For traffic that reaches Forge, both deployments use the same supported Forge
inspection, policy, and activity pipeline. Forge routes native application,
developer API, and MCP traffic to the matching enforcement path. The deployment
type changes the network setup and available identity context, not the Forge
policy model.
The deployment type is fixed after a connection is created. Create a separate
Palo Alto connection to use the other deployment type.
Standalone PAN-OS with GlobalProtect
The standalone integration routes selected AI traffic from GlobalProtect devices through Forge. Native web, desktop, and CLI traffic keeps its existing provider login. Explicit API-key traffic uses the LLM Gateway, and registered MCP traffic uses the MCP Gateway. Forge applies identity, access, content, and tool policies in the inline Forge path. You select the users and devices protected by Gateway routing. Forge keeps the destination and routing set current, then automatically sends matching traffic to the right Forge Gateway. Users do not need to configure individual AI tools or applications.Setup at a glance
Connect PAN-OS, prepare the private path, match GlobalProtect sessions to Forge devices, establish certificate trust, then review and activate. Forge guides each step and shows what remains before routing can begin.Before you start
Have these items ready:- A PAN-OS management URL that Forge can reach over HTTPS.
- A dedicated PAN-OS XML API key with Configuration, Operational Requests, and Commit access.
- The administrator name that issued the API key.
- An existing GlobalProtect gateway with tunnel mode and an IPv4 client pool.
- The public IPv4 address that terminates the firewall side of the IPsec tunnel.
- The users and their assigned devices in Forge.
- An enterprise CA that can sign the Forge certificate request.
Create the XML API credential
Create a dedicated administrator and Admin Role profile on the firewall. Enable the XML API Configuration, Operational Requests, and Commit capabilities needed by this integration, then generate an API key for that administrator through PAN-OS’s supported key-generation flow. Retain the issuing administrator name alongside the key. Set an expiry and plan rotation before activation. Follow Palo Alto’s API access guide. For the Panorama read-only connection below, use its separate read-access role; do not copy standalone firewall write privileges into that credential.Connect PAN-OS
Open Integrations > Palo Alto Networks.- Enter a Firewall name.
- Enter the PAN-OS management URL.
- Paste the API key.
- Allow Forge to manage its PAN-OS network and forwarding objects.
- Enter the PAN-OS administrator name that issued the key.
- Select Connect and discover.
API key
Create the key through the PAN-OS XML API. Paste only the value inside the returned<key> element. Do not enter the administrator username or password
in Forge.
Use a dedicated PAN-OS administrator with Configuration, Operational Requests,
and Commit access. See Palo Alto Networks’
API authentication documentation.
Management certificate
When the management URL uses a private or self-signed certificate, provide the SHA-256 fingerprint of the certificate used by the management HTTPS service. Leave the fingerprint empty when the management URL uses a publicly trusted certificate.Prepare the private path
Complete each section shown on the Palo Alto Networks setup page.Select the GlobalProtect network
If Forge discovers more than one supported GlobalProtect client network, choose the network whose devices should be eligible for routing. The GlobalProtect gateway must use tunnel mode, have an IPv4 client pool, and connect its tunnel interface to one zone and one virtual router.Prepare the secure path
- Enter the firewall’s public VPN address.
- Select Prepare secure path.
- Review the PAN-OS changes shown by Forge.
- Confirm the changes.
Choose people
Configure how GlobalProtect usernames map to people in your directory, then select the people or directory groups Forge should protect.- Choose the username format used by GlobalProtect, such as full email, email username, or domain and username.
- Review the directory matches and add an exact override only when a username cannot be mapped unambiguously.
- Select the people or directory groups to protect.
- Select Save and check.
Automatic Gateway routing
Forge publishes the current supported routes for:- Supported native provider and web traffic handled by Forge native inspection while preserving the provider login.
- Explicit API-key traffic handled by the LLM Gateway.
- Registered MCP traffic handled by the MCP Gateway.
Establish certificate trust
Sign the Forge subordinate certificate with your enterprise CA so managed devices can trust the Forge Gateway.- Select Start certificate setup.
- Download the signing package.
- Sign the included CSR with your enterprise CA according to the requirements in the package.
- Return one PEM file containing the signed Forge subordinate certificate first, followed by any non-root intermediate certificates.
- Approve the certificate for Gateway inspection and select Return signed certificate.
Review and activate
Forge activates forwarding only after the private tunnel, protected people, automatic Gateway routes, and certificate trust are ready.
When active, PAN-OS forwards traffic only when:
- It comes from a current GlobalProtect session for a protected person.
- Its destination is included in the current Forge routing set.
