This document describes how to configure Secure Access with Palo Alto Firewall.
Cisco recommends that you have knowledge of these topics:
The information in this document is based on:
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
Secure Access - Palo Alto
Cisco has designed Secure Access to protect and provide access to private applications, both on-premise and cloud-based. It also safeguards the connection from the network to the internet. This is achieved through the implementation of multiple security methods and layers, all aimed at preserving the information as they access it via the cloud.
1. Navigate to the admin panel of Secure Access.
Secure Access - Main Page
2. Click Connect > Network Connections.
Secure Access - Network Connections
3. Under Network Tunnel Groups click +Add.
Secure Access - Network Tunnel Groups
4. Configure the Tunnel Group Name, Region and Device Type.
5. Click Next.

Note: Choose the region nearest to the location of your firewall.
6. Configure the Tunnel ID Format and Passphrase.
7. Click Next.

8. Configure the IP address ranges or hosts you configured on your network and want to pass the traffic through Secure Access.
9. Click Save.
Secure Access - Tunnel Groups - Routing Options
10. After you click Save, the information on the tunnel is displayed, please save this information for the next step; Configure the tunnel on Palo Alto.

Navigate to the Palo Alto Dashboard.
1. Network > Interfaces > Tunnel.
2. Click Add.

3. Under the Config menu, configure the Virtual Router, Security Zone, and assign a Suffix Number.

4. Under IPv4, configure a non-routable IP. For example, you can use 169.254.0.1/30.
5. Click OK.

6. After that, you can have something like this configured:

7. If you have it configured like this, click on Commit to save your configuration and continue with the next step; Configure IKE Crypto Profile.
To configure the crypto profile, navigate to:
1. Network > Network Profile > IKE Crypto.
2. Click Add.

3. Configure the next parameters:
4. After everything is configured, click OK.

5. If you have it configured like this, click Commit to save your configuration and continue with the next step; Configure IKE Gateways.
To configure IKE Gateways
1. Network > Network Profile > IKE Gateways.
2. Click Add.

3. Configure the next parameters:

4. Click Advanced Options.
5. Click OK.

6. If you have it configured like this, click Commit to save your configuration and continue with the next step; Configure IPSEC Crypto.
1. To configure IKE Gateways, Navigate to Network > Network Profile > IPSEC Crypto.
2. Click Add.

3. Configure the next parameters:
4. Click OK.

5. If you have it configured like this, click Commit to save your configuration and continue with the next step; Configure IPSec Tunnels.
1. To configure IPSec Tunnels, navigate to Network > IPSec Tunnels.
2. Click Add.

3. Configure the next parameters:
4. Click OK

Caution: Proxy IDs are not supported, avoid any configurations with a Proxy ID in Palo Alto IPSEC Tunnels with Secure Access.
Now your VPN is successfully created, you can proceed with the step; Configure Policy Based Forwarding.
1. To configure Policy Based Forwarding, navigate to Policies > Policy Based Forwarding.
2. Click Add.

3. Configure the next parameters:
.4. Click OK and Commit.




Now you have everything configured on Palo Alto, after you configure the route, the tunnel can be established. You must continue configuring the RA-VPN, Browser-Based ZTA, or Client Base ZTA on Secure Access Dashboard.
| Revision | Publish Date | Comments |
|---|---|---|
2.0 |
09-Jul-2026
|
Updated spelling, grammar, spacing, added lines to separate sections for readability, and updated links for open in new page. |
1.0 |
31-Jan-2024
|
Initial Release |