Configure NGFW Connector Integration
Focus
Prisma Access

Configure NGFW Connector Integration

Table of Contents

Configure NGFW Connector Integration

Configure and manage NGFW as ZTNA Connectors in Prisma Access using Panorama or Strata Cloud Manager for automated, secure private application access.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama)
  • NGFW (Hardware and VM-Series)
  • Prisma Access (Managed by Strata Cloud Manager)
  • NGFW (Managed by Strata Cloud Manager)
  • PAN-OS ® version 12.1.5 and later
  • Cloud Service Plugin (CSP) version 6.1 and later (Panorama-managed deployments only)
  • Prisma Access version 6.1 and later
NGFW ZTNA Connector Integration leverages your Palo Alto Networks® NGFWs (VM-Series and Hardware NGFW) as ZTNA Connectors. This provides secure, automated connectivity to private applications for Prisma Access users. This feature enables automated connectivity to applications defined by Fully Qualified Domain Name (FQDN), IP address and port, IP subnet, or wildcard FQDN, supporting mobile, contractor, and branch users.
This feature addresses challenges like manual tunnel configuration, complex Network Address Translation (NAT) management for overlapped networks. It integrates your NGFWs directly into the Prisma Access architecture, automating these processes and optimizing application access. This approach minimizes operational complexity and improves user experience by providing more direct application access.
Your NGFW acts as a ZTNA Connector, establishing secure IPSec tunnels with Prisma Access ZTNA Tunnel Terminators (ZTTs) in relevant cloud regions. Your management interface centrally manages your NGFWs, registering them with the Prisma Access ZTNA Connector, which generates and applies necessary configurations (IPSec, Border Gateway Protocol (BGP), Network Address Translation (NAT), Loopback IP addresses) to your NGFW.
When multiple NGFW Connectors are grouped in a Connector Group, configuration removal is deferred until the last Connector in that Connector Group is explicitly deleted. This ensures configuration integrity during phased de-provisioning. Select the appropriate tab for your management interface to configure NGFW Connector.

