What are the different connections between Prisma SD-WAN ION and the controller?

What are the different connections between Prisma SD-WAN ION and the controller?

3953
Created On 01/14/24 23:56 PM - Last Modified 12/12/24 21:44 PM


Question


What are the different connections between Prisma SD-WAN ION and the controller? 



Environment


  • Prisma SD-WAN
  • Prisma SASE
  • ION
  • Strata cloud manager (SCM)


Answer


The following 4 TLS 1.2 connections are initiated by the ION device to the Controller.

  1. Message Routing Layer (MRL) session: is used for all control messages between controller and ION devices. i.e, if any config changes are made on the controller UI, etag incremented values, push to the ION through this control channel.
  2. Logs: All system logs from the device to the controller are sent over logs channel for centralized troubleshooting or debugging.
  3. Flows: Flow records collected by the device are sent to the controller over flows channel.
  4. Stats: All aggregated metrics are sent by the device to the controller over stats  channel. 

Note:

  • There is also a fifth connection called Remote access. This is an on-demand TLS session for the remote cli access from the User Interface of the controller. 
  • The connection is initiated through the MRL connection, So the MRL connection should remain up to get the remote cli access.
  • A maximum of 16 concurrent remote access is possible to the ION device.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008WbYCAU&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language