
Explore traditional hub-and-spoke branch architecture using MPLS backhaul to data centers, its cloud migration implications, and the shift to SD-WAN with internet breakout to cut costs while preserving security.
Explore the challenges of traditional hub-and-spoke vpn architecture, including backhaul to data centers, uneven performance, and visibility gaps, and see how SASE and Prisma Access address them.
Explore how the organization's perimeter expands to everywhere as apps move to cloud and users work from anywhere, and how Prisma Access secures access across data centers and SaaS.
Learn how SASE enables secure user access to data and applications from anywhere by cloud-native delivery, with identity-based and location-based policies, zero-trust, CASB, DNS security, and SD-WAN.
Explore Prisma Access overview and architecture with cloud-based next-gen firewalls, management via Panorama, global presence, zero trust with least privilege, app-based policies, threat protection, and Cortex Data Lake for analytics.
Explore Prisma Access for networks, delivering cloud-based security processing nodes with app id, url filtering, and threat prevention, while enabling direct internet and SaaS access and data center connectivity.
Prisma Access for users provides vpn with app id, url filtering, dlp, and threat prevention. It enables access to data centers, internet, and saas for unmanaged, agent-based, and pac users.
Explore benefits of a software as a service design model for Prisma Access SASE, including OpEx shift, pay-as-you-go usage, operational simplicity, auto scaling, global distribution, and inherited certifications.
Explore prisma access planning and design, covering licensing, management options, service infrastructure, BGP routing, IPsec connectivity, DNS resilience, Global Protect portals and gateways, and redundancy strategies.
Explore Prisma access licensing, including editions (business, business premium, enterprise) and local versus worldwide flavors. Understand add-ons like next-gen casb, RBI, GTN, data transfer, Cortex data lake, and panorama considerations.
Explore cloud managed Prisma Access with the Estata Cloud Manager, featuring a single pane of glass, predefined security policies, and integrated threat prevention.
Explore Panorama managed Prisma Access and its single pane for on-prem and cloud deployments, reusing existing policies, device groups, and templates.
Discover the Prisma Access service infrastructure, the cloud foundation that connects mobile users, data centers, and branch offices, and plan subnets, IP addresses, and BGP ASN to prevent routing conflicts.
Plan a RFC 1918 compliant, private, non-overlapping service infrastructure subnet for Prisma Access, avoid overlapping with internal networks and VPN pools, size for growth, and consult Palo Alto.
Plan BGP for dynamic route discovery between Prisma access and remote offices or data centers. Use static routing or RFC 6996 private-use numbers, with default 65534 if BGP isn't required.
Plan service connections by identifying data centers and hub offices, selecting IPsec devices, provisioning internet circuits with redundancy, and configuring IPsec settings, routing, tunnel monitoring, and panorama-managed service reachability.
Plan remote networks by identifying branch offices, selecting Prisma Access locations near them for local content, and configuring IPsec, templates, device groups, aggregate bandwidth model, and routing (static or BGP).
Explore the aggregate bandwidth model for Prisma Access, comparing compute locations with Prisma Access locations, and learn how bandwidth is allocated to compute locations via IPsec termination nodes.
Explore mobile user deployment planning for GlobalProtect in Prisma Access, covering location selection, VPN IP pools, DNS resilience, gateway options, and connection methods.
Design resilient service connections by enforcing redundancy at every layer, from Prisma Access with HA and dual compute locations, to dual IPsec tunnels, data center firewalls, and dual internet circuits.
Explore resiliency and redundancy design for remote networks using Prisma Access, with single and multiple IPsec tunnels, active/standby HA, and multi-location compute options.
Explain how branch users reach region-specific data centers via Prisma Access, remote security processing node, and service connection, with failover to the other data center when tunnels fail.
Explain how branch-to-remote-user traffic flows through Prisma Access NPN, service connection, and the mu gateway in hub and spoke topology, with no direct path from remote networks to mobile gateways.
Explore traffic between branch offices in Prisma Access as a full-mesh of RNAs exchanging routes via IBGP, enabling transit through RNAs connected to each site.
Understand how remote users access branch office resources through Prisma access using a hub-and-spoke service connection, with a full-mesh cloud core and strategic failover options.
Demonstrates how remote users connect to prisma access via globalprotect, routing through mobile gateways to data centers, with service connections and ipsec tunnels, and failover to data centers for resilience.
Explore how mobile users connect through Prisma Access with hub-and-spoke traffic flow via service connections, enabling reachability and redundancy for mobile onboarding.
Explore how traffic from data center one travels through a Prisma Access service connection to data center two, with routing checks at each hop and sync between data centers.
Learn how Prisma Access achieves default routing without backbone connectivity by using ibgp between regions, advertising mobile gateway subnets to data centers, and routing traffic via the Prisma Access backbone.
