Prisma Access Discussions
Prisma Access secures access to the cloud for branch offices and mobile users anywhere in the world with a scalable, cloud-native architecture that will soon be managed via a new streamlined cloud management UI.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Prisma Access Discussions
Prisma Access secures access to the cloud for branch offices and mobile users anywhere in the world with a scalable, cloud-native architecture that will soon be managed via a new streamlined cloud management UI.
About Prisma Access Discussions
Prisma Access secures access to the cloud for branch offices and mobile users anywhere in the world with a scalable, cloud-native architecture that will soon be managed via a new streamlined cloud management UI.

Discussions

Welcome to the Prisma Access Discussions!

To make this forum valuable and enjoyable for everyone, please review the following guidelines before participating: Rules and Best Practices Be Respectful: Treat fellow community members with professionalism and courtesy. Constructive discussions are encouraged; disrespectful or inflammatory comments are not. Stay On-Topic: This board is d...

JayGolf by Community Team Member
  • 2615 Views
  • 0 replies
  • 1 Likes

Understanding Prisma Access Syslog Header & messages

Hello Team, I am working on Prisma Access syslog csv format. We are able to forward & receive csv logs successfully. Now, I am trying to understand the format. I could able to understand the message part as all the field details are provided in the Palo Alto documentation clearly. However, header is where I am looking for little clarity. Fol...

Resolved! GitHub Pages Blocked but Accessible on Vercel: Seeking Help

I don't know why my blog has been blocked. It's statically deployed through GitHub Pages, and the same code is deployed on Vercel with a vercel.app domain, which is accessible. However, it's classified as a phishing site when accessed via github.io. Even the security officer at my company cannot pinpoint the specific reason, so I'm asking for he...

스크린샷 2024-04-15 08.59.58.png

DNS not resolving through Prisma Access for a particular domain

We have a hostname that doesn't get resolved by DNS while running through Prisma Access. It works fine if you are off the internal network. I know DNS is proxied via Prisma Access so I'm wondering how to fix this issue. If I bypass DNS (entry in the hosts file) it works correctly. If I query the hostname from a workstation to 8.8.8.8 I don'...

Resolved! Moving from GP to Prisma access - Prisma prompts client to choose a certificate.

We are trying to replicate our on-prem GP setup on Prisma, since we are migrating to that. The issue is when we try to connect to Prisma portal, the user gets asked to verify the certificate. However the same setup exists for on-prem GlobalProtect and the certificate does not happen. I have tried various techniques with PA Prof. Services and...

BGP configuration on active/passive setup on service connection

Hi, Need your suggestions on setting up BGP connection between active and passive setup on service connection. Here is the eg: One service connection with active/passive tunnel between Prisma access to Data center. Diagram is attached. BGP peer ip 10.1.1.1/31 on service connection and its peering on data center with two different subn...

Integration Challenges Between Prisma SASE and ServiceNow

Hello community, My team and i have been working on integrating Prisma SASE with ServiceNow to streamline our incident response process, We've followed the steps outlined in the official documentation but, unfortunately, have encountered some challenges that prevent the integration from functioning. Could anyone share insights on the connecto...

Wassif by L1 Bithead
  • 1839 Views
  • 1 replies
  • 0 Likes

GlobalProtect MFA on iOS

Hi, Has anyone configured 2FA on iOS? We are looking at the possibility of authenticating iOS users to Prisma Access via GlobalProtect. We understand that we can use client certs on the devices, but is it possible to use 2FA on the iOS devices, and what are the ramifications of using 2FA for the end user, for example will push email stop worki...

Web Security vs URL access management profiles

Hello, I'm curious about the distinctions between Web Security (SWG) and URL access management profiles (Web filtering). when is it appropriate to use each one? Additionally, I'm interested in knowing if they can be implemented simultaneously and what the best practices and use cases would be for such a scenario.

Resolved! How to exclude a specific file name from a file blocking rule

I need to allow files of a specific name of a specific type to be exempted from a security profile file type blocking rule . Eg i want to allow a specific Chrome extension file (crx) from their webstore but no others . The file blocking security profile definition can block CRX, but i cant find away to allow a file of a specific name (the chrom...

Fileupload Api scanning

Hi Team, Can anyone suggest which Prisma cloud module suitable for antimalware scan while end user uploads file with Fileupload API to the server (please refer the link for file upload vulnerabilities : https://malware.expert/modsecurity/php-file-upload-vulnerabilities/) TIA

Resolved! Mass object creation

Hi y'all, Any advice on how to perform mass object creation on the strata cloud cloud manager ? I have a lot of objects to create and I would like to ease the process. Thought of using API but maybe there is a easier way of doing it. Thank you. Regards, Missakid

Configuration Policy for Online Meetings only allow Port UDP

We created a Security policy to allow Online meeting only UDP ports that enter Prisma Access. There are 4 applications namely Webex, Google meet, Teams, and Zoom. 3 applications other than Zoom are running properly according to the rules made, but the Zoom application is still not working.All the parameters needed have been entered into the Poli...

Using Cloud IDentity Engine to enforce group-based policies in Azure AD

Hi All, Question on retrieving user-group mappings only, using Cloud Identity Engine to enforce group-based policies. So i have this setup at the moment:Panorama managed FWs in Azure with Global protect (works)The FWs use SAML currently for authenticating GP users against Azure AD (works) Additionally, what I want to achieve is the following.T...

PA_nts by L4 Transporter
  • 2889 Views
  • 3 replies
  • 0 Likes
  • 385 Posts
  • 78 Subscriptions
Top Liked Authors