<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma explicit proxy for on-premises servers? in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1226867#M1141</link>
    <description>&lt;P&gt;Sorry but you I think you need to dig dipper and to test things. I also shared that you can use trusted source ip addresses my second post that does not need kerberos, also SPN connection can also host servers as mentioned in&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/prisma-access-discussions/can-the-internal-dns-server-be-behind-spn-not-a-can/td-p/417558" target="_blank"&gt;Can the internal DNS server be behind SPN not a CAN?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Apr 2025 23:56:05 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2025-04-17T23:56:05Z</dc:date>
    <item>
      <title>Prisma explicit proxy for on-premises servers?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1225957#M1128</link>
      <description>&lt;P&gt;Hi Palo experts!&lt;/P&gt;
&lt;P&gt;Do you know if Prisma explicit proxy can be used for on-Orem servers’ internet sccess?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have few small sites with two segments: remote networks (for users) and server subnet (which is reachable via service connection from Prisma MU).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i do not have interconnect license neither on-prem proxy to be used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you think it’s possible to use explicit proxy in this case to let servers access the internet with Prisma Access policies?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Kasper&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 16:30:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1225957#M1128</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2025-04-08T16:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma explicit proxy for on-premises servers?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1226636#M1138</link>
      <description>&lt;P&gt;You can but you will need to use kerberos for your servers&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/kerberos-authentication-for-explicit-proxy-deployments" target="_blank"&gt;Kerberos Authentication for Explicit Proxy Deployments&lt;/A&gt;&amp;nbsp;as it is what palo alto recommends for authenticating your servers to the prisma access explicit proxy. The supported authentication is the issue by Prisma Access for not web browser users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still if that is not an option then you may need to deploy palo alto firewall in one location and maybe steer the outbound server Internet traffic to that location with vpn tunnels to the firewall (2 FW in HA active/standby) as to exit from the firewall after being checked. This way you will not need to deploy firewalls in all locations and as only server updates of the software and apps in most cases will generate internet traffic it shouldn't be that much.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 05:17:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1226636#M1138</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2025-04-16T05:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma explicit proxy for on-premises servers?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1226651#M1139</link>
      <description>&lt;P&gt;Also I forgot to mention if you don't want authentication then but just to trust and decrypt the server traffic based on IP addrresses then see the options below but if possible source the server traffic with specific dedicated public ip address:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/how-explicit-proxy-identifies-users" target="_blank"&gt;How Explicit Proxy Identifies Users&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-explicit-proxy/set-up-explicit-proxy#tabs-id1b210867-53e3-4c99-9dff-d84d25f4a062" target="_blank"&gt;Set Up Explicit Proxy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 05:28:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1226651#M1139</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2025-04-16T05:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma explicit proxy for on-premises servers?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1226706#M1140</link>
      <description>&lt;P&gt;Thank you Nikoolayy1,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have PAN220 in every site, it's not a problem, but I have no security licenses there.&lt;/P&gt;
&lt;P&gt;Thus I do not want to open all traffic from the server to the internet, but use Prisma instead.&lt;/P&gt;
&lt;P&gt;Servers will be in the "SC" network, not "RN".&lt;/P&gt;
&lt;P&gt;I saw in Palo documents that the connection from LAN to explicit proxy should use RN tunnel.&lt;/P&gt;
&lt;P&gt;I'm afraid the kerberos authentication issues - I have no idea what apps will be used on the servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At the moment, the only solution I can imagine is web proxy (squid?), in "Prisma RN enabled LAN" and configured on the servers (for apps that supports proxy), and static internet access policies for the ones that does not support it (I would need to know the destination).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Kacper&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2025 10:20:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1226706#M1140</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2025-04-16T10:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma explicit proxy for on-premises servers?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1226867#M1141</link>
      <description>&lt;P&gt;Sorry but you I think you need to dig dipper and to test things. I also shared that you can use trusted source ip addresses my second post that does not need kerberos, also SPN connection can also host servers as mentioned in&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/prisma-access-discussions/can-the-internal-dns-server-be-behind-spn-not-a-can/td-p/417558" target="_blank"&gt;Can the internal DNS server be behind SPN not a CAN?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 23:56:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-explicit-proxy-for-on-premises-servers/m-p/1226867#M1141</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2025-04-17T23:56:05Z</dc:date>
    </item>
  </channel>
</rss>

