Secure Windows workloads with L7-aware microsegmentation. Redirect east-west
traffic to Prisma AIRS for deep inspection.
| Where Can I Use This? | What Do I Need? |
|
|
- NGFW license
- panredirect package installed on each
protected workload
- Administrator privileges on target workloads
|
Microperimeter provides Layer 7 (L7) aware
microsegmentation for Windows workloads. It redirects east-west traffic to a Prisma
AIRS firewall for deep inspection and policy enforcement. This establishes granular,
application-layer security for internal network traffic, protecting critical assets
from lateral movement and application-layer attacks.
The Microperimeter Agent, installed on Windows workloads, operates with kernel
privileges. It intercepts inbound and outbound L3 traffic, encapsulates it, and
redirects it to a user-specified Prisma AIRS firewall. The Prisma AIRS firewall
performs deep packet inspection at L7, enforcing security policies based on
application identity and contextual information.
Prerequisites
Before deploying the Microperimeter Agent on Windows, ensure the following
prerequisites are met:
- Windows workloads running non-End-of-Life (EOL) distributions and versions in
your environment.
- Windows workloads residing in private cloud datacenters or public cloud
environments.
- Direct IP connectivity between your Windows workloads and the designated Prisma
AIRS firewall in your network.
- L3 traffic redirection enabled for inspection in your environment.
- Prisma AIRS firewall 12.1.5 or higher, deployed in your environment with one of
the following configurations: greater than 9 GB memory, 4.5 GB to 9 GB memory,
Public Cloud-BYOL, Public Cloud-PAYG, or Private Cloud.
- IP address of your designated Prisma AIRS firewall's data interface known and
available.