<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log out SASE without any alert in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/log-out-sase-without-any-alert/m-p/430264#M247</link>
    <description>&lt;P&gt;My company has just introduced prisma access (SASE) in this year.&lt;/P&gt;&lt;P&gt;According to increasing telecommuing and business trip, the concept of SASE is greate and fit to our requirement that everyone can use and external netwrok like an internal network always.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the way, there is a very weird contraint on global protect agent which should ensure network availabliity at all time based on SASE concept.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;The maximum log-in life time is 365 days, means that everyone who are working using a global protect suddenly loses their network service witohout any prior notice after 1year.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The meaning of VPN in SASE concetp, it is not a temporary internal network use, but a main business purpose network.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Why there is no slection for Permanet on life-time configuration?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;How to explain to my employees on this matter?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;EM&gt;"After 1 year since Global Protect log-in, your network will be suddenly cut off. So, don't do any impotant work at this time or please use annual leaving".&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;EM&gt;In add&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I already know that maintaining cookie permanently is one of the security risk.&lt;/P&gt;&lt;P&gt;But also it has some problem the connection would be broken.&lt;/P&gt;&lt;P&gt;SASE concept means it provides all security environment which was set by companies policy.&lt;/P&gt;&lt;P&gt;But if SASE connection was broken we can't maintain our policy.&lt;/P&gt;&lt;P&gt;Because User's will not log in SASE because it control their Device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Than it may causes security accident like security leak. (They can also access to malware websites)&lt;/P&gt;&lt;P&gt;It would be risk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Does this make sense??????????&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 31 Aug 2021 01:59:08 GMT</pubDate>
    <dc:creator>Prisma_Admin</dc:creator>
    <dc:date>2021-08-31T01:59:08Z</dc:date>
    <item>
      <title>Log out SASE without any alert</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/log-out-sase-without-any-alert/m-p/430264#M247</link>
      <description>&lt;P&gt;My company has just introduced prisma access (SASE) in this year.&lt;/P&gt;&lt;P&gt;According to increasing telecommuing and business trip, the concept of SASE is greate and fit to our requirement that everyone can use and external netwrok like an internal network always.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the way, there is a very weird contraint on global protect agent which should ensure network availabliity at all time based on SASE concept.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;The maximum log-in life time is 365 days, means that everyone who are working using a global protect suddenly loses their network service witohout any prior notice after 1year.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The meaning of VPN in SASE concetp, it is not a temporary internal network use, but a main business purpose network.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Why there is no slection for Permanet on life-time configuration?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;How to explain to my employees on this matter?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;EM&gt;"After 1 year since Global Protect log-in, your network will be suddenly cut off. So, don't do any impotant work at this time or please use annual leaving".&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#0000FF"&gt;&lt;EM&gt;In add&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I already know that maintaining cookie permanently is one of the security risk.&lt;/P&gt;&lt;P&gt;But also it has some problem the connection would be broken.&lt;/P&gt;&lt;P&gt;SASE concept means it provides all security environment which was set by companies policy.&lt;/P&gt;&lt;P&gt;But if SASE connection was broken we can't maintain our policy.&lt;/P&gt;&lt;P&gt;Because User's will not log in SASE because it control their Device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Than it may causes security accident like security leak. (They can also access to malware websites)&lt;/P&gt;&lt;P&gt;It would be risk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Does this make sense??????????&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 01:59:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/log-out-sase-without-any-alert/m-p/430264#M247</guid>
      <dc:creator>Prisma_Admin</dc:creator>
      <dc:date>2021-08-31T01:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Log out SASE without any alert</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/log-out-sase-without-any-alert/m-p/430554#M248</link>
      <description>&lt;P&gt;Using a cookie without an expiration is a security risk. To allow devices to connect seamlessly without depending on the cookie authentication lifetime is better to use certificates (machine/user). It is also a best practice.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 19:30:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/log-out-sase-without-any-alert/m-p/430554#M248</guid>
      <dc:creator>SuperMario</dc:creator>
      <dc:date>2021-08-31T19:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Log out SASE without any alert</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/log-out-sase-without-any-alert/m-p/430642#M249</link>
      <description>&lt;P&gt;Thanks for your comment. Using a certificate is just one of option we can choose.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we talk about security or security risk, it should be after availavility is secured in advance.&lt;/P&gt;&lt;P&gt;In case of prisma, there is no control function against unspecified network cut-off !!!!!!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 00:03:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/log-out-sase-without-any-alert/m-p/430642#M249</guid>
      <dc:creator>Prisma_Admin</dc:creator>
      <dc:date>2021-09-01T00:03:58Z</dc:date>
    </item>
  </channel>
</rss>

