The Prisma Access—NCC Gateway solution provides data inspection and
security policy controls across diverse cloud environments, as shown in the
following use cases.
To access the internet from Prisma Access, deploy an MCW Remote
Network secure processing node (MCW RN SPN). To access private apps hosted in a
data center from Prisma Access, deploy an MCW Service Connection SPN (MCW SC
).
This integration supports two deployment types, on-ramp and off-ramp.
Mobile Users Accessing Private Apps Using the MCW-SC
Off-Ramp—Provides secure app access for agent-based mobile users
(Prisma Access, GlobalProtect and also Prisma Browser). Traffic flows
from mobile users through the MCW service connection (MCW SC) and to the
NCC Gateway which connects to the GCP infrastructure and interconnects
where the private apps are hosted.
You write
security policies for mobile
users in the mobile users configuration scope in
Strata Cloud Manager
and
Prisma Access applies the policies at the gateway.
The following graphic shows the network travel path. The dashed
lines are internal Prisma Access connections and don’t require any
configuration.
Users at Remote Branch Offices Accessing Public and Private Apps
Access Using the MCW-RN On-Ramp—Provides secure private
app access for user traffic originating from remote offices and
campuses, and for remote users from a third-party VPN solution via a
Colo facility to the NCC Gateway. The NCC Gateway service routes the
customer traffic from these sources to Prisma Access for security
inspection for both private app access and internet bound traffic.
You write
security policies for users in
branch offices in the
Remote Networks configuration
scope. Security policies apply data, application and full
inspection controls to determine whether to allow or block the
connections. You can write additional policies to block other traffic
(such as traffic to and from a bitcoin server) and send an alert if
malicious traffic is detected.
Internet-Based Apps—Prisma Access inspects
traffic requests to the internet from the NCC Gateway.
East-West Traffic Inspection for Apps Hosted in
Regional VPCs—Users at the branch access the app after
Prisma Access secures the app through the MCW RN. Policy
enforcement is at the MCW RN and you write policies in the
Remote Network configuration scope.
- Users Accessing Apps that Require an Update Using the On-Ramp—Allows
apps to update if the update site requires access to the internet. In this
example, a headless app operating on Google Compute Engine (GCE) in VPC A
requires an update from the internet. In this use case, security policy
rules are applied that allow the app access to the internet apps and
services so that the app can retrieve and download the needed updates
You can also write additional policies to block other traffic
(such as traffic to and from a bitcoin server) and send an alert if
malicious traffic is detected. You write security policies for the users
in the remote branch remote network configuration scope and Prisma
Access applies the policy at the MCW RN.
To update an
app in a VPC, traffic takes the following path.