<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma Access as a Replacement for GlobalProtect and Security Inspection Platform – Seeking Real-World Feedback in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265614#M1329</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129161627"&gt;@alirezabtf&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="4,0"&gt;Building on the points above, here are a few additional technical considerations and best practices based on real-world migrations from on-premises GlobalProtect to Prisma Access:&lt;/P&gt;
&lt;P data-path-to-node="4,0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="4,1"&gt;1. Security &amp;amp; Feature Parity&lt;/P&gt;
&lt;P data-path-to-node="4,2"&gt;Because Prisma Access runs native PAN-OS under the hood, you get full inspection parity for WildFire, Advanced Threat Prevention, Advanced URL Filtering, and DNS Security.&lt;/P&gt;
&lt;UL data-path-to-node="4,3"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,3,0,0"&gt;SSL Decryption &amp;amp; Enterprise DLP: Capabilities match on-prem firewalls, but you will want to review your decryption bypass lists early. Decrypting heavily pinned or certificate-bound applications will require fine-tuning your SSL profiles in Panorama or Strata Cloud Manager.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="4,4"&gt;2. Performance &amp;amp; Optimization&lt;/P&gt;
&lt;UL data-path-to-node="4,5"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,5,0,0"&gt;SaaS Optimization / Traffic Steering: For real-time media applications (Microsoft 365, Teams, Zoom), leverage Split Tunneling / SaaS Direct Breakout. Hairpinning high-volume UDP video/audio streams through full SSL inspection often introduces artificial latency and degrades user experience.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,5,1,0"&gt;Egress IP Whitelisting: Because Prisma Access uses dynamic cloud egress nodes, third-party SaaS vendors that mandate static source IP whitelisting will require you to assign Dedicated Egress IPs in Prisma Access or route that specific traffic back through a Service Connection.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="4,6"&gt;3. Visibility &amp;amp; Troubleshooting&lt;/P&gt;
&lt;UL data-path-to-node="4,7"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,7,0,0"&gt;Logging: All logs stream natively to Strata Logging Service (SLS), giving you unified User-ID, App-ID, and Threat visibility across all remote endpoints.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,7,1,0"&gt;Autonomous DEM (ADEM): On-prem firewalls rely on local interface statistics, but Prisma Access relies heavily on Prisma Access Insights (PAI) and ADEM. ADEM is particularly critical—it provides synthetic hop-by-hop telemetry from the client endpoint, through the GlobalProtect app, across the Prisma Cloud node, and out to the target application.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="4,8"&gt;4. Key Architectural Considerations&lt;/P&gt;
&lt;UL data-path-to-node="4,9"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,9,0,0"&gt;Service Connections: Ensure adequate bandwidth is allocated to your Service Connections (the IPSec tunnels connecting Prisma Access back to your corporate datacenters/HQ).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,9,1,0"&gt;Cloud Identity Engine (CIE): Deploy CIE early to handle User-ID and group mapping seamlessly in the cloud without relying on on-prem Domain Controller log forwarding.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope these provide more insights.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;</description>
    <pubDate>Mon, 05 Oct 2026 14:11:15 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2026-10-05T14:11:15Z</dc:date>
    <item>
      <title>Prisma Access as a Replacement for GlobalProtect and Security Inspection Platform – Seeking Real-World Feedback</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265125#M1327</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are currently evaluating Prisma Access as a replacement for our traditional GlobalProtect deployment and are considering using Prisma Access as our primary cloud-delivered security platform for remote users.&lt;/P&gt;
&lt;P&gt;Our goal is to leverage the full security stack, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;URL Filtering&lt;/LI&gt;
&lt;LI&gt;WildFire&lt;/LI&gt;
&lt;LI&gt;DNS Security&lt;/LI&gt;
&lt;LI&gt;Advanced Threat Prevention&lt;/LI&gt;
&lt;LI&gt;DLP&lt;/LI&gt;
&lt;LI&gt;SSL Decryption&lt;/LI&gt;
&lt;LI&gt;SaaS Visibility and Control&lt;/LI&gt;
&lt;LI&gt;User and Application Visibility&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For organizations that have already made this transition, I would appreciate hearing about your experience.&lt;/P&gt;
&lt;P&gt;Some questions we have are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Have you encountered any issues or unexpected challenges after moving to Prisma Access?&lt;/LI&gt;