Configure NGFW Connector Integration Strata Cloud Manager

Configure your NGFWs as ZTNA Connectors in Strata Cloud Manager by registering them to your tenant, configuring network settings, and creating the NGFW Connector.
Before you begin, ensure the following are in place:
  • PAN-OS® version 12.1.5 and later
  • Prisma Access version 6.2 and later
  • Strata Cloud Manager license and AIOps for NGFW license activated on the tenant
  • LAN interface configured on the NGFW for local network connectivity
When your NGFWs are managed by Strata Cloud Manager, NGFWs in the same tenant are automatically discovered as available NGFW Connectors — no Cloud Services Plugin (CSP) installation, TSG ID, or service account configuration is required. Complete the network prerequisites in Strata Cloud Manager before creating the NGFW Connector.
A tenant can manage NGFW Connectors using either Strata Cloud Manager or Panorama — not both simultaneously. If your tenant already has Panorama-managed NGFW Connectors, Strata Cloud Manager-managed NGFW Connector onboarding will fail, and vice versa.
  1. Verify that an NGFW license is activated on your Strata Cloud Manager tenant.
    Your tenant requires one of the following licenses: AIOps for NGFW, Strata Cloud Manager Pro, or an equivalent NGFW SKU. To confirm the license is active, navigate to the NGFW section in Strata Cloud Manager, if All Firewalls is visible, the license is activated.
  2. Register your NGFW with the Strata Cloud Manager tenant and move it to cloud management.
    1. Ensure your NGFW has a valid Device Certificate from the Palo Alto Networks support portal.
    2. In the Palo Alto Networks Hub, go to Device Associations, select Add Device, and associate your NGFW by serial number with your tenant.
      Once associated, the device appears under Available Devices in Strata Cloud Manager.
    3. In Strata Cloud Manager, select SettingsDevice ManagementAvailable Devices, select your NGFW, and choose Move to Cloud Management.
  3. On the NGFW, set the management mode to Cloud Service and commit the changes. Verify that the cloud management status on the NGFW shows Connected before proceeding.
  4. Verify that the NGFW is using default routing mode.
    Advanced routing isn't supported for NGFW Connector. In Strata Cloud Manager, select the NGFW's Virtual Router, if the router shows Legacy, default routing is active. If it shows Advanced, disable advanced routing on the NGFW and reboot it before proceeding.
  5. In Strata Cloud Manager, create a folder for your NGFW devices and add your device to it.
    1. Go to System SettingsFolder ManagementAdd Folder.
    2. Add a Name, Description, Labels, and select which firewalls you want to associate with. Select Create to create a folder, and move your NGFW device into it.
    Strata Cloud Manager uses snippets to group NGFW Connector-related configuration separately from your existing folder configuration. Snippets are automatically created and attached to the folder when you onboard an NGFW Connector, you don't configure them directly.
  6. Configure the WAN and local interface variables for your NGFW.
    1. At the folder level, assign the WAN interface variable to the appropriate physical interface (for example, ethernet1/1).
      Strata Cloud Manager uses object variables for interface assignment, you cannot assign a physical interface directly. Default variables for WAN and local interfaces are available, or you can create custom variables.
    2. At the device level, set the specific values for each variable, including the WAN IP address and local interface IP address.
  7. Configure a Virtual Router with a default route for internet connectivity.
    1. In Strata Cloud Manager, go to NetworkVirtual Routers and create a new Virtual Router or select an existing one.
    2. Add the WAN and local interfaces to the Virtual Router.
    3. Under Static Routes, add a default route through the WAN interface for internet connectivity.
  8. Assign the WAN and local interfaces to security zones.
    In Strata Cloud Manager, go to NetworkZones. Default zones are available — assign the WAN interface to the internet or untrust zone and the local interface to the trust or local zone. You can also create new zones.
  9. Commit and Push the network configuration to the NGFW.
    This commits the folder, interface, virtual router, and zone configuration from the preceding steps. Review the changes before committing to avoid unintended modifications to your environment. After you create the NGFW Connector in the next phase, Strata Cloud Manager automatically pushes the connector configuration to your NGFW.

Configure NGFW Connector Integration (Panorama)

