1. Home
Location
    Techdocs Logo Techdocs Logo
    • Documentation Home
    • Palo Alto Networks
    • Support
    • Live Community
    • Knowledge Base
    1. Home
    2. Prisma
    3. Prisma Access
    4. Prisma Access Administrator’s Guide (Panorama Managed)
    PDF Cover Image
    Download PDF
    Last Updated:
    Nov 21, 2022
    Current Version:
    2.2 Preferred
    • Version 4.0 Preferred
    • Version 3.2 Preferred and Innovation
    • Version 3.1 Preferred and Innovation
    • Version 3.0 Preferred and Innovation
    • Version 2.2 Preferred
    • Version Prisma Access China

    Table of Contents


    Filter icon
    Filter
    Prisma Access Overview
    Prisma Access
    Prisma Access Infrastructure Management
    Releases and Upgrades
    Manage Upgrade Options for the GlobalProtect App
    Notifications and Alerts for Panorama, Cloud Services Plugin, and PAN-OS Dataplane Versions
    Prisma Access Licensing
    Monitor Your Data Transfer Usage
    Retrieve the IP Addresses for Prisma Access
    Plan for IP Address Changes for Mobile Users, Remote Networks, and Service Connections
    Service IP and Egress IP Address Allocation for Remote Networks
    How to Calculate Remote Network Bandwidth
    Prisma Access APIs
    Use Logging, Routing, and EDL Information to Troubleshoot Your Deployment
    Activate and Install the Prisma Access Components
    Activate and Install Prisma Access (Panorama Managed)
    Transfer or Update Prisma Access Licenses
    Reset Your Prisma Access License
    Transfer or Update Prisma Access Licenses Between Panorama Appliances
    Configure Panorama Appliances in High Availability for Prisma Access
    Prepare the Prisma Access Infrastructure and Service Connections
    Set Up Prisma Access
    Plan the Service Infrastructure and Service Connections
    Configure the Service Infrastructure
    Create a Service Connection to Allow Access to Your Corporate Resources
    Create a Service Connection to Enable Access between Mobile Users and Remote Networks
    Deployment Progress and Status
    How BGP Advertises Mobile User IP Address Pools for Service Connections and Remote Network Connections
    Use Traffic Steering to Forward Internet-Bound Traffic to Service Connections
    Routing Preferences for Service Connection Traffic
    Create a High-Bandwidth Network Using Multiple Service Connections
    List of Prisma Access Locations
    Secure Mobile Users with Prisma Access
    Plan To Deploy Prisma Access for Mobile Users
    Secure Mobile Users With GlobalProtect
    Secure Mobile Users with an Explicit Proxy
    Zone Mapping
    Specify IP Address Pools for Mobile Users
    How the GlobalProtect App Selects a Prisma Access Location for Mobile Users
    View Logged In User Information and Log Out Current Users
    Quick Configs for Mobile User Deployments
    Use Explicit Proxy to Secure Public Apps and GlobalProtect or a Third-Party VPN to Secure Private Apps
    Prisma Access with On-Premises Gateways
    Manage Priorities for Prisma Access and On-Premises Gateways
    Set Equal Gateway Priorities for On-Premises and Prisma Access Gateways
    Set a Higher Gateway Priority for an On-Premises Gateway
    Set Higher Priorities for Multiple On-Premises Gateways
    Configure Priorities for Prisma Access and On-Premises Gateways
    Allow Mobile Users to Manually Select Specific Prisma Access Gateways
    DNS Resolution for Mobile Users—GlobalProtect and Remote Network Deployments
    IPv6 Support for Private App Access
    Sinkhole IPv6 Traffic In Mobile Users—GlobalProtect Deployments
    Identification and Quarantine of Compromised Devices With Prisma Access
    Support for Gzip Encoding in Clientless VPN
    Report Website Access Issues
    Use Remote Networks to Secure Branches
    Plan to Deploy Remote Networks
    Onboard and Configure Remote Networks
    Plan to Migrate to an Aggregate Bandwidth Remote Network Deployment
