
Explore Prisma Access within the SASE framework, covering cloud-delivered security, architecture, licensing, add-ons, and management options such as Panorama and cloud-managed Prisma Access, plus mobile and remote networks.
Presents SASE as a cloud-delivered fusion of network security and wide area networking, with identity-centric zero-trust access that unifies security and networking for secure, optimized access to apps from anywhere.
Understand why cloud delivered security and cloud delivered firewalls suit a hybrid workforce by providing scalable, global coverage with zero trust and centralized management.
Prisma Access delivers Palo Alto's cloud-delivered security service edge, extending next-gen firewall features to mobile and remote users with zero-trust access, app-ID, user-ID, and threat protection.
Prisma Access can be managed either from Panorama (physical or virtual appliance) or from the Palo Alto Hub Portal cloud platform, with only one management method used at a time.
Explain Prisma Access architecture with cloud-hosted nodes in AWS, Azure, or GCP and how mobile users connect via GP VPN or IPsec. Enforce unified security across internet, SaaS, on prem.
Prisma Access offers two licensing variants—mobile users and remote networks—with three editions (business, business premium, enterprise) and add-ons, priced by users or by site bandwidth.
Explain prisma access components—mobile gateways, service connections, remote networks, cortex data lake, and globalprotect portal—and how cloud-delivered firewalls secure mobile users and connect to on-prem data centers via ipsec vpn.
Explore Prisma Access gateways as cloud-delivered firewalls serving mobile users and remote networks; learn how GlobalProtect VPN secures IPsec/SSL connections, gateway provisioning, and portal-driven configuration.
Explore Prisma Access components, focusing on corporate access nodes that connect to on-prem and cloud data centers via IPsec VPN service connections.
Manage the GlobalProtect vpn portal in the Prisma Access cloud, configuring external and internal gateways, gateway priorities, authentication certificates, and host information profile data collection across regional nodes.
Provide VPN entry to the corporate network, internal apps, or internet via the SWG feature; GlobalProtect gateways in Prisma Access act as firewall gateways with license-based security enforcement.
Explore how Prisma Access routes traffic via automatic BGP peering between node types—service connection and corporate access nodes, portals, NSPs, and remote networks—based on geolocation, with optional redundancy.
Prisma Access enforces security only on internet-facing interfaces; traffic from the internet to the SVM is inspected, while internal or corporate-originated traffic receives no security enforcement.
Explore how internet connectivity works with Prisma Access: only security processing nodes provide internet reachability for mobile users and remote networks, while service connections and corporate access nodes do not.
Explore Prisma Access routing for mobile users, remote sites, and data centers, including VPN pool assignment, internet routing, IBGP-based route redistribution among service connections, and traffic steering options.
Compare Prisma Access service connection routing options, including the default internal routing via IBGP and hot potato routing that exits at the nearest service connection, with implications for asymmetric routing.
Default routing with service connections uses Prisma Access internal ibgp to decide egress. It routes traffic via the nearest service connection and, if needed, to another connection for data centers.
Explore how default routing with service connections directs mobile user traffic to data centers, how BGP advertises VPN pools in /24 chunks, and how to avoid asymmetric routing.
Explore how mobile users access remote networks and the internet through service connections, SPN nodes, and full-mesh IBGP routing, with failover and traffic steering for data centers.
Explore hot potato routing with Prisma Access service connections, comparing AS path prepends versus default routing, including primary/backup tunnels, BGP advertisements, and VPN pools routing to data centers.
Panorama automatically creates device groups and templates for mobile users, remote networks, and service connections, then pushes unified policies and QoS via template stacks.
Deploy Prisma Access by creating IPsec tunnels for service connections and remote networks, onboard those connections, and configure IBGP with a private ASN.
Configure Prisma Access lab topology with gateways and service connections, set up dynamic IPsec VPN with a GP VPN pool, and apply routing managed via Panorama and Cortex Data Lake.
Activate Prisma Access by installing the cloud service plugin on Panorama, verify compatibility between Panorama and the plugin, retrieve licenses, and use the activation OTP to verify and commit changes.
Configure the Prisma Access service setup infrastructure, including routing method selection (default or hot potato), internal domain lists with DNS servers, and Cortex Data Lake locations.
Configure prisma access by setting subnet, BGP, templates; define internal domains and DNS; associate cortex data lake; choose default or hot potato routing; commit to panorama and push to devices.
Learn the theory of service connection onboarding in Prisma Access, mapping IPsec tunnels, enabling backup connections with hot potato routing, and configuring routing (static, BGP), QoS, and logging.
