Prisma Access BW Allocation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Prisma Access BW Allocation

L0 Member

Hi All,

Would be great if you can help me clarify these questions:

1- On Panorama managed Prisma Access we can configure the BW Allocation on Compute location level, assuming a Scenario of multiple compute locations used and allocated BW out of the total BW Subscription purchased, and No Qos is configured at all.

What would happen if one of the compute locations  BW utilization is increased more than it's allocated value ?

Would this traffic be dropped or shaped by default by Palo? Or it would still be allowed as long as the total BW for all compute locations is still below the total subscription value?

2- For the Remote Network  Inbound Access , There is an option of "Allow inbound flows to other Remote Networks over the Prisma Access Backbone", As per the documentation this allows access   resources that is in a remote network site that has inbound access enabled  to be accessed by  users at non-inbound access sites .

My question is what this option offers more than what is offered already using the interconnect Add-on license that enables communication between Remote Networks?

 

3- For remote Networks Overlapped Subnets (ex: 2 branch sites have the same subnet assigned for guests users) , Does this limit access for only guest subnets to other prisma access connected resources , or this limits the entire branch connectivity to prisma resources allowing only internet access from these entire branch subnets?

Appreciating your Support.

Thanks

 

 

1 REPLY 1

Cyber Elite
Cyber Elite

1- the bw will be bursted beyond the assigned BW (capped at 1000mb/RNSPN i think). as long as this doesn't happen all the time you should be fine, but make sure to assign more bandwidth if you consistently pass your assigned BW

 

2- secure inbound access creates access from the internet into a remote network. this can be useful if the RN hosts a website or an app: https://docs.paloaltonetworks.com/prisma/prisma-access/preferred/2-2/prisma-access-panorama-admin/pr...

 

3- overlapping subnets limits access to everything except the internet : https://docs.paloaltonetworks.com/prisma/prisma-access/3-2/prisma-access-panorama-admin/prisma-acces...

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 837 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!