Deploy the Microperimeter Agent on Windows Workloads
Focus
Focus
Prisma AIRS

Deploy the Microperimeter Agent on Windows Workloads

Table of Contents

Deploy the Microperimeter Agent on Windows Workloads

Secure Windows workloads with L7-aware microsegmentation. Redirect east-west traffic to Prisma AIRS for deep inspection.
Where Can I Use This?What Do I Need?
  • Prisma AIRS
  • NGFW license
  • panredirect package installed on each protected workload
  • Administrator privileges on target workloads
Microperimeter provides Layer 7 (L7) aware microsegmentation for Windows workloads. It redirects east-west traffic to a Prisma AIRS firewall for deep inspection and policy enforcement. This establishes granular, application-layer security for internal network traffic, protecting critical assets from lateral movement and application-layer attacks.
The Microperimeter Agent, installed on Windows workloads, operates with kernel privileges. It intercepts inbound and outbound L3 traffic, encapsulates it, and redirects it to a user-specified Prisma AIRS firewall. The Prisma AIRS firewall performs deep packet inspection at L7, enforcing security policies based on application identity and contextual information.
Prerequisites
Before deploying the Microperimeter Agent on Windows, ensure the following prerequisites are met:
  • Windows workloads running non-End-of-Life (EOL) distributions and versions in your environment.
  • Windows workloads residing in private cloud datacenters or public cloud environments.
  • Direct IP connectivity between your Windows workloads and the designated Prisma AIRS firewall in your network.
  • L3 traffic redirection enabled for inspection in your environment.
  • Prisma AIRS firewall 12.1.5 or higher, deployed in your environment with one of the following configurations: greater than 9 GB memory, 4.5 GB to 9 GB memory, Public Cloud-BYOL, Public Cloud-PAYG, or Private Cloud.
  • IP address of your designated Prisma AIRS firewall's data interface known and available.
  1. Obtain the Microperimeter agent for Windows.
    1. Login to your Customer Support Portal and access software updates.
    2. Select the Windows installer package for the Microperimeter agent.
  2. Install the Microperimeter agent on your Windows workload.
    1. Execute the downloaded Windows installer package on your Windows workload.
    2. Follow the on-screen instructions to complete the installation.
    panredirect.msi is the Windows Installer package that can be installed in various attended and unattended ways, including Group Policy Objects, Microsoft Configuration Manager, Microsoft Intune, or third-party tools. Consult your Windows administrator for options specific to your environment.
  3. Configure the firewall data interface IP for redirection.
    panredirect configure --fwip <firewall_data_interface_ip>
  4. Enable redirection on the target network interface.
    panredirect enable <nic1_name> <nic2_name>
  5. Configure the rule list using panredirect rule insert or panredirect rule append commands.
    See the command line reference for a complete description. For example:
    panredirect rules list panredirect rule append --iface <nic_name> --action redirect ...
  6. Restart panredirect to apply changes.
    panredirect restart
  7. Verify geneve tunnel status.
    Panredirect.exe status
  8. Verify agent status and traffic redirection.
    1. Check the Microperimeter agent's health monitoring status.
      panredirect health_check
    2. Confirm network traffic from your Windows workload is redirected to your Prisma AIRS firewall for inspection by observing firewall logs or using network monitoring tools.
    To stop redirection and revert all changes on a workload, run panredirect disable <nic_name>.