Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Can the internal DNS server be behind SPN not a CAN?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Can the internal DNS server be behind SPN not a CAN?

L3 Networker

Can the internal global or specific   internal DNS servers for mobile users or remote networks be behind SPN and not a CAN as the CAN is just there for routing for mobile users without a real active ipsec tunnel?

 

 

Basically I mean the internal DNS servers to be in the remote network address space that is connected to the SPN, because the SPN provides policy check and ssl decryption as the Data Center firewalls is old layer3/4 with no ssl decryption, better use SPN than a CAN.

 

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-fo...

1 accepted solution

Accepted Solutions

L3 Networker

I think that also Authentication servers like LDAP and other services can be behind an security processing node if the Data Center does not have a good firewall (this is why service node seems a bad idea). As the Prisma Access is full mesh iBGP I will consider this the case as every source may connect to every destination (only for mobile gateways a  CAN even if it is without active ipsec tunnels is needed for routing) till someone says that this is not possible.

 

 

 

 

Edit:

 

 

 

Palo Alto confirmed that this is the case.

View solution in original post

1 REPLY 1

L3 Networker

I think that also Authentication servers like LDAP and other services can be behind an security processing node if the Data Center does not have a good firewall (this is why service node seems a bad idea). As the Prisma Access is full mesh iBGP I will consider this the case as every source may connect to every destination (only for mobile gateways a  CAN even if it is without active ipsec tunnels is needed for routing) till someone says that this is not possible.

 

 

 

 

Edit:

 

 

 

Palo Alto confirmed that this is the case.

  • 1 accepted solution
  • 2997 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!