Private IP Address Visibility and Enforcement for Agent Based Proxy Traffic
Focus
Focus
Prisma Access

Private IP Address Visibility and Enforcement for Agent Based Proxy Traffic

Table of Contents

Private IP Address Visibility and Enforcement for Agent Based Proxy Traffic

Learn how to enable private IP address visibility and enforcement for GlobalProtect proxy mode and GlobalProtect tunnel and proxy mode.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama)
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access 5.2
  • GlobalProtect app version 6.3.1 for Windows or macOS
  • Prisma Access dataplane 10.2.4
  • Prisma Access Mobile User license
  • Panorama plugin version 5.2.0
Users who connect to Prisma Access Explicit Proxy through GlobalProtect agent from branches, can leverage Private IP addresses of endpoints for logging or to apply IP address based enforcement.

Private IP Address Visibility and Enforcement for Agent Based Proxy Traffic (Strata Cloud Manager)

Configure private IP address visibility in GlobalProtect Proxy mode.
  1. Enable the Agent-based Proxy functionality (Proxy mode or Tunnel and Proxy mode) for mobile users.
  2. Navigate to WorkflowsPrisma Access SetupExplicit ProxyAdvanced Security Settings, and click the settings icon. Under Trusted Source Address, add the branch egress IP address.
  3. Navigate to WorkflowsPrisma Access Setup Explicit ProxyInfrastructure Settings. Under Proxy URL Settings, enable Enable Source IP based visibility and enforcement, and click Save.
  4. (Optional) Configure the security rules with the source IP address of the endpoint.
  5. Push Config to Explicit Proxy.

Private IP Address Visibility and Enforcement for Agent Based Proxy Traffic (Panorama)

Configure the private IP visibility and enforcement for GlobalProtect in Proxy mode for panorama.
  1. Enable the Agent-based Proxy functionality (Proxy mode and Tunnel and Proxy mode) for mobile users.
  2. Navigate to Cloud ServicesConfiguration Mobile UsersExplicit ProxySettingsAuthentication Settings and add the branch egress IP address under Known Source IP Address.
  3. Navigate to Cloud ServicesConfiguration Mobile Users-Explicit Proxy. Under Agent, enable Enable Source IP based Visibility and Enforcement from Sites, and click OK.
  4. (Optional) Configure the security rules with the source IP address of the endpoint.
  5. Commit and push to the Explicit_Proxy_Device_Group.