    Migrate to the Aggregate Bandwidth Model
    Quick Configs for Remote Network Deployments
    Remote Network Locations with Overlapping Subnets
    Remote Network Locations with WAN Link
    Use Predefined IPSec Templates to Onboard Service and Remote Network Connections
    Onboard Remote Networks with Configuration Import
    Configure Quality of Service in Prisma Access
    Create a High-Bandwidth Network for a Remote Site
    Provide Secure Inbound Access to Remote Network Locations
    Configure User-ID and User-Based Policies with Prisma Access
    Configure User-ID in Prisma Access
    Configure User-ID for Remote Network Deployments
    Configure Your Prisma Access Deployment to Retrieve Group Mapping
    Redistribute User-ID Information Between Prisma Access and On-Premises Firewalls
    Get User and Group Information Using the Cloud Identity Engine
    Redistribute HIP Information and View HIP Reports
    Redistribute HIP Information with Prisma Access
    View HIP Reports from Panorama
    Manage Multiple Tenants in Prisma Access
    Multitenancy Overview
    Multitenancy Configuration Overview
    Plan Your Multitenant Deployment
    Create an All-New Multitenant Deployment
    Enable Multitenancy and Migrate the First Tenant
    Add Tenants to Prisma Access
    Delete a Tenant
    Create a Tenant-Level Administrative User
    Control Role-Based Access for Tenant-Level Administrative Users
    Sort Logs by Device Group ID for External Logging
    Prisma Access in a FedRAMP Environment
    Panorama Managed Prisma Access and FedRAMP Authorization
    Panorama Managed Prisma Access FedRAMP Requirements
    Configure a Prisma Access FedRAMP Deployment
    Use DLP With Prisma Access
    DLP Integration with Prisma Access
    IoT Security Integration with Prisma Access
    Use IoT Security with Prisma Access
    Create and Configure Prisma Access for Clean Pipe
    Prisma Access for Clean Pipe Overview
    Configure Prisma Access for Clean Pipe
    Visibility and Monitoring Features in the Prisma Access App
    • Prisma Access Overview
      • Prisma Access
      • Prisma Access Infrastructure Management
      • Releases and Upgrades
      • Manage Upgrade Options for the GlobalProtect App
      • Notifications and Alerts for Panorama, Cloud Services Plugin, and PAN-OS Dataplane Versions
      • Prisma Access Licensing
        • Monitor Your Data Transfer Usage
      • Retrieve the IP Addresses for Prisma Access
      • Plan for IP Address Changes for Mobile Users, Remote Networks, and Service Connections
      • Service IP and Egress IP Address Allocation for Remote Networks
      • How to Calculate Remote Network Bandwidth
      • Prisma Access APIs
      • Use Logging, Routing, and EDL Information to Troubleshoot Your Deployment
    • Activate and Install the Prisma Access Components
      • Activate and Install Prisma Access (Panorama Managed)
      • Transfer or Update Prisma Access Licenses
        • Reset Your Prisma Access License
        • Transfer or Update Prisma Access Licenses Between Panorama Appliances
      • Configure Panorama Appliances in High Availability for Prisma Access
    • Prepare the Prisma Access Infrastructure and Service Connections
      • Set Up Prisma Access
      • Plan the Service Infrastructure and Service Connections
      • Configure the Service Infrastructure
      • Create a Service Connection to Allow Access to Your Corporate Resources
      • Create a Service Connection to Enable Access between Mobile Users and Remote Networks
      • Deployment Progress and Status
      • How BGP Advertises Mobile User IP Address Pools for Service Connections and Remote Network Connections
      • Use Traffic Steering to Forward Internet-Bound Traffic to Service Connections
      • Routing Preferences for Service Connection Traffic
      • Create a High-Bandwidth Network Using Multiple Service Connections
