Complete Post-Migration Tasks (Strata Cloud Manager)
Focus
Focus
Prisma Agent

Complete Post-Migration Tasks (Strata Cloud Manager)

Table of Contents

Complete Post-Migration Tasks (Strata Cloud Manager)

Uninstall GlobalProtect and review common configuration scenarios after migrating from GlobalProtect to the Prisma Agent on a Strata Cloud Manager-managed tenant.
After you confirm that all users are operating correctly on the Prisma Agent, uninstall GlobalProtect. Then, review and implement other common configuration scenarios as needed.
  1. Prepare to Uninstall GlobalProtect
    1. Ensure GlobalProtect is disconnected or disabled.
    2. Verify Prisma Agent is functioning correctly.
    3. Confirm that all users have been migrated to Prisma Agent.
  2. Uninstall GlobalProtect
    Windows
    macOS
  3. (Optional) Configure Third-Party Agent Coexistence
    When you deploy Prisma Agent in environments with existing remote access solutions, you can configure bypass rules to enable both agents to coexist on an endpoint. The bypass functionality enables Prisma Agent to ignore specific traffic, enabling third-party agents to handle designated connections while Prisma Access continues to secure other traffic according to your forwarding profile rules.
    When Connectivity type is set to Direct, the packets matching the forwarding rule are bounded to the physical interface. When set to Bypass, no such bindings is implemented, that way, the packets can be controlled through a third-party VPN solution.
  4. (Optional) Configure Common Use Cases
    Review common scenarios for configuring Prisma Agent.
    Most enterprises will use different Prisma Agent configurations for employees and contractors. For example, employees require the Always On mode with a full tunnel, providing seamless authentication. Contractors, however, will require an on-demand secure access method specifically for private applications.
    Always-On Access - Full Tunnel (Employees)
    All employee traffic is sent through the tunnel to Prisma Access with Always On as the connection method. In this case, configure agent settings with:
    • Connect Method: Always On
    • Forwarding Profile: All traffic through tunnel (Default forwarding rule)
    On-Demand Access - Split Tunnel (Contractors)
    Contractors need to connect to Prisma Agent only when accessing private applications.
    1. The private application traffic needs to be routed through the tunnel using Forwarding Profiles. Select ConfigurationNGFW and Prisma AccessConfiguration ScopeMobile Users ContainerSetupForwarding Profiles Setup.
    2. Add a new forwarding profile for contractors. Within the new profile, add a new forwarding rule to route private applications with destinations set as Internal Site Exclusions and connectivity set as Best Available – Fail Safe (tunnel).
    3. Save the forwarding profile.
    4. For the Destination, the predefined Internal Site Exclusions profile was used. You can also configure a new destination profile consisting of a combination of FQDN or IP addresses.
    5. In the contractors forwarding profile, move the newly created rule to the top of the forwarding rules and change the connectivity method on the Default rule to Direct. This ensures that only private application traffic routes through the tunnel; all other traffic routes directly to the endpoint's physical interface.
    6. Save the forwarding profile.
    7. Select ConfigurationNGFW and Prisma AccessConfiguration ScopeAccess AgentSetupPrisma Access Agent. Under Agent Settings, add a new profile setting with a match criteria based on your contractors-only user group and the connect method set to On-Demand.
    8. Scroll to the Forwarding Profile section and select the forwarding profile created above.
    9. Save the profile and move it to the top of the Agent Settings table.
    10. Push the configuration to Prisma Access by selecting Push ConfigPush.