Learn how Prisma Access uses default routing with a backbone network between data centers, advertising and selecting BGP routes, enabling cross-region traffic and resilient failover.
Explore Prisma Access hot potato routing, where IBGP and BGP route traffic to the nearest service connection across data centers, using prepend values for primary and backup paths.
Explore Prisma sd-wan architecture, including the controller, remote office and data center io devices, and a carrier-agnostic underlay that builds a secure overlay fabric with IPsec.
Explore Prisma sd-wan design considerations, including cloud-based versus on-prem portal controllers, data center and branch site sizing, device and circuit choices, and high availability.
Explore prisma sd-wan devices across branch offices and data centers. Review hardware and software models, ports such as controller, bypass, poe, and multi-gig ports, plus cellular support on select models.
Design high-availability for branch offices using dual sd-wan devices with active and backup states and dual isp links. Utilize bypass mode to extend connectivity and maintain heartbeat-based failover.
Learn high-availability design for data centers with an active-active data center cluster of SD-WAN devices and BGP-based routing for redundant, symmetric paths to branch offices.
Design a scalable data center using region-based SD-WAN clusters with BGP, connecting to MPLS and internet clouds, ensuring redundancy and future capacity for branch offices.
Explore how the Prisma Access GTN connector enables zero trust network access to private data center apps through automatic tunnels from GT to the GTA connector.
Define GTN connected components: connectors, connector groups, and targets. Deploy connectors as VMs to build IPsec tunnels from data centers to Prisma Access for private applications.
Explore ZTNA connector use cases for overlapped private networks with Prisma access and IPsec. Onboard GTN connectors in data centers and clouds, enforcing least-privilege access.
Compare the GTN connector and service connection in Prisma Access, highlighting automatic tunnel establishment and location discovery with GTN, overlapped network access, and ten gbps versus one gbps throughput.
Explains GTN connector supported hosting environments and provides deployment configurations for AWS, Google Cloud, Azure, KVM, and VMware ESX with required CPU, memory, and disk sizes.
Meet the network prerequisites to enable the ztna connector, including mtu under 1300, open udp ports 4500/500 and tcp 443, dns resolution, and reserving ip blocks for Prisma Access.
Learn how ZTNA connectors enable remote users to access private data center apps via Prisma Access, using application IP blocks, connector IP blocks, NAT, and DNS resolution.
Enable the GTN connector from Panorama by configuring application IP blocks, advertising those blocks to remote networks, configuring connector IP blocks, and onboarding the connector via the Prisma Access app.
Configure the GTN connector in Prisma Access by creating a connector group, adding connectors, onboarding with key and secret, and defining wild card, Fqdn, and IP subnet targets.
Learn to onboard a GTN connector in VMware ESXi for Prisma Access SASE, including downloading the OVA, deploying the template, configuring WAN/LAN, and verifying the tunnel.
Access Prisma Access hub to upgrade GTN connector through the connector group where it is hosted, then install now or schedule the upgrade and cancel up to five minutes prior.
Master a planning checklist to activate Prisma Access for Panorama Managed, including activation email/link, cloud service plugin requirements, DNS and NTP configuration, and CSP portal verification.
Activate prisma access for panorama managed via the CSP portal by selecting the purchased product, linking the license to a CSP account, and configuring tenant and Cortex data lake region.
Learn how to onboard Prisma Access to Panorama by generating an OTP, installing cloud service plugins, retrieving licenses, verifying accounts, and configuring device groups for seamless integration.
Configure Prisma Access service infrastructure in Panorama by setting infrastructure subnet, internal domains, Cortex Data Lake theater, routing and logging options, then commit, push, and verify Cortex Data Lake status.
Explore predefined IPsec tunnels and gateways in Prisma Access for third-party sd-wan devices. Learn how to reuse, customize, or backup these configurations via Panorama Service Connection and remote network templates.
Learn to configure an IPsec tunnel for Prisma Access service connections via Panorama, including creating a new IPsec tunnel, AI gateway, crypto profiles, tunnel monitoring, and committing changes.
Configure a Panorama-managed Prisma Access service connection with static routes by onboarding the connection, naming it, selecting the nearest Prisma Access location, and selecting or creating IPsec tunnels.
Configure a service connection with BGP routing from Panorama to Prisma Access, enable route summarization and no export community, then commit and push to Prisma Access.
Explore templates and template stacks in Panorama to configure firewall settings, including interface, zone, logging, and syslog, then group them into stacks and push to firewalls with priority-based conflict resolution.
Explore device groups in SD-WAN networks, Panorama, and Palo Alto firewalls to group policies and objects by data centers, branches, or regions within a hierarchical device group structure.
Explore device group hierarchy in sd-wan design, nesting shared, data center, and branch policies across multi-level groups, with up to four nested levels and policy propagation to firewalls.
Leverage device groups to implement a layered policy model, pushing shared pre, post, and default rules from Panorama while enabling region, data center, and branch specific controls.
