<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Instructions and Best Practices guide for setting up Prisma cloud for Azure Container Registry and Azure Kubernetes Service in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574862#M1160</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have referred docs from compute edition. I understand compute edition is self-managed where you run prisma-cloud console as a docker container within your cluster. We are planning to use Prisma-cloud enterprise edition where we will be using prisma-cloud console provided by the enterprise edition and deploy defender in AKS to send details to prisma-cloud in SAAS. So my question is after I deploy defender in my AKS cluster as daemonset, it automatically communicates to SAAS prisma-cloud console right? I don't need any additional configuration either in AKS or in Prisma-cloud console right? Also our AKS is a private cluster. So how to make the daemonset communicate to prisma-cloud console. Is it via HTTP Proxy?&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jan 2024 05:22:40 GMT</pubDate>
    <dc:creator>clakshmikanthan</dc:creator>
    <dc:date>2024-01-30T05:22:40Z</dc:date>
    <item>
      <title>Instructions and Best Practices guide for setting up Prisma cloud for Azure Container Registry and Azure Kubernetes Service</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574398#M1151</link>
      <description>&lt;P&gt;Looking for Instructions and Best Practices guide for setting up Prisma cloud for Azure Container Registry and Azure Kubernetes Service&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 06:49:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574398#M1151</guid>
      <dc:creator>clakshmikanthan</dc:creator>
      <dc:date>2024-01-25T06:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Instructions and Best Practices guide for setting up Prisma cloud for Azure Container Registry and Azure Kubernetes Service</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574492#M1152</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133155959"&gt;@clakshmikanthan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the Doc To Configure Azure Container Registry -&amp;nbsp;&lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/vulnerability-management/registry-scanning/scan-acr" target="_self"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/vulnerability-management/registry-scanning/scan-acr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additional Docs to Configure Prisma Cloud on AKS Cluster&amp;nbsp;&lt;A href="https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-console/console-on-aks" target="_self"&gt;https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-console/console-on-aks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-defender/orchestrator/orchestrator" target="_self"&gt;https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-defender/orchestrator/orchestrator&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let us know if you need additional help.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 16:58:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574492#M1152</guid>
      <dc:creator>SNimmagadda</dc:creator>
      <dc:date>2024-01-25T16:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Instructions and Best Practices guide for setting up Prisma cloud for Azure Container Registry and Azure Kubernetes Service</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574683#M1154</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/278088"&gt;@SNimmagadda&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133155959"&gt;@clakshmikanthan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the Doc To Configure Azure Container Registry -&amp;nbsp;&lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/vulnerability-management/registry-scanning/scan-acr" target="_self"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/vulnerability-management/registry-scanning/scan-acr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additional Docs to Configure Prisma Cloud on AKS Cluster&amp;nbsp;&lt;A href="https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-console/console-on-aks" target="_self"&gt;https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-console/console-on-aks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-defender/orchestrator/orchestrator" target="_self"&gt;https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-defender/orchestrator/orchestrator&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let us know if you need additional help.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;Thank You Very much. Appreciate your support. &lt;BR /&gt;I have a question. I understand by integrating Prisma Cloud with Azure Container Registry, Vulnerability scanning of container images uploaded to ACR will automatically happen and the report will be generated.&amp;nbsp;&lt;BR /&gt;What about the prisma cloud defenders in AKS. Will it also scan any image deployed in AKS automatically? Once the Daemon set is installed in AKS what additional steps we have to do ? what benefit will it give?&lt;BR /&gt;2. Is there a best practice guidelines on using and configuring Prisma wrt AKS and Azure container registry.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 05:59:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574683#M1154</guid>
      <dc:creator>clakshmikanthan</dc:creator>
