Tagged: Prisma SDWAN
8 posts · browse all tags
-
Palo Alto Prisma SDWAN Deep Dive Part 1: From CloudGenix to App-Defined SASE
Starting an eight-part deep dive into Palo Alto Prisma SDWAN — the fourth control-plane philosophy this site has covered, after Fortinet, Arista/VeloCloud, and Cisco/Viptela. Part 1 covers the CloudGenix lineage, the 2020 acquisition, and what 'app-defined' actually means before we touch a single ION device.
-
Palo Alto Prisma SDWAN Deep Dive Part 2: ION, Strata Cloud Manager, and the Planes
The ION device line from 1000 to 9000, physical and virtual, and Strata Cloud Manager — the cloud-only console that absorbed the old CloudGenix Portal. Part 2 maps Prisma SDWAN onto the planes framework this site has used for Fortinet, Arista, and Cisco, and explains why there's no controller box to rack.
-
Palo Alto Prisma SDWAN Deep Dive Part 3: AppFabric and Path Selection Without a Routing Protocol
How AppFabric actually builds its full-mesh Secure Fabric Links, why circuit categories and labels stand in for TLOCs, and how per-flow path selection works when there's no routing protocol advertising a route in the first place. The mechanics behind Part 1's philosophical claim.
-
Palo Alto Prisma SDWAN Deep Dive Part 4: The Data Plane — App-ID, Adaptive QoS, and Control vs Analytics Mode
What App-ID actually classifies at the packet level, how Adaptive QoS measures real circuit capacity instead of trusting a configured bandwidth number, and the practical operational differences between an ION in Control mode and one still in Analytics.
-
Palo Alto Prisma SDWAN Deep Dive Part 5: Security — Prisma Access, Clean Pipe, and CloudBlades
What the ION's local Zone-Based Firewall actually covers, where the line to Prisma Access gets drawn, and how CloudBlades chains in Zscaler, Netskope, and AWS Transit Gateway without touching the branch device. This is the post where 'app-defined SASE' from Part 1 stops being a tagline.
-
Palo Alto Prisma SDWAN Deep Dive Part 6: Cloud Onramp and Multicloud
Prisma SDWAN treats a VPC or VNet as just another data centre: a pair of virtual IONs joins the fabric, and a CloudBlade automates the cloud-native plumbing around them — Transit VNETs and vWAN Hub association on Azure, Transit Gateway attachment on AWS. How that compares to Cisco's and Fortinet's cloud onramp designs already on this site.
-
Palo Alto Prisma SDWAN Deep Dive Part 7: The MPLS Cutover Playbook
A per-site MPLS-to-Prisma-SDWAN migration playbook built around the Analytics-to-Control progression from Part 3: zero-touch bootstrap, a genuinely evidence-based baseline before anything changes behaviour, a bounded rollback window per site, and a decommission sequence that doesn't ask anyone to trust the fabric on day one.
-
Palo Alto Prisma SDWAN Deep Dive Part 8: Failure Modes, Scale Limits, and a Vendor Comparison Checklist
Series finale. What actually happens when Strata Cloud Manager goes dark, where Prisma SDWAN's scale limits sit, and an honest, direct comparison against Fortinet's collapsed model and Cisco's fully decoupled one — the fourth philosophy, lined up against the three already covered on this site.