<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zones in Remote Networks in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/zones-in-remote-networks/m-p/511564#M390</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we are onboarding the first remote network sites and we tried to map the preexisting zones from our shared internet-policies to the trust and untrust zones.&lt;/P&gt;
&lt;P&gt;But inside the traffic logs, we can see, that traffic from the remote networks are coming from a zone, with the name of the remote network.&lt;/P&gt;
&lt;P&gt;I would have guest, that these are all in the "trust" zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now the big question is, how to fix that, so we can use our preexisting global internet access policies?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Johannes&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2022 13:28:30 GMT</pubDate>
    <dc:creator>jo.schoensa</dc:creator>
    <dc:date>2022-08-11T13:28:30Z</dc:date>
    <item>
      <title>Zones in Remote Networks</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/zones-in-remote-networks/m-p/511564#M390</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we are onboarding the first remote network sites and we tried to map the preexisting zones from our shared internet-policies to the trust and untrust zones.&lt;/P&gt;
&lt;P&gt;But inside the traffic logs, we can see, that traffic from the remote networks are coming from a zone, with the name of the remote network.&lt;/P&gt;
&lt;P&gt;I would have guest, that these are all in the "trust" zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now the big question is, how to fix that, so we can use our preexisting global internet access policies?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Johannes&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 13:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/zones-in-remote-networks/m-p/511564#M390</guid>
      <dc:creator>jo.schoensa</dc:creator>
      <dc:date>2022-08-11T13:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Zones in Remote Networks</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/zones-in-remote-networks/m-p/511835#M394</link>
      <description>&lt;P&gt;Better check your zone mapping to be certain. Also the link below has something that could be helpfull.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-----&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV style="display: inline;"&gt;When creating zones, do not use any of the following names for the zones, because these are names used for internal zones:
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV style="display: inline;"&gt;
&lt;UL&gt;
&lt;LI class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class=""&gt;
&lt;DIV style="display: inline;"&gt;trust&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class=""&gt;
&lt;DIV style="display: inline;"&gt;untrust&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class=""&gt;
&lt;DIV style="display: inline;"&gt;inter-fw&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class=""&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV class=""&gt;
&lt;DIV style="display: inline;"&gt;Any name you use for the remote networks (remote network names are used as the source zone in Cortex Data Lake logs)
&lt;P&gt;Prisma Access logs that display a zone of inter-fw are logs used for communication within the Prisma Access infrastructure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-overview/zone-mapping" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-overview/zone-mapping&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 15 Aug 2022 11:40:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/zones-in-remote-networks/m-p/511835#M394</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-08-15T11:40:46Z</dc:date>
    </item>
  </channel>
</rss>

