---
title: "Configure a Palo Alto Networks cloud connector"
canonical: "https://docs.aryaka.com/space/KNOW/1642767/Configure%20a%20Palo%20Alto%20Networks%20cloud%20connector"
format: markdown
---
Aryaka enables you to connect your branch locations to Palo Alto Networks GlobalProtect cloud service by providing a cloud-controlled SD-WAN solution that selectively forwards Internet traffic to Palo Alto Networks GlobalProtect cloud service using a secure IPSec tunnel. This topic describes Palo Alto Networks-specific configuration settings for connecting your Aryaka ANAP device to the Palo Alto Networks GlobalProtect Cloud Service (GPCS) platform using IKEv1 or IKEv2 IPSec VTI-based tunnels. This information is designed to be used in conjunction with the general configuration steps described in the  Configure cloud connectors  topic. This integration is supported for the following Aryaka ANAP topologies: Inline routed mode Edge routed mode The following table describes the configuration settings for both of these modes. Field Description Tunnel Destination Public IP of Palo Alto Network cloud on which the tunnel terminates. In Panorama, the IP address can be found in the Network Details of Cloud Service. Refer to the Service IP Address section to obtain the IP address. Tunnel Source Interface The interface that is used for the tunnel. Use Interface IP for Tunnel Source  (edge routed mode only) If you select Yes, the tunnel source is the selected interface IP. If you select No, you must provide an IP from the same ISP that is associated with the interface selected in the Tunnel Source Interface field. Tunnel Settings Shared Key Enter the shared key that is configured for the IKE Gateway in Panorama. ANAP FQDN Enter a fully qualified domain name for the ANAP if the IP address of the M1/M2 interface is dynamic. Traffic Forwarding Select traffic that you want to forward to Palo Alto All internet traffic—Aryaka creates a default route in the  Route controller  that routes all Internet traffic through the cloud connector tunnel. Specific traffic—You must manually create routes using the  Route controller  to route specific traffic through the tunnel. If the ANAP supports segmentation, you must match the traffic by selecting the existing match rules on this page. If not, create a new one and reference it here. Drop Traffic to private subnet Allows or blocks private destination IPs that are routed over the tunnel. Operation on both tunnel failure Determines the behavior of the ANAP If both tunnels are down. Optionally, you can enable a secondary tunnel. The configuration is similar to that of the primary tunnel. Solution Architecture This section provides a high-level solution overview of a sample deployment that includes two sites: Site A and Site B. An ANAP (Aryaka Network Access Point) device is deployed at both sites. The ANAP is a branch edge device that is provided with your Aryaka SmartServices subscription. Site-to-site traffic originating from clients is optimized, accelerated, and encrypted before it is sent over a secure IPSec tunnel to Aryaka global SD-WAN cloud. Internet-bound traffic is encrypted and sent over a secure IPSec tunnel to Palo Alto Networks GlobalProtect where their security policies are applied. The following graphic illustrates the integrated architecture: Prerequisites Satisfy the following prerequisites before integrating Aryaka SmartServices with Palo Alto Networks GlobalProtect: Aryaka SmartServices subscription License for Palo Alto Networks GlobalProtect Cloud Services plugin installed on Panorama Palo Alto Networks GlobalProtect Configuration Using Panorama, GlobalProtect must be configured with details about the following: The branch site network's infrastructure subnet The IPSec tunnel The internet key exchange (IKE) protocol that negotiates between your remote network location and GlobalProtect The remote network Any desired security policies These steps provide general configuration guidelines. Refer to the  GlobalProtect Cloud Service Getting Started Guide  for additional details.  While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. Configure an Infrastructure Subnet GlobalProtect requires an infrastructure subnet that does not overlap any of your existing networks. This subnet is used to create the network backbone used for communication between your branch office networks and GlobalProtect. To create an infrastructure subnet Log into Panorama. Click the  Panorama  tab, then click  Cloud Services  >  Configuration  in the left navigation pane. Click the  Service Setup  tab, then click the  Settings  icon. The Settings dialog appears: Enter the subnet's IP address in the Infrastructure Subnet field, then click  OK . You are returned to the Configuration page. Continue to the next section. Configure an IPSec Tunnel Click  New IPSec Tunnel . The IPSec Tunnel dialog appears: Configure the tunnel as follows: Enter a name in the Name field. Enter a name in the IKE Gateway field. Select  default  from the IPSec Crypto Profile field drop-down list. Click  OK . You are returned to the Configuration page. Continue to the next section. Configure an IKE Gateway Click  New IKE Gateway . The IKE Gateway dialog appears:  Configure the gateway as follows: Enter a name in the Name field. Select  IKEv1 only mode  from the Version field drop-down list. Select  Static  in the Peer IP Type field, then enter the address in the Peer IP Address field. Select  Pre-shared Key  in the Authentication field, then enter and confirm the key in the corresponding fields. Select  None  from the Local Identification and Peer Identification drop-down lists. Click  OK . You are returned to the Configuration page. Continue to the next section. Configure the Remote Network The remote network is the branch network at which you are integrating Aryaka with GlobalProtect. GlobalProtect uses this network's configuration details to route requests to the appropriate branch site. To create a remote network Click the  Remote Network  tab, then click  Onboarding . The Onboarding dialog appear: Configure the remote network as follows: Enter a name for the remote network in the Name field. Select the geographic region from the  Region  drop-down list. Select the IPSec tunnel that you configured previously from the  IPSec Tunnel  drop-down list. In the Branch Subnets field, add the IP subnetworks and individual IP addresses at the corporate site to which your users need to access. This associates the addresses with the selected IPSec tunnel. (Optional) Click  Enable Secondary WAN  and specify a tunnel for it to use if you use one.  (Optional) Create zones and map them as shown to enable consistent security policy enforcement. Click  OK . The remote network is created. Click  Commit  >  Commit to Panorama  to commit all of your changes to Panorama and push the configuration settings to the GlobalProtect cloud service. Obtain the Service IP address The service IP address is the public-facing tunnel destination address of the GlobalProtect tunnel that connects to the Aryaka ANAP. You need to enter this address when you configure the cloud security integration in MyAryaka in the next section. To determine the service IP address Navigate to  Panorama  >  Cloud Services  >  Status  >  Network Details . The infrastructure subnets and remote networks that you configured appear in the Network Details table. The corresponding IP address appears in the Service IP Address column.  MyAryaka Configuration Aryaka allows you to connect to a cloud security service using a cloud connector. Connector configuration can be done using MyAryaka service portal at  https://my.aryaka.com/  or with the help of Aryaka’s technical support team. When configuring the connector in MyAryaka, you can also configure traffic forwarding. If and how traffic forwarding is performed depends on the routing mode of your ANAP device: When an ANAP is in  simple routed mode , all traffic that is not destined for the Aryaka POP is routed to the Palo Alto Network tunnels. If you want to forward only select traffic, you must create some form of policy-based routing in your upstream firewall or router. When an ANAPs in  edge routed mode  or  inline routed mode , you can control what traffic gets forwarded to Palo Alto Networks in MyAryaka. To configure the Palo Alto Networks connector On the Cloud Security Connector (Add) tab page, ensure that  Basic  is selected (top right), then click  Add New  in the Tunnel Configurations pane. The Tunnel Configurations (Add) tab page appears. In the Basic Information pane, verify that VTI is selected in the  Tunnel Type  drop-down list. The list only displays supported tunnel types, and Palo Alto supports only VTI.  Ensure the  Enable IKEv2  field is set to No. Click  Add New  in the Tunnel Configurations section. The Tunnel Configurations tab page appears. Select the Tunnel Source Interface in the Tunnel Details section. This is the tunnel source IP address and is dependent on ANAP deployment mode: Select  LAN  if the ANAP is deployed in Simple Routed Mode. Select  M1  or  M2  IP addresses if ANAP is deployed in Edge or Inline Routed Mode Select IP from the Tunnel Destination Type drop-down list, then enter the primary public destination IP that was assigned by Palo Alto Networks in the Tunnel Destination IP field. Configure ICMP keepalive IP addresses if provided by Palo Alto Networks. (Optional) Click  Advanced  (top right) to modify the default tunnel failure and private subnet settings. By default, Aryaka drops packets when tunnels fail or if traffic is destined to a private subnet.  Click  OK . The tunnel configuration is saved, and you are returned to the Tunnel Configurations (Add) tab page. Do one of the following: Click the  Save  icon to save your settings, then configure traffic forwarding as described in the next section. Click the  Submit  icon to create a change request and send it to Aryaka support for processing. To configure traffic forwarding Open the Cloud Security Connector (Add) page. It includes a Forward Traffic toggle that is disabled by default: After adding the required tunnels (as described in the previous section), click the  Forward Traffic  toggle to configure traffic match criteria that, when matched, forwards traffic to the Palo Alto Networks connector. The following fields appear:  Forward Using—Drop-down list that includes the following options: Internet Policies—Select this if you want the ANAP to route those traffic to Palo Alto Networks that only reaches the public interfaces after all other routing decisions have been made on the traffic. Local Policies—Select this if you want the ANAP to override all other routing decisions that could possibly make on that traffic. For example, traffic may be heading to ASN but you want to override that decision and send it to Palo Alto Networks. If Forward Fails—Drop-down list that includes the following options: Blackhole—Select this if you want the ANAP to silently discard the traffic and send no response back to the sender. Prohibit—Select this if you want to send a code 13 ICMP administratively prohibited message back to the sender. Policy Name table with Add New button—Click  Add New  to define a local or internet policy (depending on your selection in the Forward Using field), then provide the following details in the Policy (Add) page that appears: Name—Enter a descriptive policy name. Zone—Select the zone where the traffic originates. Match Rules—Set the toggle to  Explicit , click  Choose  in the Match Rules Details table that appears, and then select a preconfigured mach rule from the  Name  drop-down list that matches the traffic you want to forward to Palo Alto Networks. Click the  Submit  icon to create a change request and send it to Aryaka support for processing. In this topic Related topics Configure cloud connectors Route controller