Complete Post-Migration Tasks (Panorama)
Uninstall GlobalProtect, configure third-party agent coexistence, and review common
configuration scenarios after migrating from to Prisma Agent on a
Panorama-managed tenant.
After you confirm that all users are operating correctly on the Prisma Agent,
uninstall GlobalProtect. Then, review and implement other common configuration
scenarios as needed.
Prepare to Uninstall GlobalProtect Ensure GlobalProtect is disconnected or disabled.
Verify
Prisma Agent is functioning correctly.
Confirm that all users have been migrated to
Prisma Agent.
Uninstall GlobalProtect (
Optional)
Configure Third-Party Agent Coexistence
When you deploy Prisma Agent in environments with existing remote
access solutions, you can configure bypass rules to enable both agents to
coexist on an endpoint. The bypass functionality enables Prisma Agent to ignore specific traffic, enabling third-party
agents to handle designated connections while Prisma Access continues to
secure other traffic according to your forwarding profile rules.
When Connectivity type is set to Direct, the
packets matching the forwarding rule are bounded to the physical
interface. When set to Bypass, no such bindings
is implemented, that way, the packets can be controlled through a
third-party VPN solution.
(
Optional)
Configure Common Use Cases
Review common scenarios for configuring Prisma Agent.
Most enterprises will use different Prisma Agent configurations
for employees and contractors. For example, employees require the Always On
mode with a full tunnel, providing seamless authentication. Contractors,
however, will require an on-demand secure access method specifically for
private applications.
Always-On Access - Full Tunnel (Employees)
All employee traffic is sent through the tunnel to Prisma Access with
Always On as the connection method. In this case,
configure agent settings with:
- Connect Method: Always On
- Forwarding Profile: All traffic through tunnel
(Default forwarding rule)
On-Demand Access - Split Tunnel (Contractors)
Contractors need to connect to Prisma Agent only when accessing
private applications.
- The private application traffic needs to be routed through the tunnel
using Forwarding Profiles. Select .
- Add a new forwarding profile for contractors. Within the new profile,
add a new forwarding rule to route private applications with
destinations set as Internal Site Exclusions and
connectivity set as Best Available – Fail Safe
(tunnel).
- Create the forwarding profile.
- For the Destination, the predefined Internal Site
Exclusions profile was used. You can also configure a
new destination profile consisting of a combination of FQDN or IP
addresses.
- In the contractors forwarding profile, move the newly created rule to
the top of the forwarding rules and change the connectivity method on
the Default rule to
Direct. This ensures that only private
application traffic routes through the tunnel; all other traffic
routes directly to the endpoint's physical interface.
- Update the forwarding profile.
- Select . Under Agent Settings, add a new profile setting with a
match criteria based on your contractors-only user group and the connect
method set to On-Demand.
- Scroll to the Forwarding Profile section and select the forwarding
profile created above.
- Create the profile and move it to the top of the
Agent Settings table.
- Push the configuration to Prisma Access by selecting .