Features Introduced in July 2026
Focus
Focus
Prisma SD-WAN

Features Introduced in July 2026

Table of Contents

Features Introduced in July 2026

Learn about the features introduced in the Prisma SD-WAN July release.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN
  • Prisma SD-WAN license
Here's a preview of the new features introduced in Prisma SD-WAN in July 2026.

Coffeeshop Policies in the Prisma SASE branch

Prisma SD-WAN now supports Coffeeshop deployment to automatically route Prisma Access Mobile User and Explicit Proxy traffic directly to the internet at branch sites, eliminating the need to manually configure and maintain path policies as gateway IP addresses change. Prisma SD-WAN now automatically learns Mobile User and Explicit Proxy gateway IP addresses from the Prisma Access infrastructure and maintains read-only, dynamically updated prefix lists. For tenants with Remote Network High Performance enabled, Prisma SD-WAN creates a Default Path Coffeeshop Simple Stack Policy Set with two protected rules that route this traffic directly to the internet. The rules automatically synchronize backup and L3 failure paths with your default rule configuration.
You can activate this feature by attaching the auto-created policy set to your active path policy stack and enabling the rules. You can adjust rule priority and enable or disable the rules, but path and prefix configurations are read-only and managed automatically.

Support for New Indonesia Controller

Prisma SD-WAN now includes a cloud controller hosted in Indonesia, expanding regional coverage to host control plane data, ensuring both data plane and control plane data reside in Indonesia. The Indonesia controller addresses Indonesia's infrastructure demands, enabling lower-latency, locally compliant SD-WAN management for enterprise customers across the region. It is designed to support large-scale branch deployments in key verticals including Banking & Financial Services (BFSI), Telecommunications, and more.
Customers can now onboard SD-WAN tenants with data residency in Indonesia, meeting local regulatory and data sovereignty requirements critical for financial institutions and government-linked organizations operating in the country.

Support for Post-Quantum Cryptography

You can now protect Standard VPN connections against future quantum computer attacks using Post-Quantum Cryptography (PQC) on ION devices running release 6.8.1 and above. This release addresses "Harvest Now, Decrypt Later" threats where attackers collect encrypted data today to decrypt it when quantum computers become available.
This release includes:
  • RFC 8784 support for Post-Quantum Pre-shared Keys (PPK) with Mandatory and Preferred negotiation modes
  • RFC 9370/9242 support for up to seven additional key exchange rounds combining NIST-approved ML-KEM algorithms (ML-KEM-512, ML-KEM-768, ML-KEM-1024) with classical algorithms (ECDH, Diffie-Hellman)
  • TLS 1.3 with quantum-resistant hybrid key exchange groups (X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024) for secure ION-to-controller communication
You configure PQC features when creating IPsec profiles for Standard VPN connections.