Standalone troubleshooting
Forge cannot connect
- Confirm the management URL is reachable over HTTPS.
- Confirm the API key is current and has the required access.
- Confirm the administrator name matches the API key owner.
- If requested, confirm the management certificate fingerprint.
No GlobalProtect network appears
- Confirm tunnel mode is enabled on the GlobalProtect gateway.
- Confirm the gateway has a tunnel interface and IPv4 client pool.
- Confirm the tunnel interface belongs to one zone and one virtual router.
- Return to Forge and select Check PAN-OS again.
No live session appears
- Connect the device through GlobalProtect.
- Confirm its username matches a protected person in Forge.
- Check current identity status again.
Forwarding is not active
Confirm that the private tunnel, protected people, automatic Gateway routes, and certificate trust all show as ready. Configure forwarding shows the remaining issue.Panorama-managed Prisma Access Explicit Proxy
Use this path when Panorama manages an existing Prisma Access Explicit Proxy. Prisma decrypts the selected traffic and chains it to Forge over TLS. For traffic that reaches Forge, the same supported Forge policies and activity processing apply. This path attributes activity to the person and does not claim device identity.Setup at a glance
Connect Panorama, configure the Explicit Proxy chain, match Prisma usernames to Forge people, then verify forwarding and activity for the protected group.Before you start
Have these items ready:- A Prisma Access Mobile User license, Prisma Access 5.2.2, and PAN-OS dataplane 11.2.6, as required by Palo Alto Networks for proxy chaining.
- An existing Mobile Users—Explicit Proxy deployment.
- The Panorama management address and a dedicated XML API key with read access to system, Cloud Services, and security rulebase configuration.
- The exact Explicit Proxy device group and, for multi-tenant Panorama, the exact Prisma tenant name.
- The IPv4 egress CIDRs Prisma uses for upstream proxy connections.
- Directory users synchronized into Forge and the people or groups to protect.
- The Forge Prisma ingress hostname.
1. Connect Panorama in Forge
Open Integrations > Palo Alto Networks.- Select Panorama-managed Prisma Access.
- Select the Panorama tenancy mode and enter the tenant name when required.
- Enter the exact Explicit Proxy device group.
- Enter the Trusted Prisma source CIDRs, one IPv4 CIDR per line.
- Enter the Panorama name, HTTPS management address, and XML API key.
- Add the management certificate fingerprint when Panorama uses a private or self-signed certificate.
- Select Connect Panorama.
2. Configure Prisma in Panorama
For the protected scope:- Enable Explicit Proxy authentication.
- Select only the approved AI destinations in the forwarding profile and decryption policy.
- Add an App-ID
quicdeny and a UDP/443 deny above the applicable allow rules so traffic cannot bypass the proxy over HTTP/3. - Create an upstream proxy profile for the Forge hostname on port
443with TLS enabled. - Share
X-Authenticated-UserandX-Forwarded-Forat the HTTP layer. - Add an enabled upstream proxy rule for only the protected users and approved destinations with Failclose as the fallback action.
- Commit in Panorama and push to the Explicit Proxy device group.
Create and push the Prisma decryption, chaining, and QUIC rules in Panorama.
Forge validates the Panorama connection and relevant rule coverage.
3. Choose people in Forge
- Open People and groups for the Palo Alto connection.
- Choose the username format Prisma sends in
X-Authenticated-User. - Review the directory matches and add an exact override only when required.
- Select the people or groups to protect.
- Select Save and check.
4. Verify and roll back
- Send a protected person’s approved AI traffic through Prisma.
- Confirm the activity appears in Forge for the correct person.
- Confirm an unselected person and unrelated destinations keep their existing path.
- Confirm the selected traffic cannot reach the provider directly over QUIC.
- Repeat with another approved destination.
Prisma troubleshooting
- Panorama connects but traffic is not forwarded: confirm the exact tenant, device group, source CIDRs, and API read permissions, then select Save and check again.
- Forge denies the request: confirm the source CIDR, one
X-Authenticated-Uservalue, directory match, protected-user selection, and decrypted destination. - Traffic works but is absent from Forge: confirm the App-ID
quicand UDP/443 denies are enabled and above the allow rules. - Prisma cannot reach Forge: use the Forge hostname rather than its IP and
confirm port
443, TLS, IPv4 resolution, and public certificate trust.
Related pages
Gateway
Govern routed model and supported browser AI traffic.
MCP Gateway
Control MCP discovery, tools, authentication, and runtime access.
Policies
Define access and content controls applied at supported enforcement points.
Architecture
Review agentless routing, inline enforcement, and endpoint control paths.