<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prisma access palo alto privileged remote access (PRA) adding an app in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-palo-alto-privileged-remote-access-pra-adding-an/m-p/1222021#M123408</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is it possible to add an application for PRA by making use of Wildcard FQDN or IP subnet range?&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2025 11:24:59 GMT</pubDate>
    <dc:creator>heyheyyoyojj</dc:creator>
    <dc:date>2025-02-26T11:24:59Z</dc:date>
    <item>
      <title>Prisma access palo alto privileged remote access (PRA) adding an app</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-palo-alto-privileged-remote-access-pra-adding-an/m-p/1222021#M123408</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is it possible to add an application for PRA by making use of Wildcard FQDN or IP subnet range?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 11:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-palo-alto-privileged-remote-access-pra-adding-an/m-p/1222021#M123408</guid>
      <dc:creator>heyheyyoyojj</dc:creator>
      <dc:date>2025-02-26T11:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma access palo alto privileged remote access (PRA) adding an app</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-palo-alto-privileged-remote-access-pra-adding-an/m-p/1222028#M123409</link>
      <description>&lt;P&gt;Yes, it is possible to add an application for Prisma Remote Access (PRA) by using Wildcard FQDN or IP subnet range, but the approach depends on the specific configuration and security policies in place.&lt;/P&gt;
&lt;P&gt;Options for Defining Applications in PRA:&lt;BR /&gt;&lt;STRONG&gt;Wildcard FQDN (Fully Qualified Domain Name)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;PRA allows the use of wildcard FQDNs to define applications when domain-based policies are required.&lt;BR /&gt;Example: *.example.com can be used to match any subdomain under example.com.&lt;BR /&gt;This is useful when the application has dynamic subdomains that are difficult to list individually.&lt;BR /&gt;&lt;STRONG&gt;IP Subnet Range&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Instead of defining individual IPs, you can specify a subnet (e.g., 192.168.1.0/24) to include multiple IP addresses within that range.&lt;BR /&gt;This method works well for applications hosted in a known range of IP addresses.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 13:05:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-palo-alto-privileged-remote-access-pra-adding-an/m-p/1222028#M123409</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2025-02-26T13:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma access palo alto privileged remote access (PRA) adding an app</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-palo-alto-privileged-remote-access-pra-adding-an/m-p/1222029#M123410</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Suresh,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thanks for the swift response.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;May I know what will be the user experince or User interface look like if I use wildcard fqdn(*Suresh.com)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;is it like user once logged in the pra portal, they can have a box to type in the requested fqdn (abc.Suresh.com)?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 13:53:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-palo-alto-privileged-remote-access-pra-adding-an/m-p/1222029#M123410</guid>
      <dc:creator>heyheyyoyojj</dc:creator>
      <dc:date>2025-02-26T13:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma access palo alto privileged remote access (PRA) adding an app</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-palo-alto-privileged-remote-access-pra-adding-an/m-p/1225399#M123849</link>
      <description>&lt;P&gt;If you configure a wildcard FQDN (*.suresh.com) for an application in Prisma Access Remote Access (PRA), the user experience (UX) will depend on how the access is set up. Here’s how it typically works:&lt;/P&gt;
&lt;P&gt;1. User Login to the PRA Portal&lt;BR /&gt;The user logs into the PRA portal using their credentials (e.g., SSO, username/password).&lt;/P&gt;
&lt;P&gt;After authentication, they will land on the PRA App Portal.&lt;/P&gt;
&lt;P&gt;2. Application Access with Wildcard FQDN&lt;BR /&gt;Scenario 1: If the Wildcard FQDN is Used for an Application&lt;BR /&gt;When an app is added with a wildcard FQDN (*.suresh.com), users will NOT see a manual text box to enter a subdomain.&lt;/P&gt;
&lt;P&gt;Instead, the available applications will be displayed as icons/links on the PRA App Portal.&lt;/P&gt;
&lt;P&gt;If multiple subdomains exist (e.g., abc.suresh.com, xyz.suresh.com), these need to be explicitly added as separate apps in the portal for users to see them.&lt;/P&gt;
&lt;P&gt;User Experience:&lt;/P&gt;
&lt;P&gt;The user clicks on an app in the portal (e.g., app1.suresh.com) and is redirected.&lt;/P&gt;
&lt;P&gt;If wildcard FQDNs are used for internal routing, users will be able to access abc.suresh.com, xyz.suresh.com, etc., but they won’t have an input box to enter their own subdomain.&lt;/P&gt;
&lt;P&gt;Scenario 2: If Using a Wildcard FQDN in Security Policies&lt;BR /&gt;If the wildcard FQDN is used in Security Policies, it applies to all matching subdomains.&lt;/P&gt;
&lt;P&gt;The user will not notice any UI change but will experience access control based on policy rules.&lt;/P&gt;
&lt;P&gt;3. Can Users Enter a Custom FQDN (abc.suresh.com)?&lt;BR /&gt;No, PRA does not provide a manual input box for users to enter a custom subdomain dynamically.&lt;/P&gt;
&lt;P&gt;However, if you configure a generic internal web portal that allows users to enter a subdomain manually, they could enter abc.suresh.com and be redirected.&lt;/P&gt;
&lt;P&gt;Final Summary&lt;BR /&gt;Feature Wildcard FQDN (*.suresh.com)&lt;BR /&gt;UI Experience No manual input box; users see predefined app links&lt;BR /&gt;Access Behavior Users can access multiple subdomains if configured&lt;BR /&gt;Dynamic Subdomain Entry Not supported directly in PRA Portal&lt;BR /&gt;Security Policy Controls access to all matching subdomains&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 05:26:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prisma-access-palo-alto-privileged-remote-access-pra-adding-an/m-p/1225399#M123849</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2025-04-02T05:26:59Z</dc:date>
    </item>
  </channel>
</rss>

