a ZTNA Connector in Microsoft Azure
        • Google Cloud Platform Deployments Supported by ZTNA Connector
          • Onboard a ZTNA Connector in Google Cloud Platform
        • Amazon Web Services Deployments Supported by ZTNA Connector
          • Onboard a ZTNA Connector in Amazon Web Services
        • VMware ESXi Deployment Supported by Prisma Access ZTNA Connector
          • Onboard a ZTNA Connector in VMware ESXi
      • Monitor ZTNA Connector
      • ZTNA Connector Logs
        • ZTNA Connector Audit Logs
        • ZTNA Connector Traffic Logs
        • ZTNA Connector Config Logs
        • View ZTNA Connector Logs
    • Prisma Access Monitoring and Visibility
      • Prisma Access Logs
      • Prisma Access Activity Dashboards and Reports
      • Prisma Access Insights
      • Prisma Access and Autonomous DEM
    • Prisma Access User-Based Policy
      • Integrate Cloud Identity Engine with Prisma Access
      • Configure User-Based Policy for Prisma Access
      • Retrieve User-ID Group Mappings for Prisma Access
      • Identity Redistribution
    • Prisma Access Multi-Tenancy
      • Multitenancy Configuration Overview
      • Plan Your Multitenant Deployment
      • Create an All-New Multitenant Deployment
      • Enable Multitenancy and Migrate the First Tenant
      • Add Tenants to Prisma Access
      • Delete a Tenant
      • Create a Tenant-Level Administrative User
      • Control Role-Based Access for Tenant-Level Administrative Users
        • Remove Plugin Access for a Tenant-Level Administrative User
      • Sort Logs by Device Group ID in a Multitenant Deployment
    • Prisma Access in a FedRAMP Environment
      • Prisma Access FedRAMP Requirements
      • Configure Prisma Access in a FedRAMP Environment
    • Prisma Access Advanced Deployments
      • Add a New Compute Location for a Deployed Prisma Access Location
      • IPv6 Support for Private App Access
        • Enable and Configure IPv6 Networking and IP Pools in Your Prisma Access Infrastructure
        • Enable IPv6 Networking for a Mobile Users—GlobalProtect Deployment
        • Enable IPv6 Networking for Service Connections
        • Enable IPv6 Networking for Remote Networks
      • DNS Resolution for Mobile Users—GlobalProtect and Remote Network Deployments
        • DNS Resolution for Mobile Users—GlobalProtect Deployments
        • DNS Resolution for Remote Networks
      • How BGP Advertises Mobile User IP Address Pools for Service Connections and Remote Network Connections
      • Proxy Support for Prisma Access and Cortex Data Lake
      • Prisma Access Service Connection Advanced Deployments
        • Service Connection Multi-Cloud Redundancy
          • Configure and Activate Service Connection Cloud Provider Redundancy
          • Supported In-Country Active and Backup Cloud Provider Redundancy Locations
        • Use Traffic Steering to Forward Internet-Bound Traffic to Service Connections
          • Default Routes With Prisma Access Traffic Steering
          • Traffic Steering in Prisma Access
          • Traffic Steering Requirements
          • Default Routes with Traffic Steering Example
          • Default Routes with Traffic Steering Direct to Internet Example
          • Default Routes with Traffic Steering and Dedicated Service Connection Example
          • Prisma Access Traffic Steering Rule Guidelines
          • Configure Zone Mapping and Security Policies for Traffic Steering Dedicated Connections
          • Configure Traffic Steering in Prisma Access
        • Routing for Service Connection Traffic
          • Mobile User and Remote Network Routing to Service Connections
          • Prisma Access Default Routing
          • Prisma Access Hot Potato Routing
          • Configure Routing Preferences
        • Create a High-Bandwidth Network Using Multiple Service Connections
          • Create a High-Bandwidth Connection to a Headquarters or Data Center Location
          • Configure More than Two Service Connections to a Headquarters or Data Center Location
      • Prisma Access Mobile Users—GlobalProtect Advanced Deployments
        • Configure Multiple Portals in Prisma Access
        • Dynamic DNS Registration Support for Mobile Users—GlobalProtect
          • Enable DDNS for Mobile Users—GlobalProtect
          • Verify Dynamic DNS Configuration
        • Identification and Quarantine of Compromised Devices in a Prisma Access GlobalProtect Deployment
          • Use Cases for Quarantine List Redistribution
          • Configure Quarantine List Redistribution in Prisma Access
        • Sinkhole IPv6 Traffic In Mobile Users—GlobalProtect Deployments
          • Configure GlobalProtect to Disable Direct Access to the Local Network
          • Set Up an IPv6 Sinkhole On the On-Premises Gateway
        • Redistribute HIP Information with Prisma Access
          • HIP Redistribution Overview
          • Use Cases for HIP Redistribution
          • Configure HIP Redistribution in Prisma Access
        • View HIP Reports
        • Support for Gzip Encoding in Clientless VPN
      • Prisma Access Remote Network Advanced Deployments
        • Provide Secure Inbound Access to Remote Network Locations
          • Secure Inbound Access for Remote Network Sites
          • Secure Inbound Access Examples
          • Guidelines for Using Secure Inbound Access
          • Configure Secure Inbound Access for Remote Network Sites
            • Configure Secure Inbound Access for Remote Network Sites for Locations that Allocate Bandwidth by Location
            • Configure Secure Inbound Access for Remote Network Sites
          • Create a High-Bandwidth Network for a Remote Site
            • Create a High-Bandwidth Remote Network Connection
    • Prisma Access for Clean Pipe
      • Prisma Access for Clean Pipe Overview
        • Clean Pipe Use Cases
        • Clean Pipe Examples
        • Clean Pipe and Partner Interconnect Requirements
      • Complete the Clean Pipe Configuration
        • Enable Multitenancy and Create a Tenant

