Verify the NGFW and Remote Browser Isolation Integration
Focus
Focus
Remote Browser Isolation

Verify the NGFW and Remote Browser Isolation Integration

Table of Contents

Verify the NGFW and Remote Browser Isolation Integration

Confirm the IPSec tunnel is active, internet traffic egresses through Prisma® Access, and Remote Browser Isolation isolation is working correctly.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by PAN-OS or Panorama)
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access license with Remote Networks license subscription
  • Remote Browser Isolation license
  • Strata Cloud Manager Pro license
After pushing the configuration, verify that the tunnel is active, traffic is routing through Prisma Access, and RBI isolation is triggering for the configured URL categories.
  1. Confirm the IPSec tunnel is active on the NGFW.
    1. On the NGFW, select NetworkIPSec Tunnels and confirm the tunnel shows a green status.
  2. Confirm internet traffic egresses through Prisma Access.
    1. From an endpoint behind the NGFW, open a browser and navigate to a site that returns your public IP address (for example, https://ifconfig.me).
    2. Confirm the IP address shown is a Prisma Access egress IP, not the NGFW's public IP.
      If the NGFW's public IP is returned, the tunnel is not carrying traffic. Check the static route and confirm that SNAT is not configured on the tunnel interface.
  3. Confirm RBI isolation is active.
    1. From the same endpoint, navigate to a site in an isolated URL category (for example, a news or sports site).
    2. Confirm the page loads with the RBI notification banner and Floating Action Button (FAB) visible, indicating isolation is active.
    3. Navigate to a non-isolated site (for example, a search engine) and confirm the page loads normally with no RBI banner, confirming pass-through behavior for trusted categories.
  4. Verify log visibility.
    1. On the NGFW, select MonitorLogsTraffic and confirm sessions from branch endpoints show as egressing via tunnel.1.
    2. In Strata Cloud Manager, select InsightsAdvanced URL Filtering and confirm URL filtering events are visible with the correct source IP attribution.