&lt;LI&gt;Are you able to perform all required security inspections successfully?&lt;/LI&gt;
&lt;LI&gt;Do you feel you have the same level of visibility as you had with on-premises Palo Alto firewalls?&lt;/LI&gt;
&lt;LI&gt;Have you experienced any visibility gaps, blind spots, or troubleshooting challenges?&lt;/LI&gt;
&lt;LI&gt;How effective are the logging, monitoring, and reporting capabilities?&lt;/LI&gt;
&lt;LI&gt;Have you had any concerns related to SSL decryption, DLP, or user experience?&lt;/LI&gt;
&lt;LI&gt;Have you noticed any increase in latency, application slowness, or performance issues after directing traffic through Prisma Access for inspection?&lt;/LI&gt;
&lt;LI&gt;Were there any applications or services that required special handling or exceptions to maintain acceptable performance&lt;/LI&gt;
&lt;LI&gt;We are particularly interested in understanding whether organizations have been able to achieve full inspection and maintain complete visibility after moving security services to Prisma Access.
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Any feedback, concerns, recommendations, or lessons learned would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;Thank you in advance for sharing your experience.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2026 14:23:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265125#M1327</guid>
      <dc:creator>alirezabtf</dc:creator>
      <dc:date>2026-09-28T14:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access as a Replacement for GlobalProtect and Security Inspection Platform – Seeking Real-World Feedback</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265418#M1328</link>
      <description>&lt;P&gt;Transitioning from traditional GlobalProtect to Prisma Access generally delivers robust security parity and excellent cloud scalability, but most organizations encounter initial hurdles with SSL decryption overhead, complex troubleshooting across remote nodes, and occasional latency spikes requiring strategic traffic steering (such as local breakout for trusted SaaS apps like Zoom or Microsoft 365). While you achieve the same comprehensive visibility and full stack inspection as on-prem Palo Alto firewalls, success heavily depends on properly sizing remote networks, fine-tuning decryption policies to avoid user friction, and leveraging tools like Prisma Access Insights for effective log monitoring.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2026 10:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265418#M1328</guid>
      <dc:creator>ronald59pepper</dc:creator>
      <dc:date>2026-10-01T10:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access as a Replacement for GlobalProtect and Security Inspection Platform – Seeking Real-World Feedback</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265614#M1329</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129161627"&gt;@alirezabtf&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="4,0"&gt;Building on the points above, here are a few additional technical considerations and best practices based on real-world migrations from on-premises GlobalProtect to Prisma Access:&lt;/P&gt;
&lt;P data-path-to-node="4,0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="4,1"&gt;1. Security &amp;amp; Feature Parity&lt;/P&gt;
&lt;P data-path-to-node="4,2"&gt;Because Prisma Access runs native PAN-OS under the hood, you get full inspection parity for WildFire, Advanced Threat Prevention, Advanced URL Filtering, and DNS Security.&lt;/P&gt;
&lt;UL data-path-to-node="4,3"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,3,0,0"&gt;SSL Decryption &amp;amp; Enterprise DLP: Capabilities match on-prem firewalls, but you will want to review your decryption bypass lists early. Decrypting heavily pinned or certificate-bound applications will require fine-tuning your SSL profiles in Panorama or Strata Cloud Manager.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="4,4"&gt;2. Performance &amp;amp; Optimization&lt;/P&gt;
&lt;UL data-path-to-node="4,5"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,5,0,0"&gt;SaaS Optimization / Traffic Steering: For real-time media applications (Microsoft 365, Teams, Zoom), leverage Split Tunneling / SaaS Direct Breakout. Hairpinning high-volume UDP video/audio streams through full SSL inspection often introduces artificial latency and degrades user experience.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,5,1,0"&gt;Egress IP Whitelisting: Because Prisma Access uses dynamic cloud egress nodes, third-party SaaS vendors that mandate static source IP whitelisting will require you to assign Dedicated Egress IPs in Prisma Access or route that specific traffic back through a Service Connection.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="4,6"&gt;3. Visibility &amp;amp; Troubleshooting&lt;/P&gt;
