PAC Retention and URL Category Priority Behavior in Prisma Access

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PAC Retention and URL Category Priority Behavior in Prisma Access

L0 Member

Hello community.
This is a confirmation regarding Prisma Access (existing contract) for a specific project.

 

As background,
we are currently conducting a Proof of Concept (PoC) to verify whether Prisma Access (via Global Protect) can reliably implement the display of the “Information Security Pledge Screen” for external users of our customer.

This functionality was previously handled by the authentication proxy.

 

The intended flow is as follows:
- When an unpledged external user attempts to access the web, the user is redirected to an Override page.
- From there, the user is redirected to the pledge page.
- The pledge page itself is configured as Allow.

After the pledge is completed, subsequent user traffic should be routed through a proxy using a PAC file.
However, the pledge page cannot be accessed through the proxy, so unpledged user traffic must not use the PAC file.

 


Question 1: PAC configuration remains in the Global Protect app

In Prisma Access (Mobile Users):

1. GP App Configuration #1 (PAC enabled)
→ After connecting, the Global Protect app correctly retrieves PAC information.

2. On the same endpoint, we then apply
GP App Configuration #2 (PAC disabled)
→ However, the PAC configuration obtained from Configuration #1 still remains on the device, even though the new configuration has PAC disabled.

Is this the expected behavior?
If so, is there any method to prevent this, such as automatically clearing / removing the previously applied PAC configuration?


Question 2: Priority behavior of Custom URL Categories in Prisma Access

We configured the following Custom URL Categories in Prisma Access:

- Category ①: * (Action: Override)
- Category ②: yahoo.co.jp (Action: Allow)

With this configuration, all traffic matches Category ①, and traffic never matches Category ②.

Is this the expected behavior?
If so, is there any recommended method to give precedence to a specific URL (such as yahoo.co.jp) over a wildcard category?

 

Thank you very much for your support and clarification.

0 REPLIES 0
  • 299 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!