At A Glance: Prisma Access: Security As A Service Layer Network As A Service Layer Management
At A Glance: Prisma Access: Security As A Service Layer Network As A Service Layer Management
• Routing branch and mobile user traffic directly to the internet without inspection is not safe.
• First-generation cloud-delivered security products, such as proxies, DNS filtering, and cloud access security brokers (CASB) have limited security capabilities.
These issues drive up administrative costs and create operational challenges, and the market demands a change. In 2019, Gartner defined a new cloud-delivered architecture for networking
and security called the “secure access service edge” (SASE), which converges first-generation, standalone products with a common service delivery model.
Prisma Access
Prisma™ Access is a SASE that helps organizations embrace cloud and mobility by providing networking and network security services from the cloud. With a growing number of users, branch
offices, data, and services located outside the protection of traditional network security appliances, organizations need a cloud-based infrastructure that converges networking and network
security capabilities. Prisma Access provides consistent security services and access to cloud applications (including public cloud, private cloud, and software as a service), delivered through a
common framework for a seamless user experience.
All users, whether at corporate headquarters, branch offices, or on the road, connect to Prisma Access to safely use cloud and data center applications as well as the internet. Prisma Access
consistently inspects all traffic across all ports and provides bidirectional networking to enable branch-to-branch as well as branch-to-HQ traffic.
Prisma Access is delivered as a cloud service from more than 100 locations in 76 countries for users and branch offices to connect, enabling connectivity and security for mobile users, branch
offices, and retail locations.
SASE Services
Prisma Access delivers both networking and security services, which include:
Networking
• SD-WAN—support for Palo Alto Networks Next-Generation Firewalls and integration with third-party SD-WAN
• VPN—options for connecting users and networks, including IPsec, SSL/IPsec, and clientless VPN
• Zero Trust network access (ZTNA)—access control and threat prevention to protect applications
• Quality of service (QoS)—prioritization of bandwidth for critical applications
• Clean Pipe—outbound internet security for managed service providers
Security
• Firewall as a service (FWaaS)—next-generation firewall security for branch offices and retail locations
• DNS Security—advanced analytics and machine learning to protect against threats in DNS traffic
• Threat Prevention—blocking of exploits, malware, and command-and-control (C2) traffic using threat intelligence
• Cloud secure web gateway (SWG)—blocking of malicious sites using static analysis and machine learning
• Data loss prevention (DLP)—categorize sensitive data and apply policies to control access
• Cloud access security broker (CASB)—governance and data classification to stop threats with in-line and API-based security
Licensing Options
Prisma Access for Networks is licensed based on the total bandwidth used across all sites, with the bandwidth pool divided into the amounts each location needs (minimum bandwidth
pool: 200 Mbps).
Prisma Access for Users is licensed based on the total number of users, with tiers from 200 users up to more than 100,000. Prisma Access for users requires the GlobalProtect app.
Supported endpoints include Microsoft Windows®, Apple macOS® and iOS, Android®, Google Chrome® OS, and Linux.