Prisma Access must be able to connect to the IPSec-capable
CPE (such as a router or SD-WAN device) that your organization uses
to terminate the service connection, and the IP address for the
device must be reachable from Prisma Access.
You create a
service connection using standard
IPSec and
IKE cryptographic profiles
between the stack location and Prisma Access. You can use static
routes, BGP, or a combination or both when you
create a service connection and
use traffic steering. If you use default routes with traffic steering,
Palo Alto Networks recommends that you use either BGP only or static
routes only. If you use static routing, specify the public IP address
used by the organization’s CPE as the
Peer Address when
you
create an IKE gateway.