      • List of Prisma Access Locations
    • Secure Mobile Users with Prisma Access
      • Plan To Deploy Prisma Access for Mobile Users
      • Secure Mobile Users With GlobalProtect
      • Secure Mobile Users with an Explicit Proxy
      • Zone Mapping
      • Specify IP Address Pools for Mobile Users
      • How the GlobalProtect App Selects a Prisma Access Location for Mobile Users
      • View Logged In User Information and Log Out Current Users
      • Quick Configs for Mobile User Deployments
        • Use Explicit Proxy to Secure Public Apps and GlobalProtect or a Third-Party VPN to Secure Private Apps
        • Prisma Access with On-Premises Gateways
        • Manage Priorities for Prisma Access and On-Premises Gateways
          • Set Equal Gateway Priorities for On-Premises and Prisma Access Gateways
          • Set a Higher Gateway Priority for an On-Premises Gateway
          • Set Higher Priorities for Multiple On-Premises Gateways
          • Configure Priorities for Prisma Access and On-Premises Gateways
          • Allow Mobile Users to Manually Select Specific Prisma Access Gateways
        • DNS Resolution for Mobile Users—GlobalProtect and Remote Network Deployments
        • IPv6 Support for Private App Access
        • Sinkhole IPv6 Traffic In Mobile Users—GlobalProtect Deployments
        • Identification and Quarantine of Compromised Devices With Prisma Access
        • Support for Gzip Encoding in Clientless VPN
      • Report Website Access Issues
    • Use Remote Networks to Secure Branches
      • Plan to Deploy Remote Networks
      • Onboard and Configure Remote Networks
      • Plan to Migrate to an Aggregate Bandwidth Remote Network Deployment
        • Migrate to the Aggregate Bandwidth Model
      • Quick Configs for Remote Network Deployments
        • Remote Network Locations with Overlapping Subnets
        • Remote Network Locations with WAN Link
        • Use Predefined IPSec Templates to Onboard Service and Remote Network Connections
        • Onboard Remote Networks with Configuration Import
        • Configure Quality of Service in Prisma Access
        • Create a High-Bandwidth Network for a Remote Site
        • Provide Secure Inbound Access to Remote Network Locations
    • Configure User-ID and User-Based Policies with Prisma Access
      • Configure User-ID in Prisma Access
      • Configure User-ID for Remote Network Deployments
      • Configure Your Prisma Access Deployment to Retrieve Group Mapping
      • Redistribute User-ID Information Between Prisma Access and On-Premises Firewalls
      • Get User and Group Information Using the Cloud Identity Engine
    • Redistribute HIP Information and View HIP Reports
      • Redistribute HIP Information with Prisma Access
      • View HIP Reports from Panorama
    • Manage Multiple Tenants in Prisma Access
      • Multitenancy Overview
      • Multitenancy Configuration Overview
      • Plan Your Multitenant Deployment
        • Create an All-New Multitenant Deployment
      • Enable Multitenancy and Migrate the First Tenant
      • Add Tenants to Prisma Access
      • Delete a Tenant
      • Create a Tenant-Level Administrative User
      • Control Role-Based Access for Tenant-Level Administrative Users
      • Sort Logs by Device Group ID for External Logging
    • Prisma Access in a FedRAMP Environment
      • Panorama Managed Prisma Access and FedRAMP Authorization
      • Panorama Managed Prisma Access FedRAMP Requirements
      • Configure a Prisma Access FedRAMP Deployment
    • Use DLP With Prisma Access
      • DLP Integration with Prisma Access
    • IoT Security Integration with Prisma Access
      • Use IoT Security with Prisma Access
    • Create and Configure Prisma Access for Clean Pipe
      • Prisma Access for Clean Pipe Overview
      • Configure Prisma Access for Clean Pipe
    • Visibility and Monitoring Features in the Prisma Access App

