Prisma SD Wan Netskope Integration
Prisma SD Wan Netskope Integration
Prisma SD Wan Netskope Integration
1.0.0
docs.paloaltonetworks.com
Table of Contents
Table of Contents
Prisma SD-WAN Netskope Integraon........................................................ 4
Set up the Netskope Security Cloud...................................................................................... 5
Configure Prisma SD-WAN Tunnels to Netskope Security Cloud................................. 11
Create an IPsec Profile................................................................................................. 11
Create a Service Group................................................................................................ 12
Create an IPsec Tunnel.................................................................................................14
Create a Path Policy......................................................................................................17
Verify the Configuraon...............................................................................................18
Monitor Cybersecurity Events on the Netskope Portal................................................... 20
Netskope Integraon Guide Version 1.0.0 2 ©2022 Palo Alto Networks, Inc.
Table of Contents
Netskope Integraon Guide Version 1.0.0 3 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
As enterprises rely on SaaS or Cloud-based delivery models for business-crical
applicaons, there is a compelling need for per-applicaon policy enforcement without
increasing remote office infrastructure. Tradional hardware-router based approaches
are limited by cumbersome policies for direct-to-internet versus policy enforcement
per-applicaon. Router-based approaches are packet-based versus applicaon-session
based and fail to meet applicaon session-symmetry requirements, causing network
and security outages.
You can integrate Prisma SD-WAN with Netskope Security Cloud to have a remote
office hardware, while sll having a full suite of applicaon-specific security policies.
4
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 5 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 6 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 7 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 8 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
10. (Oponal) Click the ellipsis next to the tunnel entry to see addional opons to edit and
view tunnel configuraon parameters.
Netskope Integraon Guide Version 1.0.0 9 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
• The throughput capacity refers to the actual traffic going through the tunnel.
• Save the probe IP address to be used later in the Prisma SD-WAN endpoint
configuraon for liveliness checks.
Netskope Integraon Guide Version 1.0.0 10 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 11 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
STEP 9 | Click Next, review the sengs of the profile and then click Save & Exit.
Netskope Integraon Guide Version 1.0.0 12 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
STEP 6 | Give the endpoint a name and check the Admin UP box.
STEP 8 | Enter a comma separated list of the Netskope Primary and Failover POP IP addresses and
click Done.
Prisma SD-WAN will check RTT for each of these IP addresses and will automacally choose
the desnaon with the lowest latency as the IPsec tunnel endpoint.
Netskope Integraon Guide Version 1.0.0 13 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
STEP 10 | Configure the Probe IP Address from Netskope Tunnel configuraon along with ICMP ping
interval and failure count and click Done.
The probe IP address in the Netskope Security Cloud will be pinged to check liveliness of the
tunnel. In the example below, an ICMP packet will be sent once every 10 seconds. When 3
consecuve pings fail, the tunnel will be declared Down.
STEP 12 | At the Groups tab, under the Domains column, against the Groups row, click Add to add a
new group.
STEP 14 | Give the group a name and in the Endpoints drop-down, choose the endpoint that was just
configured.
STEP 2 | Click the ellipsis menu for the device to be configured with the IPsec tunnel and select
Configure the device.
Netskope Integraon Guide Version 1.0.0 14 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 15 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 16 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
STEP 4 | Give the path policy set a name and click Save.
Netskope Integraon Guide Version 1.0.0 17 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
STEP 7 | Navigate to the Apps tab next and choose the applicaons that you want to forward to the
Netskope Security Cloud over the Standard VPN.
STEP 8 | Navigate to the Paths tab and choose the overlay path Standard VPN on circuit category Any
Public.
STEP 10 | Under Acve, choose the Group configured in the previous steps from the drop-down list.
STEP 11 | Verify the configuraon summary and click Save & Exit.
STEP 2 | On the Prisma SD-WAN web interface, navigate to the Acvity tab.
Netskope Integraon Guide Version 1.0.0 18 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 19 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 20 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 21 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
STEP 3 | Go to the main dashboard and select Skope IT for granular security data.
The Sites tab shows URL analycs.
Netskope Integraon Guide Version 1.0.0 22 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
STEP 4 | Click the Network Events tab to show user informaon, applicaon accessed, acon taken
on this session and bytes transferred.
Netskope Integraon Guide Version 1.0.0 23 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
STEP 5 | Click on Alerts to see what policy was applied to a flow and what acon was taken on it and
if there were malicious objects detected in this flow.
Netskope Integraon Guide Version 1.0.0 24 ©2022 Palo Alto Networks, Inc.
Prisma SD-WAN Netskope Integraon
Netskope Integraon Guide Version 1.0.0 25 ©2022 Palo Alto Networks, Inc.