Access Private Apps with Prisma Browser Connector
Focus
Focus
Prisma Browser

Access Private Apps with Prisma Browser Connector

Table of Contents

Access Private Apps with Prisma Browser Connector

Access Private Apps with Prisma Browser for Mobile Connector
The Prisma Browser Connector provides secure, authenticated access to private applications across all supported operating systems. Utilizing a standardized MASQUE tunnel mechanism, the connector creates a secure transport channel for enterprise traffic originating from both desktop and mobile environments.

Platform Compatibility

Prisma Browser Connector is natively supported across the following platforms:
  • Desktop: Windows, macOS, and Linux
  • Mobile: Prisma Browser Mobile (iOS and Android)
Mobile clients establish connections using the exact same MASQUE tunneling protocol as desktop clients, ensuring consistent security posture, policy enforcement, and authentication mechanisms across all endpoints. Both iOS and Android platforms integrate with the Prisma Access console to maintain shared policy rules. However, administrators should account for mobile-specific differences—such as File Download controls skipping specific extension checks and blocking downloads when enabled—by scoping policy rules to dedicated mobile device groups.

Prerequisites & Configuration

Trusted Certificate Authority (CA) Requirement
To successfully establish and validate MASQUE tunnels, the Certificate Authority (CA) issuing your Connector or proxy certificate must be explicitly registered as a trusted CA within your Prisma Browser security policies.
Configuration Checklist:
  1. From Strata Cloud Manager, select ConfigurationPolicyControl SetsBrowser SecurityNetwork Protection
  2. Select Trusted Certificate Authorities.
  3. Ensure the signing CA certificate is added to either the device trust store or the browser/internal trust store, depending on your operational deployment model.
  4. Verify that the CA trust settings are pushed and applied consistently across all platform profiles (Desktop, iOS, and Android).
Failure to import and trust the issuing CA will result in the browser being unable to verify the Connector endpoint. Unverified connection attempts will fail or automatically fall back to a blocked state. Always confirm CA deployment prior to rolling out Connector-based access to end users.

MASQUE Protocol Architecture & Tunneling

The Prisma Browser Connector utilizes MASQUE (Multiplexed Application Substrate over QUIC Encryption) to construct secure, high-performance transport channels over HTTP/3. MASQUE leverages QUIC to multiplex multiple flows across streams, encrypt flow metadata, and apply a unified congestion controller. This enables seamless proxying of TCP, UDP, and IP-based applications with minimal latency and high resilience.
For every connection request, the browser generates a 64-bit random integer sent via the x-panw-flow-id header to correlate connection streams and facilitate session tracking.

Fallback Mechanisms

To guarantee connectivity across constrained or restrictive network environments, the Prisma Browser Connector employs a multi-tiered fallback architecture:
  • HTTP/2 Fallback: If QUIC/HTTP/3 traffic is blocked or unsupported on the user's underlying network, chromium-based bad-proxy detection automatically triggers a rollover to MASQUE over HTTP/2. Network conditions are continuously monitored, and HTTP/3 connection attempts are automatically re-evaluated whenever a network change event occurs (e.g., switching Wi-Fi networks or connecting an Ethernet cable).
  • Enterprise Protector (EP) Fallback: If HTTP/2 proxying is also blocked or unavailable, traffic can route via Enterprise Protector (EP) as a fallback mechanism. This path is controlled via feature flags and can be enabled per tenant upon request.

Access ID (AID / ZID) Allocation & Lifecycle

Traffic authentication and user isolation rely on Access IDs (AID, formerly ZID) allocated dynamically during session startup:
  • JWT Acquisition: Upon launch, the browser requests a short-lived JSON Web Token (JWT) from the Prisma Browser backend, which is automatically refreshed every 20 minutes.
  • Caching & Persistence: The backend obtains the allocated Access ID and stores it in a Redis cache with a standard Time-To-Live (TTL) of 3 days. Re-allocation is only triggered if the cache entry expires or if a change in User ID or Device ID is detected.
  • Header Injection: All private application traffic sent over the MASQUE proxy includes the Access ID claim within the JWT, as well as in the dedicated x-panw-access-id (or x-panw-zerotrust-id) request header.
  • Resilience: If the backend fails to respond to an allocation request, the browser continues to authenticate and pass traffic through the proxy without failing the underlying session.