<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring Prisma Access Remote networks and Service Connections on the same device/site in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/configuring-prisma-access-remote-networks-and-service/m-p/421504#M212</link>
    <description>&lt;P&gt;Hi everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to know what would be the challenges to deploy Service Connection and Remote Networks on the same device/site and what would be the best solution or workaround as per PAN best practices&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per my understanding, if we deploy Service Connection and Remote Networks then, there could be some routing challenges&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a standard config for RN, we have the default route towards the RN tunnel and also a route towards the infrastructure subnet in the RN configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Service Connection also we have route towards the service infrastructure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now when the MU comes to Service connection to access some resources, the return route will be having 2 options RN default route and SVC advertised route&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is a eg. LDAP request from MU that can use infra subnet and both RN and SVC will have that route causing Asymetric routing issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it a feasible solution to have SVC and RN on same node/site, if yes what all things are required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jul 2021 21:28:12 GMT</pubDate>
    <dc:creator>DheerajDixit</dc:creator>
    <dc:date>2021-07-22T21:28:12Z</dc:date>
    <item>
      <title>Configuring Prisma Access Remote networks and Service Connections on the same device/site</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/configuring-prisma-access-remote-networks-and-service/m-p/421504#M212</link>
      <description>&lt;P&gt;Hi everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to know what would be the challenges to deploy Service Connection and Remote Networks on the same device/site and what would be the best solution or workaround as per PAN best practices&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per my understanding, if we deploy Service Connection and Remote Networks then, there could be some routing challenges&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a standard config for RN, we have the default route towards the RN tunnel and also a route towards the infrastructure subnet in the RN configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Service Connection also we have route towards the service infrastructure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now when the MU comes to Service connection to access some resources, the return route will be having 2 options RN default route and SVC advertised route&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is a eg. LDAP request from MU that can use infra subnet and both RN and SVC will have that route causing Asymetric routing issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it a feasible solution to have SVC and RN on same node/site, if yes what all things are required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 21:28:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/configuring-prisma-access-remote-networks-and-service/m-p/421504#M212</guid>
      <dc:creator>DheerajDixit</dc:creator>
      <dc:date>2021-07-22T21:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Prisma Access Remote networks and Service Connections on the same device/site</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/configuring-prisma-access-remote-networks-and-service/m-p/424685#M219</link>
      <description>&lt;P&gt;Why not just use Remote network SPN connection if you need firewall capabilities (this is needed if you don't have next generation Firewall in the data center otherwise the service connection is used) for filtering traffic going out of the Data Center ? With Remote Network again the internal DNS servers, Ldap servers and etc that are behind the Remote Network SPN can be accessed by Prisma Access or mobile users or other Remote Network Sites?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just as an info If you need a service infrastructure/connection because of the mobile users routing you can create a fake one without the ipsec tunnel being up and use the SPN for filtering traffic comming from your DC and allowing traffic to your DC from mobile users or other SPN remote networks for services like internal DNS , LDAP etc.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 11:23:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/configuring-prisma-access-remote-networks-and-service/m-p/424685#M219</guid>
      <dc:creator>NikolayDimitrov</dc:creator>
      <dc:date>2021-08-05T11:23:20Z</dc:date>
    </item>
  </channel>
</rss>

