Complete the Clean Pipe Configuration
Focus
Focus
Prisma Access

Complete the Clean Pipe Configuration

Table of Contents

Complete the Clean Pipe Configuration

Complete the Clean Pipe configuration.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama)
To complete configuration of Prisma Access for Clean Pipe, you perform configuration in the Partner Interconnect and in Panorama.
Make sure that you can access and configure the CE and cloud routers on the Partner Interconnect (non-Prisma access) side of the Partner Interconnect.
  1. In the Partner Interconnect side of the configuration, create a VLAN attachment, using the Pairing Key that you retrieved from Panorama.
    For more information about creating VLAN attachments with Partner Interconnects and configuring customer edge (CE) routers to communicate with cloud routers, refer to the Google Cloud documentation at https://cloud.google.com/interconnect/docs/
    Make sure that the location and bandwidth you select matches the Location you specified in Panorama. The service provider you use for the Partner Interconnect uses the pairing key, along with your requested connection location and capacity, to complete the configuration of your VLAN attachment.
  2. After the connection comes up, return to Panorama, select PanoramaCloud ServicesStatusNetwork DetailsClean Pipe and make a note of the MSSP CE and Cloud Router IP addresses.
    These values populate after you enter the Pairing Key on the other side of the VLAN attachment.
  3. Log in to the CE router and perform the following configuration.
    1. Enter the MSSP CE address as the local IP address.
    2. Enter the Cloud Router IP address as the peer IP address.
    3. Enter a BGP ASN that matches the BGP Peer ASN you entered when you configured the Clean Pipe in Panorama.
      Make sure that you enter these values correctly; you cannot change them.
  4. Check the Clean Pipe status.
    1. In Panorama, select PanoramaCloud ServicesStatus, select the Tenant from the drop-down, and check the Clean Pipe’s Status.
      See the list of Prisma Access locationsfor acceptable values.
      The Deployment Status area allows you to view the progress of onboarding and deployment jobs before they complete, as well as see more information about the status of completed jobs. See Deployment Progress and Status for details.
    2. Select PanoramaCloud ServicesStatusClean Pipe, and click the Monitor tab to see a map with the status of the deployed Clean Pipes.
      Click the tabs below the map to see additional statistics for the Clean Pipes.
      Status tab:
      • Compute Region—The compute region where your cloud service infrastructure is deployed for the clean pipe instance.
      • Name—The name of the clean pipe instance.
      • Allocated Bandwidth (Mbps)—The amount of bandwidth you allocated for the clean pipe instance.
      • Config Status—The status of your last configuration push to the service. If you have made a change locally, and not yet pushed the configuration to the cloud, the status shows Out of sync. Hover over the status indicator for more detailed information. After committing and pushing the configuration to Prisma Access, the Config Status changes to In sync.
      • BGP Status—Displays information about the BGP state between the firewall or router at the clean pipe instance and Prisma Access. Although you might temporarily see the status pass through the various BGP states (idle, active, open send, open pend, open confirm, most commonly, the BGP status shows:
        • Connect—The router at the clean pipe instance is trying to establish the BGP peer relationship with the cloud firewall.
        • Established—The BGP peer relationship has been established.
          This field will also show if the BGP connection is in an error state:
        • Warning—There has not been a BGP status update in more than eight minutes. This may indicate an outage on the firewall.
        • Error—The BGP status is unknown.
      • Status—The operational status of the connection between Prisma Access and the clean pipe instance.
      Statistics tab:
      • Region—The region where your cloud service infrastructure is deployed for the clean pipe instance.
      • Name—The name of the clean pipe instance.
      • Allocated Bandwidth (Mbps)—The amount of bandwidth you allocated for the remote network location.
      • QoS— Select QoS to display a page that contains graphical QoS statistics.
      • Avg Egress Bandwidth 5 Min (Mbps)—The average amount of clean pipe egress bandwidth averaged over 5 minutes.
      • Avg Egress Bandwidth 60 Min (Mbps)—The average amount of clean pipe egress bandwidth averaged over 60 minutes.
      • Avg Ingress Bandwidth 5 Min (Mbps)—The average amount of clean pipe ingress bandwidth averaged over 5 minutes.
      • Avg Ingress Bandwidth 60 Min (Mbps)—The average amount of clean pipe ingress bandwidth averaged over 60 minutes.
      • Egress Peak Bandwidth 1 Hour (Mbps)—The amount of peak egress bandwidth for the clean pipe instance for the last 1 hour.
      • Egress Peak Bandwidth 24 Hour (Mbps)—The amount of peak egress bandwidth for the clean pipe instance for the last 24 hours.
      • Egress Peak Bandwidth 7 Days (Mbps)—The amount of peak egress bandwidth for the clean pipe instance for the last 7 days.
      • Egress Peak Bandwidth 30 Days (Mbps)—The amount of peak egress bandwidth for the clean pipe instance for the last 30 days.
      • Ingress Peak Bandwidth 1 Hour (Mbps)—The amount of peak ingress bandwidth for the clean pipe instance for the last 1 hour.
      • Ingress Peak Bandwidth 24 Hour (Mbps)—The amount of peak ingress bandwidth for the clean pipe instance for the last 24 hours.
      • Ingress Peak Bandwidth 7 Days (Mbps)—The amount of peak ingress bandwidth for the clean pipe instance for the last 7 days.
      • Ingress Peak Bandwidth 30 Days (Mbps)—The amount of peak ingress bandwidth for the clean pipe instance for the last 30 days.