    Prisma Access Administrator’s Guide (Panorama Managed)


    Version 2.2 Preferred

    PDF Cover Image
    Download PDF
    Last Updated:
    Nov 21, 2022
    Current Version:
    2.2 Preferred
    • Version 4.0 Preferred
    • Version 3.2 Preferred and Innovation
    • Version 3.1 Preferred and Innovation
    • Version 3.0 Preferred and Innovation
    • Version 2.2 Preferred
    • Version Prisma Access China

    Table of Contents


    Filter icon
    Filter
    Prisma Access Overview
    Prisma Access
    Prisma Access Infrastructure Management
    Releases and Upgrades
    Manage Upgrade Options for the GlobalProtect App
    Notifications and Alerts for Panorama, Cloud Services Plugin, and PAN-OS Dataplane Versions
    Prisma Access Licensing
    Monitor Your Data Transfer Usage
    Retrieve the IP Addresses for Prisma Access
    Plan for IP Address Changes for Mobile Users, Remote Networks, and Service Connections
    Service IP and Egress IP Address Allocation for Remote Networks
    How to Calculate Remote Network Bandwidth
    Prisma Access APIs
    Use Logging, Routing, and EDL Information to Troubleshoot Your Deployment
    Activate and Install the Prisma Access Components
    Activate and Install Prisma Access (Panorama Managed)
    Transfer or Update Prisma Access Licenses
    Reset Your Prisma Access License
    Transfer or Update Prisma Access Licenses Between Panorama Appliances
    Configure Panorama Appliances in High Availability for Prisma Access
    Prepare the Prisma Access Infrastructure and Service Connections
    Set Up Prisma Access
    Plan the Service Infrastructure and Service Connections
    Configure the Service Infrastructure
    Create a Service Connection to Allow Access to Your Corporate Resources
    Create a Service Connection to Enable Access between Mobile Users and Remote Networks
    Deployment Progress and Status
    How BGP Advertises Mobile User IP Address Pools for Service Connections and Remote Network Connections
    Use Traffic Steering to Forward Internet-Bound Traffic to Service Connections
    Routing Preferences for Service Connection Traffic
    Create a High-Bandwidth Network Using Multiple Service Connections
    List of Prisma Access Locations
    Secure Mobile Users with Prisma Access
    Plan To Deploy Prisma Access for Mobile Users
    Secure Mobile Users With GlobalProtect
    Secure Mobile Users with an Explicit Proxy
    Zone Mapping
    Specify IP Address Pools for Mobile Users
    How the GlobalProtect App Selects a Prisma Access Location for Mobile Users
    View Logged In User Information and Log Out Current Users
    Quick Configs for Mobile User Deployments
    Use Explicit Proxy to Secure Public Apps and GlobalProtect or a Third-Party VPN to Secure Private Apps
    Prisma Access with On-Premises Gateways
    Manage Priorities for Prisma Access and On-Premises Gateways
    Set Equal Gateway Priorities for On-Premises and Prisma Access Gateways
    Set a Higher Gateway Priority for an On-Premises Gateway
    Set Higher Priorities for Multiple On-Premises Gateways
    Configure Priorities for Prisma Access and On-Premises Gateways
    Allow Mobile Users to Manually Select Specific Prisma Access Gateways
    DNS Resolution for Mobile Users—GlobalProtect and Remote Network Deployments
    IPv6 Support for Private App Access
    Sinkhole IPv6 Traffic In Mobile Users—GlobalProtect Deployments
    Identification and Quarantine of Compromised Devices With Prisma Access
    Support for Gzip Encoding in Clientless VPN
    Report Website Access Issues
    Use Remote Networks to Secure Branches
    Plan to Deploy Remote Networks
    Onboard and Configure Remote Networks
    Plan to Migrate to an Aggregate Bandwidth Remote Network Deployment
    Migrate to the Aggregate Bandwidth Model
    Quick Configs for Remote Network Deployments
    Remote Network Locations with Overlapping Subnets
    Remote Network Locations with WAN Link
    Use Predefined IPSec Templates to Onboard Service and Remote Network Connections
    Onboard Remote Networks with Configuration Import
    Configure Quality of Service in Prisma Access
    Create a High-Bandwidth Network for a Remote Site
    Provide Secure Inbound Access to Remote Network Locations
    Configure User-ID and User-Based Policies with Prisma Access
    Configure User-ID in Prisma Access
    Configure User-ID for Remote Network Deployments
    Configure Your Prisma Access Deployment to Retrieve Group Mapping
    Redistribute User-ID Information Between Prisma Access and On-Premises Firewalls
    Get User and Group Information Using the Cloud Identity Engine
    Redistribute HIP Information and View HIP Reports
    Redistribute HIP Information with Prisma Access
    View HIP Reports from Panorama
    Manage Multiple Tenants in Prisma Access
    Multitenancy Overview
    Multitenancy Configuration Overview
    Plan Your Multitenant Deployment
    Create an All-New Multitenant Deployment
    Enable Multitenancy and Migrate the First Tenant
    Add Tenants to Prisma Access
    Delete a Tenant
    Create a Tenant-Level Administrative User
    Control Role-Based Access for Tenant-Level Administrative Users
    Sort Logs by Device Group ID for External Logging
    Prisma Access in a FedRAMP Environment
    Panorama Managed Prisma Access and FedRAMP Authorization
    Panorama Managed Prisma Access FedRAMP Requirements
    Configure a Prisma Access FedRAMP Deployment
    Use DLP With Prisma Access
    DLP Integration with Prisma Access
    IoT Security Integration with Prisma Access
    Use IoT Security with Prisma Access
    Create and Configure Prisma Access for Clean Pipe
    Prisma Access for Clean Pipe Overview
    Configure Prisma Access for Clean Pipe
    Visibility and Monitoring Features in the Prisma Access App
    • Prisma Access Overview