Understand how device group objects define scope across shared and local groups, how inheritance and duplication determine object precedence in policies.
Prisma Access creates predefined templates and template stacks for explicit proxy, mobile user, remote network, and service connection; you can reuse templates or device groups by adding them to stacks.
Explore Prisma Access zones, including trust, untrust, and clientless VPN, and how Prisma Access manages zones and interfaces while customers create security policies mapped to these zones.
Configure remote networks in Panorama by setting the remote network template stack and device group, optionally reusing existing templates. Then commit and push the changes to Prisma Access remote networks.
Configure remote network zones in Panorama, create remote trust and remote untrust zones, and map them to Prisma Access zones before committing and pushing to the Prisma Access cloud.
Allocate bandwidth for remote networks in Prisma Access by selecting the compute location and Mbps, then commit and post the changes to Prisma Access.
Configure a remote network with a single IPsec tunnel and static routes in Panorama, then push the settings to Prisma Access and verify deployment status.
Onboard remote networks with a single ipsec tunnel and bgp in prisma access, configuring the ipsec termination node, predefined templates, and optional backup paths.
Onboard a remote network with multiple IPsec tunnels and ICMP load balancing (ECMP), enable BGP, and configure default route advertising for Prisma Access.
Learn how to configure mobile user templates and device groups in Prisma Access, manage a parent device group with inherited security policies via Panorama, and commit and push changes.
Configure a ldap server profile and an authentication profile in Panorama to onboard mobile users to Prisma Access using Active Directory, with scope, binding details, and tls options, then commit.
Onboard mobile users to Prisma Access using GlobalProtect by configuring portal settings, SSL/TLS profiles, authentication, internal host detection, network redundancy, IP pools, DNS, and location-based gateways.
Verify mobile users with globalprotect in prisma access, validate deployment and config status, view current and last 90 days users, and monitor regional map views for troubleshooting.
Learn to configure split tunneling for GlobalProtect users in Prisma Access by adjusting default configs, including or excluding networks, domains, and apps, then push changes to mobile gateways.
Learn how to configure mobile users' GlobalProtect app settings in Prisma Access, including connect methods, disable and uninstall controls, upgrade options, sign-on, and single sign-on with SAML.
Explore GlobalProtect app settings for mobile users, including credential handling on logout, Kerberos and SAML authentication, VPN restoration timers, captive portal, notification options, and certificate renewal.
Learn to upgrade the GlobalProtect app for mobile users in Prisma Access via Panorama, including activation and commit and push of the new version.
Learn to upgrade the GlobalProtect app in stages within Prisma Access by cloning the default config, assigning a batch user group, selecting prompts, and pushing changes for phased deployment.
Discover how explicit proxy works with Prisma Access: a pac file routes browser traffic to the proxy, where ssl decryption, saml authentication via acs, and policy checks govern access.
Configure explicit proxy in prisma access with valid licenses and ssl decryption for https traffic. Enforce tls 1.3, note http/2 downgrades, and plan for pac file, idp reachability, saml authentication.
Configure a single pac file in prisma access, upload after onboarding explicit proxy, and include at least one proxy URL with IPv4, plus bypass rules for identity provider and acs.
Learn to configure Azure AD SAML for explicit proxy by creating a SAML identity provider, importing metadata into Panorama, and building an authentication profile for Prisma Access explicit proxy.
The Prisma Access SASE Security: Design and Operation (EDU-318) course describes Panorama Managed Prisma Access Secure Access Service Edge (SASE) and how it helps organizations embrace cloud and mobility by providing network and network security services from the cloud. This course is intended for people in public cloud security and cybersecurity or anyone wanting to learn how to secure remote networks and mobile users by using the Prisma SASE provided by Palo Alto.
Objectives
Successful completion of this course will help enhance your understanding of how to protect better your applications, remote networks, and mobile users using a SASE implementation. You will get hands-on experience configuring, managing, and troubleshooting Prisma Access.
Target Audience
Security Engineers, Security Administrators, Security Operations Specialists, Security Analysts, and Network Engineers.
Prerequisites
Participants should have a basic knowledge of cloud computing and the public cloud. Participants must complete the Firewall Essentials: Configuration and Management course (EDU-210) and the Panorama: Managing Firewalls at Scale course (EDU-220) or have equivalent experience. Participants also must have experience with networking concepts, including routing, switching, and IP addressing.
Course Modules
1. Prisma Access Overview
2- Planning and Design
3- Routing and SD-WAN Design
4- Zero Trust Network Access (ZTNA) Connector
5- Activate and Configure
6- Security Processing Nodes
7- Panorama Operations for Prisma Access
8- Remote Networks
9- Mobile Users
10- Cloud Secure Web Gateway
11- Tune, Optimize, and Troubleshoot
12- Manage Multiple Tenants
13- Insights
14- ADEM