Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management.
Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.
Quelldateien prüfen
Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management.
When implementing enterprise-grade SASE with integrated ZTNA, SWG, CASB, and FWaaS
When replacing both VPN and branch office firewalls with cloud-delivered security
When needing advanced threat prevention (WildFire, DNS Security) for remote access traffic
When deploying zero trust for both mobile users and remote network (branch) connections
When integrating ZTNA with existing Palo Alto NGFW infrastructure via Strata Cloud Manager
Do not use for small organizations (< 200 users) where simpler ZTNA solutions suffice, for environments requiring only web application access without full network security, or when budget constraints preclude enterprise SASE licensing.
Prerequisites
Prisma Access license (Business Premium or equivalent)
Strata Cloud Manager (SCM) tenant configured
GlobalProtect agent for endpoint deployment
ZTNA Connector VM: 4 vCPU, 8GB RAM, 128GB disk (VMware, AWS, Azure, or GCP)
Step 1: Configure Prisma Access Infrastructure in Strata Cloud Manager
Set up the cloud infrastructure for mobile user and remote network connections.
Strata Cloud Manager > Prisma Access > Infrastructure Settings:
Mobile Users Configuration:
- Service Connection: Auto-selected based on user location
- DNS Servers: 10.1.1.10, 10.1.1.11 (corporate DNS)
- IP Pool for Mobile Users: 10.100.0.0/16
- Authentication: SAML with Okta (Primary), Entra ID (Secondary)
- GlobalProtect Portal: portal.company.com
- GlobalProtect Gateway: Auto (nearest Prisma Access location)
Infrastructure Subnet:
- Range: 172.16.0.0/16
- Allocation: /24 per Prisma Access location
Step 2: Deploy ZTNA Connectors for Private Application Access
Install ZTNA Connectors to provide secure access to internal applications.
GlobalProtect Agent: Endpoint connectivity agent with HIP data collection
ZTNA Connector: Outbound-only tunnel connector for internal application access
Cortex Data Lake: Centralized log storage with analytics and threat detection
WildFire: Cloud-based malware analysis and prevention integrated with Prisma Access
Common Scenarios
Scenario: Enterprise SASE Migration for 5,000-User Organization
Context: A manufacturing company with 5,000 users across 15 offices is consolidating VPN, SWG, and branch firewalls into Prisma Access SASE. Users access 50+ internal applications and need consistent security regardless of location.
Approach:
Deploy ZTNA Connectors at 3 data centers (2 per DC for HA) for internal application access
Configure GlobalProtect with pre-logon connection for always-on security
Define 50+ application definitions in SCM with FQDN and port mappings
Create HIP profiles: Standard (encryption + AV), Enhanced (+ CrowdStrike + patches)
Build security policies mapping user groups to applications with HIP requirements
Deploy GlobalProtect agent via SCCM to all 5,000 endpoints in phases
Configure Cortex Data Lake forwarding to Splunk for SOC monitoring
Decommission VPN concentrators and branch firewall appliances
Pitfalls: ZTNA Connector requires minimum 4 vCPU and 8GB RAM; under-provisioning causes latency. GlobalProtect pre-logon requires machine certificates for authentication before user login. HIP check intervals should be 60 seconds minimum to avoid performance impact. Plan for a 4-6 week pilot before full deployment.