      • Prisma Access
      • Prisma Access Infrastructure Management
      • Releases and Upgrades
      • Manage Upgrade Options for the GlobalProtect App
      • Notifications and Alerts for Panorama, Cloud Services Plugin, and PAN-OS Dataplane Versions
      • Prisma Access Licensing
        • Monitor Your Data Transfer Usage
      • Retrieve the IP Addresses for Prisma Access
      • Plan for IP Address Changes for Mobile Users, Remote Networks, and Service Connections
      • Service IP and Egress IP Address Allocation for Remote Networks
      • How to Calculate Remote Network Bandwidth
      • Prisma Access APIs
      • Use Logging, Routing, and EDL Information to Troubleshoot Your Deployment
    • Activate and Install the Prisma Access Components
      • Activate and Install Prisma Access (Panorama Managed)
      • Transfer or Update Prisma Access Licenses
        • Reset Your Prisma Access License
        • Transfer or Update Prisma Access Licenses Between Panorama Appliances
      • Configure Panorama Appliances in High Availability for Prisma Access
    • Prepare the Prisma Access Infrastructure and Service Connections
      • Set Up Prisma Access
      • Plan the Service Infrastructure and Service Connections
      • Configure the Service Infrastructure
      • Create a Service Connection to Allow Access to Your Corporate Resources
      • Create a Service Connection to Enable Access between Mobile Users and Remote Networks
      • Deployment Progress and Status
      • How BGP Advertises Mobile User IP Address Pools for Service Connections and Remote Network Connections
      • Use Traffic Steering to Forward Internet-Bound Traffic to Service Connections
      • Routing Preferences for Service Connection Traffic
      • Create a High-Bandwidth Network Using Multiple Service Connections
      • List of Prisma Access Locations
    • Secure Mobile Users with Prisma Access
      • Plan To Deploy Prisma Access for Mobile Users
      • Secure Mobile Users With GlobalProtect
      • Secure Mobile Users with an Explicit Proxy
      • Zone Mapping
      • Specify IP Address Pools for Mobile Users
      • How the GlobalProtect App Selects a Prisma Access Location for Mobile Users
      • View Logged In User Information and Log Out Current Users
      • Quick Configs for Mobile User Deployments
        • Use Explicit Proxy to Secure Public Apps and GlobalProtect or a Third-Party VPN to Secure Private Apps
        • Prisma Access with On-Premises Gateways
        • Manage Priorities for Prisma Access and On-Premises Gateways
          • Set Equal Gateway Priorities for On-Premises and Prisma Access Gateways
          • Set a Higher Gateway Priority for an On-Premises Gateway
          • Set Higher Priorities for Multiple On-Premises Gateways
          • Configure Priorities for Prisma Access and On-Premises Gateways
          • Allow Mobile Users to Manually Select Specific Prisma Access Gateways
        • DNS Resolution for Mobile Users—GlobalProtect and Remote Network Deployments
        • IPv6 Support for Private App Access
        • Sinkhole IPv6 Traffic In Mobile Users—GlobalProtect Deployments
        • Identification and Quarantine of Compromised Devices With Prisma Access
        • Support for Gzip Encoding in Clientless VPN
      • Report Website Access Issues
    • Use Remote Networks to Secure Branches
      • Plan to Deploy Remote Networks
      • Onboard and Configure Remote Networks
      • Plan to Migrate to an Aggregate Bandwidth Remote Network Deployment
        • Migrate to the Aggregate Bandwidth Model
      • Quick Configs for Remote Network Deployments
        • Remote Network Locations with Overlapping Subnets
        • Remote Network Locations with WAN Link
        • Use Predefined IPSec Templates to Onboard Service and Remote Network Connections
        • Onboard Remote Networks with Configuration Import
        • Configure Quality of Service in Prisma Access
        • Create a High-Bandwidth Network for a Remote Site
        • Provide Secure Inbound Access to Remote Network Locations
    • Configure User-ID and User-Based Policies with Prisma Access
      • Configure User-ID in Prisma Access
      • Configure User-ID for Remote Network Deployments
      • Configure Your Prisma Access Deployment to Retrieve Group Mapping
      • Redistribute User-ID Information Between Prisma Access and On-Premises Firewalls
      • Get User and Group Information Using the Cloud Identity Engine
    • Redistribute HIP Information and View HIP Reports
      • Redistribute HIP Information with Prisma Access
      • View HIP Reports from Panorama
    • Manage Multiple Tenants in Prisma Access
      • Multitenancy Overview
      • Multitenancy Configuration Overview
      • Plan Your Multitenant Deployment
        • Create an All-New Multitenant Deployment
      • Enable Multitenancy and Migrate the First Tenant
      • Add Tenants to Prisma Access
      • Delete a Tenant
      • Create a Tenant-Level Administrative User
      • Control Role-Based Access for Tenant-Level Administrative Users
      • Sort Logs by Device Group ID for External Logging
    • Prisma Access in a FedRAMP Environment
      • Panorama Managed Prisma Access and FedRAMP Authorization
      • Panorama Managed Prisma Access FedRAMP Requirements
      • Configure a Prisma Access FedRAMP Deployment
    • Use DLP With Prisma Access
      • DLP Integration with Prisma Access
    • IoT Security Integration with Prisma Access
      • Use IoT Security with Prisma Access
    • Create and Configure Prisma Access for Clean Pipe
      • Prisma Access for Clean Pipe Overview
      • Configure Prisma Access for Clean Pipe
    • Visibility and Monitoring Features in the Prisma Access App

    © 2023 Palo Alto Networks, Inc. All rights reserved.

    Techdocs Logo