<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prisma Access routing between tenants ? in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-routing-between-tenants/m-p/520317#M427</link>
    <description>&lt;P&gt;Hello to All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After reading much about this I am starting to think that internal routing between the Prisma Access tenants is not possible and the traffic should be send with Traffic Steering to a router that is on-prem and connected to the two tenants or use &lt;SPAN&gt;&lt;EM&gt;use a dedicated service connection&lt;/EM&gt;&lt;/SPAN&gt; with the traffic stearing but then the two tenants will talk with one another through the external Prisma Access public Ip addresses and not the internal ones.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-advanced-deployments/service-connection-advanced-deployments/use-traffic-forwarding-rules-with-service-connections" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-advanced-deployments/service-connection-advanced-deployments/use-traffic-forwarding-rules-with-service-connections&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could be wrong but this seems the only way but this is a little limiting as for example to stop SIP ALG function of the SIP application is done with per device group and for a prisma access only one device group is used so this can't be stopped for a&amp;nbsp; just single Remote Network connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEsCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEsCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/disable-the-sip-application-level-gateway-alg" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/disable-the-sip-application-level-gateway-alg&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Nov 2022 13:10:07 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2022-11-04T13:10:07Z</dc:date>
    <item>
      <title>Prisma Access routing between tenants ?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-routing-between-tenants/m-p/520317#M427</link>
      <description>&lt;P&gt;Hello to All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After reading much about this I am starting to think that internal routing between the Prisma Access tenants is not possible and the traffic should be send with Traffic Steering to a router that is on-prem and connected to the two tenants or use &lt;SPAN&gt;&lt;EM&gt;use a dedicated service connection&lt;/EM&gt;&lt;/SPAN&gt; with the traffic stearing but then the two tenants will talk with one another through the external Prisma Access public Ip addresses and not the internal ones.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-advanced-deployments/service-connection-advanced-deployments/use-traffic-forwarding-rules-with-service-connections" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-advanced-deployments/service-connection-advanced-deployments/use-traffic-forwarding-rules-with-service-connections&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could be wrong but this seems the only way but this is a little limiting as for example to stop SIP ALG function of the SIP application is done with per device group and for a prisma access only one device group is used so this can't be stopped for a&amp;nbsp; just single Remote Network connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEsCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEsCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/disable-the-sip-application-level-gateway-alg" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/disable-the-sip-application-level-gateway-alg&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 13:10:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-routing-between-tenants/m-p/520317#M427</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-11-04T13:10:07Z</dc:date>
    </item>
  </channel>
</rss>