    Document:Prisma Access Administration


    Configure ZTNA Connector

    Download PDF
    Last Updated:
    May 22, 2023
    Current Version:
    4.0 Preferred
    • Version 4.0 Preferred

    Table of Contents


    Filter icon
    Filter
    Prisma Access Overview
    How To Manage Prisma Access
    How To Manage Prisma Access (Cloud Management)
    How to Manage Prisma Access (Panorama)
    Visibility Features in the Prisma Access App
    Prisma Access Locations
    Prisma Access Locations by Compute Location
    Prisma Access Locations by Theater and Location Group
    Prisma Access Locations by Region
    Map of North America Prisma Access Locations
    Explicit Proxy Locations
    Prisma Access Infrastructure Management
    Prisma Access APIs
    Prisma Access APIs (Cloud Management)
    Prisma Access APIs (Panorama)
    Your Prisma Access License
    Validate Your License
    Validate Your Prisma Access License (Cloud Management)
    Validate Your Prisma Access License (Panorama)
    All Available Apps and Services
    Cheat Sheet: ADEM with Prisma Access
    Cheat Sheet: IoT with Prisma Access
    Cheat Sheet: Enterprise DLP with Prisma Access
    Cheat Sheet: Enterprise DLP with Prisma Access (Cloud Management)
    Cheat Sheet: Enterprise DLP with Prisma Access (Panorama)
    Cheat Sheet: SaaS Security with Prisma Access
    Cheat Sheet: SaaS Security with Prisma Access (Cloud Management)
    Cheat Sheet: SaaS Security with Prisma Access (Panorama)
    Cheat Sheet: URL Filtering with Prisma Access
    Make Changes To Your License
    Reset Your Prisma Access License
    Transfer Or Update Your License
    Verify Your Prisma Access Account
    Prisma Access Releases and Upgrades
    Prisma Access Release Types
    Prisma Access Release Types (Cloud Management)
    Prisma Access Release Types (Panorama)
    Prisma Access Upgrade Types
    Prisma Access Upgrade Types (Cloud Management)
    Prisma Access Upgrade Types (Panorama)
    Cadence for Software and Content Updates for Prisma Access
    Cadence for Software and Content Updates for Prisma Access (Cloud Management)
    Cadence for Software and Content Updates for Prisma Access (Panorama)
    Prisma Access Dataplane Upgrades
    Get Upgrade Alerts and Updates
    View Prisma Access Software Versions
    View Prisma Access Software Versions (Cloud Management)
    View Prisma Access Software Versions (Panorama)
    Activate Your Prisma Access License
    Activate Your Prisma Access License (Cloud Management)
    Activate Your Prisma Access License (Panorama)
    Prisma Access Setup
    Set Up Prisma Access
    Set Up Prisma Access (Cloud Management)
    Set Up Prisma Access (Panorama)
    Prisma Access Infrastructure Subnet Requirements
    Configure the Prisma Access Service Infrastructure
    Prisma Access Service Infrastructure (Cloud Management)
    Prisma Access Service Infrastructure (Panorama)
    Mobile Users: IP Address Allocation
    Example: Public IP Address Scaling Examples (Mobile Users)
    Loopback IP Address Allocation (Mobile Users)
    Remote Networks: IPSec Termination Nodes and Service IP Addresses
    Remote Networks: IP Address Changes Related To Bandwidth Allocation
    Remote Networks: Service IP and Egress IP Address Allocation
    Retrieve the IP Addresses for Prisma Access
    Retrieve the IP Addresses for Prisma Access (Cloud Management)
    Retrieve the IP Addresses for Prisma Access (Panorama)
    API Examples for Retrieving Prisma Access IP Addresses
    Get Notifications When Prisma Access IP Addresses Change
    Use Legacy Scripts to Retrieve IP Addresses
    Retrieve Mobile User IP Addresses
    Retrieve Public, Loopback, and Egress IP Addresses
    Prisma Access Zones
    DNS for Prisma Access
    DNS for Prisma Access (Cloud Management)
    DNS for Prisma Access (Panorama)
    High Availability for Prisma Access
    Predefined Templates: Onboard a Service Connection or Remote Network
    Supported IKE and IPSec Cryptographic Profiles for Common SD-WAN Devices
    Prisma Access Service Connections
    Plan a Service Connection
    Configure a Service Connection
    Configure a Service Connection (Cloud Management)
    Configure a Service Connection (Panorama)
    Verify Service Connection Status
    Verify Service Connection Status (Cloud Management)
