Proxy Chaining from Prisma Access Explicit Proxy to Third-party Proxy
Focus
Focus
What's New in the NetSec Platform

Proxy Chaining from Prisma Access Explicit Proxy to Third-party Proxy

Table of Contents

Proxy Chaining from Prisma Access Explicit Proxy to Third-party Proxy

This feature allows sequential flow of traffic through multiple proxies.
To allow secure upstream proxy integration from Prisma Access explicit proxy deployments to a cloud-based or on-premises proxy solution, you can use proxy chaining. This functionality establishes a sequential pathway by routing the traffic through multiple proxy servers sequentially by utilizing the existing network infrastructure, thereby enhancing security and compliance. To configure proxy chaining, you create profiles with the upstream proxy server’s IP address or FQDN and port number, and create rules to define the criteria to route traffic through upstream proxy servers.
With this enhancement, you can:
  • Route traffic to the cloud or on-premises upstream proxy servers based on source IP address, URL category, usernames, and user groups.
  • Connect Prisma Access explicit proxy infrastructure to a third-party cloud-based or on-prem proxies without extensive reconfiguration.
  • Connect to upstream proxy over TLS to secure plain text data between proxies.
  • Share X-Forwarded-For (XFF) and X-Authenticated-User (XAU) headers with upstream proxy servers.