<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prisma Access Explicit Proxy  mode with globalprotect as an agent application. How does it work? in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-explicit-proxy-mode-with-globalprotect-as-an-agent/m-p/466161#M306</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just for information as I have not used Prisma Access with the globalprotect agent as an explicit proxy, this is supported right? I am asking this as I am interested in not pushing the PAC file to every browser but like the other SWG cloud solutions on the market to use an agent app on the end computer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also for connecting to the Prisma cloud what kind a tunnel is used if the globalprotect agent supports this (maybe ssl tunnel with pinned certificates or something else) or each browser needs to have palo alto plugins ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also can the explicit proxy mode work together with globalprotect VPN as for example the agent to send just web traffic to prisma access and the other traffic to the on prem firewalls ? I think this was not supported 2 yeast ago but now with Prima 3.0 maybe it is.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2022 11:51:32 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2022-02-16T11:51:32Z</dc:date>
    <item>
      <title>Prisma Access Explicit Proxy  mode with globalprotect as an agent application. How does it work?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-explicit-proxy-mode-with-globalprotect-as-an-agent/m-p/466161#M306</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just for information as I have not used Prisma Access with the globalprotect agent as an explicit proxy, this is supported right? I am asking this as I am interested in not pushing the PAC file to every browser but like the other SWG cloud solutions on the market to use an agent app on the end computer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also for connecting to the Prisma cloud what kind a tunnel is used if the globalprotect agent supports this (maybe ssl tunnel with pinned certificates or something else) or each browser needs to have palo alto plugins ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also can the explicit proxy mode work together with globalprotect VPN as for example the agent to send just web traffic to prisma access and the other traffic to the on prem firewalls ? I think this was not supported 2 yeast ago but now with Prima 3.0 maybe it is.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 11:51:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-explicit-proxy-mode-with-globalprotect-as-an-agent/m-p/466161#M306</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-02-16T11:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Explicit Proxy  mode with globalprotect as an agent application. How does it work?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-explicit-proxy-mode-with-globalprotect-as-an-agent/m-p/483121#M333</link>
      <description>&lt;P&gt;From what I read the Prisma Access Explicit proxy mode is still not integrated with a globalprotect agent and Microsoft AD GPIO policies will be needed to push the PAC file to the user devices:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-for-users/use-globalprotect-and-third-party-vpns-with-explicit-proxy/use-explicit-proxy-with-globalprotect-and-third-party-vpns-examples" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-for-users/use-globalprotect-and-third-party-vpns-with-explicit-proxy/use-explicit-proxy-with-globalprotect-and-third-party-vpns-examples&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As palo alto is a great product they just need to add this option the globalprotect agent to push the pac file settings to the computer system and web browsers as globalprotect can download this from the portal and an option for the globalprotect to review the PAC file and to auto exclude domains and destination ip addresses from entering the VPN (split tunnel) based on the PAC file will be nice. Also the globalprotect agent can add tolken header when sending the web traffic to Prisma Access and in this way cookies will not be needed as many 3-rth party cloud proxy vendors use endpoint&amp;nbsp; agents with some kind of tolkens for this as cookies cause issues with some sites, other proxy devices in between or browser settings and extensions that block the cookies. Also if the user is in the office then the on-prem firewall will be used but when the user is not an connects to Prisma Access for VPN then globalprotect may autodetect this and stop the Prisma Access Explicit Proxy PAC file settings and in this way with an agent there will be no need to make a gre/ipsec tunnel from the firewall to Prisma Access if the Firewall can't handle the SSL decryption as the Agent will direct the web traffic to Prisma access, using the PAC file even if the VPN is enabled as some companies use VPN even in the office for Security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope Palo Alto will start using the Globalprotect agent for Prisma Access Explicit Proxy mode and enable Prisma Access VPN and Prisma Access Proxy (for when the user VPN is connected to the on-prem firewalls or if the user is in the office and globalprotect has detected this using host detection DNS) to work together in the future.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 11:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-explicit-proxy-mode-with-globalprotect-as-an-agent/m-p/483121#M333</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-04-27T11:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Explicit Proxy  mode with globalprotect as an agent application. How does it work?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-explicit-proxy-mode-with-globalprotect-as-an-agent/m-p/531726#M468</link>
      <description>&lt;P&gt;In newer versions of the Globalprotect agent this seems to be added but only when the VPN tunnel is started then the proxy config is pushed by the Palo Alto Agent to the computer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-for-users/use-globalprotect-and-third-party-vpns-with-explicit-proxy/use-explicit-proxy-with-globalprotect" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-for-users/use-globalprotect-and-third-party-vpns-with-explicit-proxy/use-explicit-proxy-with-globalprotect&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe in the future even without a VPN tunnel the PAC file Proxy settings can be pushed for example for mobile users that connect to the internet using Palo Alto Prisma Access as an explicit proxy and the access to the internal applications is based on the Clientless VPN not full globalprotect tunnel.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 09:34:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-explicit-proxy-mode-with-globalprotect-as-an-agent/m-p/531726#M468</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-02-20T09:34:09Z</dc:date>
    </item>
  </channel>
</rss>

