<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW at branch with SASE in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378240#M162</link>
    <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167333"&gt;@tabner&lt;/a&gt;&amp;nbsp; that's pretty quick.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really appreciate your feedback&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jan 2021 20:38:58 GMT</pubDate>
    <dc:creator>FWPalolearner</dc:creator>
    <dc:date>2021-01-06T20:38:58Z</dc:date>
    <item>
      <title>FW at branch with SASE</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378191#M158</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a customer having branches all across the globe but very very less MPLS . 95 % they are con,nected via IPSEC VPN Tunnels&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They have Fortinet Fortigate FWs at their Branches and DCs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Prisma Access need Palo Alto FW at each Branch ?&amp;nbsp; I believe only thing needed is to make an IPSEC Connection from Branch to the SASE cloud which even a Router at Branch can make . But just confirming ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I know Prisma Access need Panorama but does it need any PAN GW also ? In my case , all the GW at branches and DC are Fortigate ( Non PAN ) .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 19:04:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378191#M158</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2021-01-06T19:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: FW at branch with SASE</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378221#M159</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The only requirement at the branch is that the CPE can build an IPSec tunnel to Prisma Access.&amp;nbsp; So it doesn't matter which vendor it is.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You don't need a PAN NGFW or any other FW at the branches unless you need local (east-West) segmentation/security or to inspect traffic that you aren't sending to Prisma Access(e.g. MPLS traffic that won't traverse Prisma Access).&amp;nbsp; You could use a router to forward all traffic via an IPSec tunnel to Prisma Access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only recommendation for on-prem FWs is for sites where you have service connections.&amp;nbsp; These are the&amp;nbsp;connections to data centers for the branches and users to access internal shared resources (e.g. AD).&amp;nbsp; &amp;nbsp;The service connections are not subjected to policy so its recommended that you have a FW terminating the Service Connections&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 19:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378221#M159</guid>
      <dc:creator>tabner</dc:creator>
      <dc:date>2021-01-06T19:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: FW at branch with SASE</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378226#M160</link>
      <description>&lt;P&gt;Ok thanks a lot,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the fw where service.connection has to be terminated has to be a PANFw or any FW Like fortigate etc ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also , this means that only Palo Alto component needed other than primsa access cloud is panorama ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 20:09:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378226#M160</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2021-01-06T20:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: FW at branch with SASE</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378227#M161</link>
      <description>&lt;P&gt;Yup, any FW.&amp;nbsp; You must have Panorama and you also must have Cortex Data Lake for logging.&amp;nbsp; When you purchase Prisma Access, it always comes with data lake for logging.&amp;nbsp; You don't do hardly anything with the data lake after initial setup and that is pretty simple.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 20:22:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378227#M161</guid>
      <dc:creator>tabner</dc:creator>
      <dc:date>2021-01-06T20:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: FW at branch with SASE</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378240#M162</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167333"&gt;@tabner&lt;/a&gt;&amp;nbsp; that's pretty quick.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really appreciate your feedback&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 20:38:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/fw-at-branch-with-sase/m-p/378240#M162</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2021-01-06T20:38:58Z</dc:date>
    </item>
  </channel>
</rss>

