Create a Service Connection to Enable Access between Mobile Users
and Remote Networks
Even if you don’t need to access resources
at your organization’s HQ or data center, you still need to configure
a service connection to allow network communication between mobile
users and remote network locations and between mobile users in different
geographical locations.
Create this type of service connection
for the following environments:
Your deployment includes
both remote networks and mobile users and you do not already have
a service connection configured.
You have mobile users in different geographical areas who
need direct access to each other’s endpoints.
You have already configured a service connection, but the
existing service connection is not in an ideal location between
the remote networks and mobile users.
All remote network locations
communicate to each other in a mesh network. Mobile users connect
to remote networks using the service connection in a hub-and-spoke
network. In some cases, it might improve network efficiency to place
another service connection closer to the remote network or networks
that the mobile users most frequently access.
To
configure a service connection to connect mobile users and remote
networks, Add a service connection using the
following values:
Specify a Region that
is close to your mobile users.
Add an IPSec Tunnel and IKE
Gateway, using placeholder values.
Add placeholder Corporate Subnets.
Since
Prisma Access doesn’t route any traffic through this tunnel, any
value that does not conflict or overlap with other configured subnets
is valid.
The following example shows a Prisma Access
deployment with mobile users in different geographical areas and
remote networks. The remote network connections are connected in
a mesh network in the Prisma Access infrastructure, but the mobile
users cannot connect to the remote networks. In addition, the mobile
users in different geographic areas cannot connect to each other
without a service connection.
After
you add a service connection, the service connection connects the
mobile users and the remote networks in a hub-and-spoke network.
Another
case where a service connection of this type is useful is when the
service connection is far from the mobile users. The following figure
shows an example of this network deployment.
Adding
a second service connection that is closer to the mobile users creates
a more efficient network between the mobile users and remote networks.