New Features in Prisma Access 6.0
Focus
Focus
Prisma Access

New Features in Prisma Access 6.0

Table of Contents

New Features in Prisma Access 6.0

Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access (Managed by Panorama)
This section provides you with a list of new features in Prisma Access 6.0 Preferred and Innovation, along with the recommended and required software versions you need to use.

Recommended Software Versions for Prisma Access 6.0 Preferred and Innovation

Prisma Access 6.0 Preferred and Innovation run on a PAN-OS 11.2.6 dataplane.
For Prisma Access 6.0 features, Palo Alto Networks recommends that you upgrade your Prisma Access to the following versions before installing the plugin.
Prisma Access VersionCloud Services Plugin VersionRequired Dataplane Version for 6.0Recommended GlobalProtect VersionRecommended Panorama Version
6.06.0
PAN-OS 11.2.6 for 6.0 Preferred and Innovation
6.0.7+
6.1.3+
6.2.1+
Minimum required versions for IPv6 Support for Public Apps for IP Optimization:
  • 6.2.6 client version for Windows and macOS
  • 6.2.7 for Linux
  • 6.1.7 for Android and IOS
10.2.10+
11.0.1+
11.1.0
11.2.6

Infrastructure, Plugin, and Dataplane Dependencies for Prisma Access 6.0 Preferred and Innovation Features

Prisma Access6.0 features require one of more of the following components to function:
  • Infrastructure Upgrade—The infrastructure includes the underlying service backend, orchestration, and monitoring infrastructure. Prisma Access upgrades the infrastructure before the general availability (GA) date of a Prisma Access release.
    Features that require only an infrastructure upgrade to be unlocked take effect for all Prisma Access deployments, regardless of version, at the time of the infrastructure upgrade.
  • Plugin Upgrade (Prisma Access Panorama Managed Deployments Only)—Installing the plugin activates the features that are available with that release. You download and install the plugin on the Panorama that manages Prisma Access.
    Prisma Access (Managed by Panorama) release 6.0 uses the Cloud Services Plugin 6.0.
  • Dataplane Upgrade—The dataplane enables traffic inspection and security policy enforcement on your network and user traffic.
    • For Prisma Access (Managed by Strata Cloud Manager), go to ManageConfigurationNGFW and Prisma AccessOverviewPrisma Access Version.'
    • For Prisma Access (Managed by Panorama) deployments, you can view your dataplane version by going to PanoramaCloud ServicesConfigurationService Setup and viewing the Prisma Access Version. Prisma Access Preferred and Innovation run PAN-OS 11.2.6.
A dataplane upgrade to 6.0 Innovation is optional, and is only required if you want to take advantage of the features that require a dataplane upgrade.
These features are activated with the infrastructure upgrade only for Prisma Access 6.0:
  • Advanced ZTNA Connector
  • Extend Prisma Access User Group Policy Support with Short Form Format
  • Mexico Central Compute Region Support
  • Remote Network Site-Based Licensing and Simplified Onboarding
  • Simplified Onboarding Workflow
These features require an infrastructure and plugin upgrade but don't require a dataplane upgrade; however, a minimum datapane version of 10.2.4 is required for these features:
  • BGP Filtering and Route Metric Support for Prisma Access
These features require an infrastructure, plugin, and dataplane upgrade to PAN-OS 11.2.6, making them Prisma Access 6.0 Preferred and Innovation features:
  • Colo-Connect Inter-Region
  • RFC6598, iOS, and Android Support for Static IP Address Allocation
  • WildFire Hold Mode Support (11.2.4 or later dataplane required)

Prisma Access 6.0 Features

The following table describes the new features that will be generally available with Prisma Access 6.0.

Advanced ZTNA Connector

Supported in: Prisma Access 6.0
Regional Support for Strata Logging Service
ZTNA Connector can now send logs to Strata Logging Service instances in the following regions:
  • Indonesia
  • Qatar
  • Saudi Arabia
  • Taiwan
Simplified Onboarding Workflow
Prisma Access now offers a simplified Day 0 onboarding workflow to setup ZTNA Connector. This guided, step-by-step process helps you:
  • Configure Prisma Access to secure private apps
  • Apply best-practice defaults
  • Automate backend tasks
  • Integrate Cloud Identity Engine (CIE), Strata Cloud Manager, and Prisma Access
This intuitive, action-oriented setup reduces complexities during onboarding.
Streamlined Licensing
Prisma Access 6.0 introduces a streamlined licensing model for ZTNA Connector:
  • You can now enable ZTNA Connector without a ZTNA add-on license.
  • Based on your existing Prisma Access licenses, you receive 10 ZTNA Connector licenses with the base license.
  • If you purchase the Private Apps add-on, you unlock a number of Service Connections and ZTNA Connectors up to the limit supported by the product in each tenant.
Prisma Access 6.0 introduces new licensing for ZTNA Connector streamlining the licensing structure, simplifying the process, and offering a more efficient approach.
This licensing model provides an option to Enable ZTNA Connector without a ZTNA add-on license. Based upon your Prisma Access licenses, you will get free but limited licenses. If you purchase an unlimited private apps add-on license, you will get an unlimited Service Connections and ZTNA Connectors.
Support for DNS SRV records and SCCM
ZTNA Connector now supports:
  • DNS SRV queries, which allow clients to locate AD domain controllers intelligently using structured, priority-based FQDNs.
  • SCCM integration, enabling the ZTNA Connector to direct software updates through the correct AD site’s distribution point.
This enhancement improves resource access, strengthens endpoint management, and maintains ZTNA-level security.

