Deploys Palo Alto Networks Prisma Access for SASE-based zero trust network access, configuring GlobalProtect agents, ZTNA Connectors, security policy enforcement, and Strata Cloud Manager integration for unified management. Use when implementing enterprise-grade SASE with integrated ZTNA/SWG/CASB/FWaaS, replacing both VPN and branch firewalls with cloud-delivered security, or integrating ZTNA with an existing Palo Alto NGFW estate.
Deploys Palo Alto Networks Prisma Access for SASE-based zero trust network access, configuring GlobalProtect agents, ZTNA Connectors, security policy enforcement, and Strata Cloud Manager integration for unified management. Use when implementing enterprise-grade SASE with integrated ZTNA/SWG/CASB/FWaaS, replacing both VPN and branch firewalls with cloud-delivered security, or integrating ZTNA with an existing Palo Alto NGFW estate.
When implementing enterprise-grade SASE with integrated ZTNA, SWG, CASB, and FWaaS
When replacing both VPN and branch office firewalls with cloud-delivered security
When needing advanced threat prevention (WildFire, DNS Security) for remote access traffic
When deploying zero trust for both mobile users and remote network (branch) connections
When integrating ZTNA with existing Palo Alto NGFW infrastructure via Strata Cloud Manager
Do not use for small organizations (< 200 users) where simpler ZTNA solutions suffice, for environments requiring only web application access without full network security, or when budget constraints preclude enterprise SASE licensing.
Prerequisites
Prisma Access license (Business Premium or equivalent)
Strata Cloud Manager (SCM) tenant configured
GlobalProtect agent for endpoint deployment
ZTNA Connector VM: 4 vCPU, 8GB RAM, 128GB disk (VMware, AWS, Azure, or GCP)
Step 1: Configure Prisma Access Infrastructure in Strata Cloud Manager
Set up the cloud infrastructure for mobile user and remote network connections.
Strata Cloud Manager > Prisma Access > Infrastructure Settings:
Mobile Users Configuration:
- Service Connection: Auto-selected based on user location
- DNS Servers: 10.1.1.10, 10.1.1.11 (corporate DNS)
- IP Pool for Mobile Users: 10.100.0.0/16
- Authentication: SAML with Okta (Primary), Entra ID (Secondary)
- GlobalProtect Portal: portal.company.com
- GlobalProtect Gateway: Auto (nearest Prisma Access location)
Infrastructure Subnet:
- Range: 172.16.0.0/16
- Allocation: /24 per Prisma Access location
Step 2: Deploy ZTNA Connectors for Private Application Access
Install ZTNA Connectors to provide secure access to internal applications.
GlobalProtect Agent: Endpoint connectivity agent with HIP data collection
ZTNA Connector: Outbound-only tunnel connector for internal application access
Cortex Data Lake: Centralized log storage with analytics and threat detection
WildFire: Cloud-based malware analysis and prevention integrated with Prisma Access
Common Scenarios
Scenario: Enterprise SASE Migration for 5,000-User Organization
Context: A manufacturing company with 5,000 users across 15 offices is consolidating VPN, SWG, and branch firewalls into Prisma Access SASE. Users access 50+ internal applications and need consistent security regardless of location.
Approach:
Deploy ZTNA Connectors at 3 data centers (2 per DC for HA) for internal application access
Configure GlobalProtect with pre-logon connection for always-on security
Define 50+ application definitions in SCM with FQDN and port mappings
Create HIP profiles: Standard (encryption + AV), Enhanced (+ CrowdStrike + patches)
Build security policies mapping user groups to applications with HIP requirements
Deploy GlobalProtect agent via SCCM to all 5,000 endpoints in phases
Configure Cortex Data Lake forwarding to Splunk for SOC monitoring
Decommission VPN concentrators and branch firewall appliances
Pitfalls: ZTNA Connector requires minimum 4 vCPU and 8GB RAM; under-provisioning causes latency. GlobalProtect pre-logon requires machine certificates for authentication before user login. HIP check intervals should be 60 seconds minimum to avoid performance impact. Plan for a 4-6 week pilot before full deployment.