Configure NGFW Connector in Panorama to use your existing next-generation firewalls as ZTNA Connectors for secure private application access.
Before you begin, ensure the following are in place:
  • PAN-OS® version 12.1.5 and later on Panorama and the NGFW
  • Cloud Service Plugin (CSP) version 6.1 and later
  • Prisma Access version 6.1 and later
  • Template stacks and device groups configured in Panorama
  • Prisma Access TSG ID and service account credentials
  • Layer 3 WAN interface configured on the NGFW
  • WAN interface assigned to a security zone
  • Routable loopback IP address configured in your data center network
  • Default route configured on the NGFW via the WAN interface
  • NGFW WAN interface has a public IP address, or is behind a NAT device with a public IP address
  • NGFW configured to resolve FQDNs for private applications via a local DNS server or DNS Proxy
When your NGFWs are managed by Panorama, use the Cloud Services Plugin (CSP) to register your NGFWs with Prisma® Access and deploy ZTNA Connector functionality. Panorama orchestrates configuration across your managed NGFWs using template stacks, and the CSP synchronizes configurations between Panorama and the Prisma Access cloud.
  1. Prepare templates and device groups in Panorama.
    1. Select PanoramaTemplatesCreate Templates and create a template.
    2. On Panorama, select TemplatesAdd Stack and create a new template stack. If required, create or modify the template variables.
    3. On Panorama, select Device GroupAdd and add a device group for your NGFW and attach the template created to the device group.
      If managing multiple NGFWs with the same template, use variables for unique configurations, such as WAN IP and LAN IP.
    4. On Panorama, select Device Registration Auth KeyAdd and add a device registration authentication key. Select Copy Auth Key and Close.
    5. On Panorama, select Managed DevicesSummaryAdd, enter the device registration key you created, select Generate Auth Key, and Commit and Push.
    6. In the firewall, select DeviceSetupManagement and edit the Panorama Settings.
    7. Enter the Panorama IP address in the first field.
    8. Enter the Auth key, select OK, and Commit your changes.
    9. On Panorama, select Managed DevicesSummary and verify the connection status.
  2. Configure the WAN and LAN interfaces within your Panorama template.
    1. On Panorama, select NetworkInterfacesEthernet, select the appropriate template from the Template context drop-down, select a slot number such as Slot1, and select an interface (for example, ethernet1/1). Select the Interface Type as Layer 3.
    2. On the Config tab, select a Virtual Router or create a new virtual router.
    3. Assign the Security Zone that is appropriate for the interface you're configuring.
    4. For an IPv4 interface, select the IPv4 tab and select Static in the Type of address field. Select Add to add a WAN IP address.
    5. On the Advanced tab, create or attach a Management Profile. Enable PoE Enable, and select OK.
    6. On Panorama, select NetworkZones and create a Zone. Add a Name and select the Type as Layer 3. Enable Packet Buffer Protection under Zone Protection and select OK.
    7. On Panorama, select NetworkVirtual Routers and select the virtual router.
    8. Select Router SettingsInterfaces. In the Static Routes tab, select default.
    9. (Optional) Configure BGP. If not configured, Prisma Access Service enables it when the Connector is onboarded.
    10. Select OK.
    11. Commit and Push to save the configuration.
  3. Connect your Prisma Access tenant to Panorama.
    1. On Panorama, select Cloud ServicesConfigurationNGFW Connector and select the settings icon.
    2. Add Prisma Access TSG ID.
    3. Create a Service Account in Strata Cloud Manager under Identity & Access Management.
    4. Get the Client Secret for this Service Account.
    5. On Panorama, add this Client Secret.
    6. On Strata Cloud Manager, select ConfigurationZTNA ConnectorOverview. Under NGFW Connector, copy the secret Key.
    7. Commit and Push to initiate the connection to Prisma Access.
    8. Verify the connection status on Panorama.
  4. Onboard the NGFW as an unclaimed connector.
    1. In Panorama, select Cloud ServicesConfigurationNGFW Connector and select Add.
    2. Enter a descriptive Name for the NGFW Connector.
    3. Choose the Template Stack and Template that manages this NGFW.
    4. Select the specific NGFW Device (identified by its serial number) from the dropdown list.
    5. Add a routable Loopback IP address for the NGFW.
    6. Select the WAN interface configured earlier in the prerequisites.
    7. Commit the changes from Panorama to NGFW and verify the NGFW Connector registration. You can see the NGFW's public IP address.
  5. (Optional) Configure DNS Proxy for private application name resolution.
    Use this procedure only if you don't have a private DNS server capable of resolving your internal applications and choose to use Panorama's DNS Proxy for static entries or wildcard resolution.
    1. In Panorama, select DeviceSetupServices and select the proxy object (for example, ztna_ngfw_proxy).
    2. Under DNS Settings, select the DNS Proxy Object, and then select ztna_ngfw_proxy.
    3. Select NetworkDNS Proxy and add DNS Static Entries for your private applications. Map application FQDNs to their corresponding IP addresses and select OK.
    4. Commit to save the DNS Proxy configuration and changes to Panorama.
      When an NGFW Connector is onboarded, Prisma Access service configures ztna_ngfw_proxy in NetworkDNS Proxy. If a DNS server is configured, ztna_ngfw_proxy uses the same DNS IP addresses.
  6. (Optional) Configure a DNS server for private application name resolution.
    1. In Panorama, select TemplatesDeviceSetupServices and select the settings icon.
    2. Under DNS Settings, select Servers, add a Primary DNS Server, and a Secondary DNS Server.