BGP Filtering and Route Metric Support for Prisma Access

Supported in: Prisma Access 6.0 (minimum 10.2.4 dataplane required)
We introduced BGP Filtering and Route Metric Support on Service Connections in Prisma Access. With this feature, you gain precise control over your network's routing behavior with our enhanced BGP filtering and route metric support. This feature enables you to implement sophisticated routing policies, optimize traffic flow, and strengthen your security posture. By integrating seamlessly with our industry-leading security platform, you can now fine-tune BGP operations while maintaining robust threat prevention.

Colo-Connect Inter-Region

Supported in: Prisma Access 6.0
Colo-Connect handles interregion traffic with a focus on high performance and scalable network solutions, ensuring seamless operation even if a compute location becomes unavailable. To address this need, we have implemented an interregion connectivity feature. This feature enables Colo-Connect instances across different regions to be interconnected and provides robust disaster recovery capabilities between regions.
Interregion support provides you with:
  • Higher bandwidth
  • Multicloud support
  • Seamless scalability across regions

DNS Resolution for Mobile Users—Explicit Proxy Deployments

Supported in: Prisma Access 6.0
Explicit Proxy expands its support to include DNS Proxy customization. Explicit Proxy supports DNS settings such as regional DNS, custom DNS and so on. You can also use a third-party DNS resolver or an on-premises DNS resolver to resolve public and private apps and can use per FQDN. This functionality is now supported on Panorama Managed Prisma Access.

Extend Prisma Access User Group Policy Support with Short Form Format

Supported in: Prisma Access 6.0
We introduced the ability to extend Prisma Access user group policy with the short form format. Migrating security policies from NGFW to Prisma Access requires policy elements standardization. Prisma Access only supports long-form DN entries for group-based policies, while the NGFW allows using other formats such as SAML account name/Common Name and email address. This feature enables customers to define the group format choice for security policy creation, allowing standardized policy creation across Prisma Access and NGFW.

Mexico Central Compute Region Support

Supported in: Prisma Access 6.0
Prisma Access supports the Mexico Central compute region.

Region Support for Explicit Proxy

Supported in: Prisma Access 6.0
Explicit proxy extends its support to the following regions:
  • Bahrain
  • Canada West
  • France North
  • Ireland
  • Sweden
  • South Africa West
  • United Arab Emirates

Remote Network Site-Based Licensing and Simplified Onboarding

Supported in: Prisma Access 6.0 (New Prisma Access Deployoments Only)
Prisma Access 6.0 introduces site-based licensing for Remote Networks, enhancing flexibility and simplifying deployment for branch sites. This licensing model allows you to allocate your sites with predefined bandwidth capacities, ranging from 25 Mbps to 2.5 Gbps. By moving away from aggregate bandwidth-based licensing, you can more easily estimate and allocate resources for your remote sites.
With site-based licensing, you no longer need to pre-allocate bandwidth to specific Prisma Access compute regions or configure redundancy manually. This approach reduces complexity in network planning and provides a more straightforward way to manage and scale your branch sites.
Using this model, you can focus on the number and types of sites needed rather than estimating total bandwidth consumption across your network.
Site-based licensing in Prisma Access aligns better with your organizational structure and growth plans, providing a more intuitive and scalable approach to securing and connecting your branch sites. This licensing model aims to enhance your experience in deploying and managing Prisma Access, offering greater control and efficiency in resource allocation across your distributed network infrastructure.
In addition, there is a simplified onboarding workflow for Prisma Access, guiding you through a step-by-step workflow to configure your remote network setup.

RFC6598, iOS, and Android Support for Static IP Address Allocation

Supported in: Prisma Access 6.0
For the Static IP Address Allocation feature for GlobalProtect™ mobile users, Prisma® Access adds the following enhanced functionality:
  • Support for iOS and Android mobile devices
  • Support for RFC6598 addresses

Simplified Onboarding Workflow

Supported in: Prisma Access 6.0
The Prisma Access onboarding workflow streamlines the onboarding process, guiding you through a step-by-step workflow to configure your Prisma Access setup for:
By incorporating best-practice defaults, automating backend tasks, and seamlessly integrating the Cloud Identity Engine and Strata Cloud Manager with Prisma Access, you can significantly reduce onboarding time. This intuitive, action-oriented approach not only accelerates time-to-value but also reduces onboarding complexity. The result is an unparalleled onboarding experience.

WildFire Hold Mode Support

Supported in: Prisma Access 6.0
If you have an active WildFire® or Advanced WildFire license, Prisma® Access now supports WildFire Hold Mode. Hold Mode enables you to configure Prisma Access to hold the transfer of a sample file while the real-time signature cloud performs a signature lookup. When the lookup completes, Prisma Access releases the file to the requesting client (or blocks it, based on your organization's security policy for specific WildFire verdicts, preventing the initial transfer of known malware. You can configure Hold Mode on a per antivirus profile basis and apply a global setting for the signature lookup timeout and the associated action.