Prisma Access as a Replacement for GlobalProtect and Security Inspection Platform – Seeking Real-World Feedback

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Prisma Access as a Replacement for GlobalProtect and Security Inspection Platform – Seeking Real-World Feedback

L1 Bithead

Hello Everyone,

 

We are currently evaluating Prisma Access as a replacement for our traditional GlobalProtect deployment and are considering using Prisma Access as our primary cloud-delivered security platform for remote users.

Our goal is to leverage the full security stack, including:

  • URL Filtering
  • WildFire
  • DNS Security
  • Advanced Threat Prevention
  • DLP
  • SSL Decryption
  • SaaS Visibility and Control
  • User and Application Visibility

For organizations that have already made this transition, I would appreciate hearing about your experience.

Some questions we have are:

  • Have you encountered any issues or unexpected challenges after moving to Prisma Access?
  • Are you able to perform all required security inspections successfully?
  • Do you feel you have the same level of visibility as you had with on-premises Palo Alto firewalls?
  • Have you experienced any visibility gaps, blind spots, or troubleshooting challenges?
  • How effective are the logging, monitoring, and reporting capabilities?
  • Have you had any concerns related to SSL decryption, DLP, or user experience?
  • Have you noticed any increase in latency, application slowness, or performance issues after directing traffic through Prisma Access for inspection?
  • Were there any applications or services that required special handling or exceptions to maintain acceptable performance
  • We are particularly interested in understanding whether organizations have been able to achieve full inspection and maintain complete visibility after moving security services to Prisma Access.
     

Any feedback, concerns, recommendations, or lessons learned would be greatly appreciated.

Thank you in advance for sharing your experience.

2 REPLIES 2

L0 Member

Transitioning from traditional GlobalProtect to Prisma Access generally delivers robust security parity and excellent cloud scalability, but most organizations encounter initial hurdles with SSL decryption overhead, complex troubleshooting across remote nodes, and occasional latency spikes requiring strategic traffic steering (such as local breakout for trusted SaaS apps like Zoom or Microsoft 365). While you achieve the same comprehensive visibility and full stack inspection as on-prem Palo Alto firewalls, success heavily depends on properly sizing remote networks, fine-tuning decryption policies to avoid user friction, and leveraging tools like Prisma Access Insights for effective log monitoring.

Community Team Member

Hi @alirezabtf ,

 

Building on the points above, here are a few additional technical considerations and best practices based on real-world migrations from on-premises GlobalProtect to Prisma Access:

 

1. Security & Feature Parity

Because Prisma Access runs native PAN-OS under the hood, you get full inspection parity for WildFire, Advanced Threat Prevention, Advanced URL Filtering, and DNS Security.

  • SSL Decryption & Enterprise DLP: Capabilities match on-prem firewalls, but you will want to review your decryption bypass lists early. Decrypting heavily pinned or certificate-bound applications will require fine-tuning your SSL profiles in Panorama or Strata Cloud Manager.

2. Performance & Optimization

  • SaaS Optimization / Traffic Steering: For real-time media applications (Microsoft 365, Teams, Zoom), leverage Split Tunneling / SaaS Direct Breakout. Hairpinning high-volume UDP video/audio streams through full SSL inspection often introduces artificial latency and degrades user experience.

  • Egress IP Whitelisting: Because Prisma Access uses dynamic cloud egress nodes, third-party SaaS vendors that mandate static source IP whitelisting will require you to assign Dedicated Egress IPs in Prisma Access or route that specific traffic back through a Service Connection.

3. Visibility & Troubleshooting

  • Logging: All logs stream natively to Strata Logging Service (SLS), giving you unified User-ID, App-ID, and Threat visibility across all remote endpoints.

  • Autonomous DEM (ADEM): On-prem firewalls rely on local interface statistics, but Prisma Access relies heavily on Prisma Access Insights (PAI) and ADEM. ADEM is particularly critical—it provides synthetic hop-by-hop telemetry from the client endpoint, through the GlobalProtect app, across the Prisma Cloud node, and out to the target application.

4. Key Architectural Considerations

  • Service Connections: Ensure adequate bandwidth is allocated to your Service Connections (the IPSec tunnels connecting Prisma Access back to your corporate datacenters/HQ).

  • Cloud Identity Engine (CIE): Deploy CIE early to handle User-ID and group mapping seamlessly in the cloud without relying on on-prem Domain Controller log forwarding.

 

I hope these provide more insights.

Kind regards,

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 122 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!