      <dc:date>2024-01-29T05:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Instructions and Best Practices guide for setting up Prisma cloud for Azure Container Registry and Azure Kubernetes Service</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574756#M1155</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133155959"&gt;@clakshmikanthan&lt;/a&gt;&amp;nbsp; Thanks for reaching out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN&gt;After deploying a Defender to a Cluster, it can immediately protect and monitor your containers and host. No additional steps are required to rebuild your containers with an agent inside.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN&gt;Here is The Defender Architecture&amp;nbsp;to refer&amp;nbsp;&lt;A href="https://docs.prismacloud.io/en/compute-edition/32/admin-guide/technology-overviews/defender-architecture" target="_self"&gt;https://docs.prismacloud.io/en/compute-edition/32/admin-guide/technology-overviews/defender-architecture&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;Please refer to the below Doc on how the Defender works after it is installed.&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN&gt;&lt;A href="https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-defender/defender-types" target="_blank"&gt;https://docs.prismacloud.io/en/compute-edition/32/admin-guide/install/deploy-defender/defender-types&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN&gt;Please let us know if this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 15:59:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574756#M1155</guid>
      <dc:creator>SNimmagadda</dc:creator>
      <dc:date>2024-01-29T15:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Instructions and Best Practices guide for setting up Prisma cloud for Azure Container Registry and Azure Kubernetes Service</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574862#M1160</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have referred docs from compute edition. I understand compute edition is self-managed where you run prisma-cloud console as a docker container within your cluster. We are planning to use Prisma-cloud enterprise edition where we will be using prisma-cloud console provided by the enterprise edition and deploy defender in AKS to send details to prisma-cloud in SAAS. So my question is after I deploy defender in my AKS cluster as daemonset, it automatically communicates to SAAS prisma-cloud console right? I don't need any additional configuration either in AKS or in Prisma-cloud console right? Also our AKS is a private cluster. So how to make the daemonset communicate to prisma-cloud console. Is it via HTTP Proxy?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 05:22:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574862#M1160</guid>
      <dc:creator>clakshmikanthan</dc:creator>
      <dc:date>2024-01-30T05:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Instructions and Best Practices guide for setting up Prisma cloud for Azure Container Registry and Azure Kubernetes Service</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574946#M1167</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133155959"&gt;@clakshmikanthan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;If you have Created below Prerequisites for Console-defender Communication.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;deploying the defender in AKS Cluster&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;will communicate to Console.&lt;/P&gt;
&lt;P class="p3"&gt;&lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/welcome/nat-gateway-ip-addresses" target="_blank"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/welcome/nat-gateway-ip-addresses&lt;/A&gt;&lt;/P&gt;
&lt;P class="p3"&gt;&lt;A href="https://docs.prismacloud.io/en/classic/cspm-admin-guide/get-started-with-prisma-cloud/enable-access-prisma-cloud-console" target="_blank"&gt;https://docs.prismacloud.io/en/classic/cspm-admin-guide/get-started-with-prisma-cloud/enable-access-prisma-cloud-console&lt;/A&gt;&lt;/P&gt;
&lt;P class="p3"&gt;Prisma® Cloud uses NAT gateway IP addresses. To ensure that you can access Prisma Cloud and the API for any integrations that you enabled between Prisma Cloud and your incidence response workflows, or your agentless deployment or &lt;STRONG&gt;the Prisma Cloud Defenders to communicate with the Prisma Cloud Compute Console,&lt;/STRONG&gt; review the list and update the IP addresses in your allow lists&lt;/P&gt;
&lt;P class="p3"&gt;&lt;A href="https://docs.prismacloud.io/en/classic/cspm-admin-guide/get-started-with-prisma-cloud/enable-access-prisma-cloud-console#idcb6d3cd4-d1bf-450a-b0ec-41c23a4d4280" target="_self"&gt;https://docs.prismacloud.io/en/classic/cspm-admin-guide/get-started-with-prisma-cloud/enable-access-prisma-cloud-console#idcb6d3cd4-d1bf-450a-b0ec-41c23a4d4280&lt;/A&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p3"&gt;In Prisma Cloud Enterprise Edition (SaaS platform for Compute), the Defender websocket connects to Console on port 443 (not configurable).&lt;/P&gt;
&lt;P class="p3"&gt;If egress connections through Proxy Require authentication. Here is the doc to configure&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;web proxy in HTTP Proxy&lt;/P&gt;
&lt;P class="p3"&gt;&lt;A href="https://docs.prismacloud.io/en/classic/compute-admin-guide/configure/proxy" target="_self"&gt;https://docs.prismacloud.io/en/classic/compute-admin-guide/configure/proxy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please let me know if this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 15:52:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/instructions-and-best-practices-guide-for-setting-up-prisma/m-p/574946#M1167</guid>
      <dc:creator>SNimmagadda</dc:creator>
      <dc:date>2024-01-30T15:52:36Z</dc:date>
    </item>
  </channel>
</rss>

