- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-07-2021 09:12 AM - edited 07-07-2021 11:09 PM
Can the internal global or specific internal DNS servers for mobile users or remote networks be behind SPN and not a CAN as the CAN is just there for routing for mobile users without a real active ipsec tunnel?
Basically I mean the internal DNS servers to be in the remote network address space that is connected to the SPN, because the SPN provides policy check and ssl decryption as the Data Center firewalls is old layer3/4 with no ssl decryption, better use SPN than a CAN.
07-12-2021 12:43 AM - edited 08-05-2021 03:08 AM
I think that also Authentication servers like LDAP and other services can be behind an security processing node if the Data Center does not have a good firewall (this is why service node seems a bad idea). As the Prisma Access is full mesh iBGP I will consider this the case as every source may connect to every destination (only for mobile gateways a CAN even if it is without active ipsec tunnels is needed for routing) till someone says that this is not possible.
Edit:
Palo Alto confirmed that this is the case.
07-12-2021 12:43 AM - edited 08-05-2021 03:08 AM
I think that also Authentication servers like LDAP and other services can be behind an security processing node if the Data Center does not have a good firewall (this is why service node seems a bad idea). As the Prisma Access is full mesh iBGP I will consider this the case as every source may connect to every destination (only for mobile gateways a CAN even if it is without active ipsec tunnels is needed for routing) till someone says that this is not possible.
Edit:
Palo Alto confirmed that this is the case.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!