&lt;UL data-path-to-node="4,7"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,7,0,0"&gt;Logging: All logs stream natively to Strata Logging Service (SLS), giving you unified User-ID, App-ID, and Threat visibility across all remote endpoints.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,7,1,0"&gt;Autonomous DEM (ADEM): On-prem firewalls rely on local interface statistics, but Prisma Access relies heavily on Prisma Access Insights (PAI) and ADEM. ADEM is particularly critical—it provides synthetic hop-by-hop telemetry from the client endpoint, through the GlobalProtect app, across the Prisma Cloud node, and out to the target application.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-path-to-node="4,8"&gt;4. Key Architectural Considerations&lt;/P&gt;
&lt;UL data-path-to-node="4,9"&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,9,0,0"&gt;Service Connections: Ensure adequate bandwidth is allocated to your Service Connections (the IPSec tunnels connecting Prisma Access back to your corporate datacenters/HQ).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-path-to-node="4,9,1,0"&gt;Cloud Identity Engine (CIE): Deploy CIE early to handle User-ID and group mapping seamlessly in the cloud without relying on on-prem Domain Controller log forwarding.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope these provide more insights.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 14:11:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265614#M1329</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-10-05T14:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access as a Replacement for GlobalProtect and Security Inspection Platform – Seeking Real-World Feedback</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265653#M1330</link>
      <description>&lt;P&gt;Thanks a lot for clear explanation&lt;BR /&gt;Are we able to do the split tunnel for our zoom and teams call for minimize the latency&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 20:12:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265653#M1330</guid>
      <dc:creator>alirezabtf</dc:creator>
      <dc:date>2026-10-05T20:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access as a Replacement for GlobalProtect and Security Inspection Platform – Seeking Real-World Feedback</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265682#M1331</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129161627"&gt;@alirezabtf&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Yes you can.&amp;nbsp; Under N&lt;SPAN class="uicontrol"&gt;etwork&lt;/SPAN&gt;&lt;SPAN&gt; &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;GlobalProtect&lt;/SPAN&gt;&lt;SPAN&gt; &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Gateways&lt;/SPAN&gt;&lt;SPAN&gt; &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="varname"&gt;&amp;lt;gateway-config&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Agent&lt;/SPAN&gt;&lt;SPAN&gt; &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="varname"&gt;&amp;lt;agent-config&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; &amp;gt; &lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Client Settings &amp;gt; Split Tunnel&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="Table_Cell"&gt;&lt;SPAN class="uicontrol"&gt;Add&lt;/SPAN&gt; the complete path of each application process for which you want to exclude the traffic from your VPN tunnel. These applications are sent through the physical adapter on endpoints rather than the virtual adapter (the tunnel). You can add up to 200 entries to the list.&lt;/DIV&gt;
&lt;DIV class="Table_Cell"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="Table_Cell"&gt;For example, to exclude traffic from the RingCentral application:&lt;/DIV&gt;
&lt;DIV class="Table_Cell"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI class="Table_Cell"&gt;For Windows endpoints, add &lt;SPAN class="userinput"&gt;%AppData%\Local\RingCentral\SoftPhoneApp\Softphone.exe&lt;/SPAN&gt; and &lt;SPAN class="userinput"&gt;%AppData%\Local\RingCentral\SoftPhoneApp\SoftphoneMapiBridge.exe&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="Table_Cell"&gt;&lt;SPAN&gt;For macOS endpoints, add &lt;/SPAN&gt;&lt;SPAN&gt;/Applications/RignCentral for Mac.app/Contents/MacOS/Softphone&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="Table_Cell"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="Table_Cell"&gt;If you do not enable split tunneling, every request is routed through the tunnel.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="Table_Cell"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="Table_Cell"&gt;Hope this helps,&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Oct 2026 08:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-as-a-replacement-for-globalprotect-and-security/m-p/1265682#M1331</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-10-06T08:24:30Z</dc:date>
    </item>
  </channel>
</rss>