    Verify Service Connection Status (Panorama)
    Use a Service Connection to Enable Access between Mobile Users and Remote Networks
    Dynamic Routing Considerations for Service Connections
    Prisma Access Colo-Connect (Preview)
    Prisma Access Mobile Users
    Mobile Users: GlobalProtect
    Planning Checklist for GlobalProtect on Prisma Access
    Set Up GlobalProtect Mobile Users
    Set Up GlobalProtect Mobile Users (Cloud Management)
    Set Up GlobalProtect Mobile Users (Panorama)
    GlobalProtect Features for Prisma Access
    GlobalProtect — Customize Tunnel Settings
    Ticket Request to Disable GlobalProtect
    GlobalProtect Pre-Logon
    GlobalProtect — Customize App Settings
    Monitor GlobalProtect Mobile Users
    Monitor GlobalProtect Mobile Users (Cloud Management)
    Monitor GlobalProtect Mobile Users (Panorama)
    IP Address Pools for a GlobalProtect Mobile Users Deployment
    How the GlobalProtect App Selects Prisma Access Locations for Mobile Users
    Allow Listing GlobalProtect Mobile Users
    Allow Listing GlobalProtect Mobile Users (Cloud Management)
    Allow Listing GlobalProtect Mobile Users (Panorama)
    GlobalProtect App Upgrades
    Select the Active GlobalProtect App Version for Prisma Access
    Select the Active GlobalProtect App Version for Prisma Access (Cloud Management)
    Select the Active GlobalProtect App Version for Prisma Access (Panorama)
    Allow Users to Upgrade the GlobalProtect App
    Allow Users to Upgrade the GlobalProtect App (Cloud Management)
    Allow Users to Upgrade the GlobalProtect App (Panorama)
    Stagger GlobalProtect App Updates
    Integrate Prisma Access with On-Premises GlobalProtect Gateways
    Setting Priority for Prisma Access and On-Premises Gateways
    Mobile Users: Explicit Proxy
    How Explicit Proxy Works
    Explicit Proxy — Guidelines
    Set Up Explicit Proxy
    Set Up Explicit Proxy (Cloud Management)
    Set Up Explicit Proxy (Panorama)
    Cloud Identity Engine Authentication for Explicit Proxy Deployments
    Cloud Identity Engine Authentication for Explicit Proxy Deployments (Cloud Management)
    Cloud Identity Engine Authentication for Explicit Proxy Deployments (Panorama)
    Monitor and Troubleshoot Explicit Proxy
    Monitor and Troubleshoot Explicit Proxy (Cloud Management)
    Monitor and Troubleshoot Explicit Proxy (Panorama)
    Block Settings for Explicit Proxy
    Use Special Objects to Restrict Explicit Proxy Internet Traffic to Specific IP Addresses
    Use Explicit Proxy with GlobalProtect (or a Third-Party VPN)
    Requirements for Using Explicit Proxy with GlobalProtect or a Third-Party VPN
    Explicit Proxy and GlobalProtect: How It Works
    Explicit Proxy and GlobalProtect: Set It Up
    Explicit Proxy and GlobalProtect: Set It Up (Cloud Management)
    Explicit Proxy and GlobalProtect: Set It Up (Panorama)
    Explicit Proxy with Third Party VPNs
    Secure Users and Devices at Remote Networks With an Explicit Proxy
    Secure Users and Devices at Remote Networks With an Explicit Proxy (Cloud Management)
    Secure Users and Devices at Remote Networks With an Explicit Proxy (Panorama)
    App-Based Office 365 Integration with Explicit Proxy
    App-Based Office 365 Integration with Explicit Proxy (Cloud Management)
    App-Based Office 365 Integration with Explicit Proxy (Panorama)
    Kerberos Authentication for Explicit Proxy Deployments
    Requirements and Recommendations for Deploying Kerberos for Explicit Proxy Deployments
    Create a Kerberos Keytab
    Configure Kerberos Authentication for Explicit Proxy Deployments
    Cloud Management
    Panorama
    GlobalProtect in Proxy Mode
    GlobalProtect in Proxy Mode (Cloud Management)
    GlobalProtect in Proxy Mode (Panorama)
    GlobalProtect in Tunnel and Proxy Mode
    GlobalProtect in Tunnel and Proxy Mode (Cloud Management)
    GlobalProtect in Tunnel and Proxy Mode (Panorama)
    Report Mobile User Site Access Issues
    Enable Mobile Users to Authenticate to Prisma Access
    Authentication Support and Features
    Set Up Authentication
    Prisma Access Remote Networks
    Planning Checklist for Remote Networks
    Allocate Remote Network Bandwidth
    Allocate Remote Network Bandwidth (Cloud Management)
    Allocate Remote Network Bandwidth (Panorama)
    Plan Your Migration to the New Model