Onboard a Prisma Access service connection by configuring service connection templates, creating an IPsec gateway and tunnel, enabling NAT traversal, and applying static routes.
Configure a site-to-site ipsec vpn between the data center firewall and prisma access service connection, using ip for the gateway, enabling nat traversal, and validating with the tunnel interface.
Learn how Prisma Access uses trust and untrust security zones, and how zone mapping with Panorama enables reuse of existing firewall policies across Prisma Access and remote sites.
Explore portal onboarding theory for Prisma Access, detailing mobile user connectivity via GlobalProtect or clientless VPN, DNS configuration, service connection nodes, IP pools, and agent settings.
Onboard a GlobalProtect portal for Prisma Access mobile users by configuring templates, zones, and a portal with a local authentication profile, then push and validate deployments.
Configure mobile user policies in Palo Alto Prisma Access SASE to enable VPN, internet access, and data center access, including log forwarding to Cortex Data Lake.
Install the GlobalProtect agent, connect to the GP cloud service, and verify VPN access from Bahrain. Validate traffic to internet and data center via Prisma Access using logs and policies.
Create clientless apps under the mobile user template, add internal applications by url or ip, group them into clientless app groups, and assign users to access groups via the portal.
Enable the egress IP allow list to prevent auto provisioning of new public IPs. Onboard via the mobile GlobalProtect portal, confirm allowed egress IPs for SaaS apps, and push changes.
Generate an API key from the Panorama cloud service plugin, then fetch Prisma Access infrastructure IP addresses for mobile user gateway and other nodes via API.
Learn how to onboard remote networks to Prisma Access using IPsec VPN, configure locations, IPsec tunnel termination, routing, QoS, bandwidth, and security policies from trust to trust.
Onboard a remote network to Prisma Access by enabling settings, mapping trust and untrust zones, and provisioning an IPsec VPN gateway in Bahrain with bandwidth and routes.
Learn how to onboard a remote network with Prisma Access SASE, configure an IPsec gateway and tunnel, set up routing, and test connectivity.
Explore inbound access for remote networks, enabling an internet-facing server with a public IP. Prisma Access creates a node to accept external connections and route them to private IP addresses.
Use cloud service plugin troubleshooting commands to verify logging status for mobile users and remote networks, and to view service connection routing tables including bgp and static route information.
Learn how Prisma Access logs forward to the Cortex Data Lake and how Panorama views them, then configure log forwarding profiles and forward to an on-prem SIEM via https.
Prisma Access automatically applies dynamic source NAT for mobile users and remote networks accessing internet or SaaS, with no manual NAT rules, and helps prevent asymmetric routing.
Explore how Prisma Access handles DNS configurations across service setup, mobile gateways, and remote networks, including internal vs cloud DNS, DNS proxy behavior, and IP address handling.
Explore how Prisma Access traffic steering routes internet-bound traffic for mobile and remote users via service connections or direct internet, using criteria like source, destination, and ports.
Explore the mobile user explicit proxy, a security processing node (spn) used to provide secure internet access without corporate resources, configured via pac files or manual pointing with authentication.
Explore the Palo Alto SASE status portal to monitor cloud services, regional availability, and outage history, and subscribe to email or text alerts for planned upgrades and incidents.
Explore multi-tenancy in Prisma Access, dividing a single license (e.g., 1000 users, five service connections, 1 gigabit remote bandwidth) into tenants with dedicated service connections, users, and bandwidth.
Learn about PaloAlto's Prisma Access which is a leading Security Solution for corporate adopting cloud and/or adopting hybrid working models. Prisma Access is a component of Palo Alto SASE portfolio. We will cover the different Prisma Access solutions i.e. Prisma Access for Mobile Users and Prisma Access for Remote Networks. We will go through below topics using Theory and Labs-
Introduction to SASE and need of cloud delivered security
Introduction to Prisma Access
Prisma Access Architecture
Prisma Access Components
Licenses required with Prisma Access Mobile Users, Remote Networks and add-ons like CASB
Routing options with Prisma Access, including a lot of routing scenarios
Types of Prisma Access Nodes, which enforce security and which don't
Onboarding Prisma Access Portal & locations for Mobile users to provide secure connectivity to Data Center applications and Secure Internet access
Onboarding Remote Network Connections to connect corporate branch offices securely to Data Centers and Internet
NAT with Prisma Access for traffic going to Internet or internal apps
How DNS and Prisma Access relate with each other for the different components
Check availability of Prisma Access Infrastructure and configure notifications to stay updated about incidents, issues or planned maintenance
Cortex Data Lake which is Palo Alto's cloud logging service - theory only
Troubleshooting steps