For traffic that reaches Forge, both deployments use the same supported Forge
inspection, policy, and activity pipeline. Forge routes native application,
developer API, and MCP traffic to the matching enforcement path. The deployment
type changes the network setup and available identity context, not the Forge
policy model.
The deployment type is fixed after a connection is created. Create a separate
Palo Alto connection to use the other deployment type.
Standalone PAN-OS with GlobalProtect
The standalone integration provides two complementary enforcement paths:
Gateway routing sends supported model, browser AI, developer API, and MCP
traffic through the matching Forge inspection path. Native web, desktop, and
CLI traffic keeps its existing provider login. Explicit API-key traffic uses
the LLM Gateway, and registered MCP traffic uses the MCP Gateway. Forge applies
the same identity, access, content, and tool policies across those paths.
Native enforcement covers the broader Forge AI catalog with PAN-OS security
controls. It does not redirect or decrypt matching traffic through Forge.
You select the users and devices protected by Gateway routing. Forge keeps the
destination and routing set current, then automatically sends matching traffic
to the right Forge Gateway. Users do not need to configure individual AI tools
or applications.
Setup at a glance
Connect PAN-OS, prepare the private path, match GlobalProtect sessions to Forge devices, establish certificate trust, then review and activate. Forge guides each step and shows what remains before routing can begin.Before you start
Have these items ready:- A PAN-OS management URL that Forge can reach over HTTPS.
- A dedicated PAN-OS XML API key with Configuration, Operational Requests, Log, and Commit access.
- The administrator name that issued the API key.
- An existing GlobalProtect gateway with tunnel mode and an IPv4 client pool.
- The public IPv4 address that terminates the firewall side of the IPsec tunnel.
- The users and their assigned devices in Forge.
- An enterprise CA that can sign the Forge certificate request.
Connect PAN-OS
Open Settings > Integrations > Palo Alto Networks.- Enter a Firewall name.
- Enter the PAN-OS management URL.
- Paste the API key.
- Allow Forge to manage its PAN-OS network and forwarding objects.
- Enter the PAN-OS administrator name that issued the key.
- Select Connect and discover.
API key
Create the key through the PAN-OS XML API. Paste only the value inside the returned<key> element. Do not enter the administrator username or password
in Forge.
Use a dedicated PAN-OS administrator with Configuration, Operational Requests,
Log, and Commit access. See Palo Alto Networks’
API authentication documentation.
Management certificate
When the management URL uses a private or self-signed certificate, provide the SHA-256 fingerprint of the certificate used by the management HTTPS service. Leave the fingerprint empty when the management URL uses a publicly trusted certificate.Prepare the private path
Complete each section shown on the Palo Alto Networks setup page.Select the GlobalProtect network
If Forge discovers more than one supported GlobalProtect client network, choose the network whose devices should be eligible for routing. The GlobalProtect gateway must use tunnel mode, have an IPv4 client pool, and connect its tunnel interface to one zone and one virtual router.Prepare the secure path
- Enter the firewall’s public VPN address.
- Select Prepare secure path.
- Review the PAN-OS changes shown by Forge.
- Confirm the changes.
Choose people
Configure how GlobalProtect usernames map to people in your directory, then select the people or directory groups Forge should protect.- Choose the username format used by GlobalProtect, such as full email, email username, or domain and username.
- Review the directory matches and add an exact override only when a username cannot be mapped unambiguously.
- Select the people or directory groups to protect.
- Select Save and check.
Automatic Gateway routing
Forge publishes the current supported routes for:- Supported native provider and web traffic handled by Forge native inspection while preserving the provider login.
- Explicit API-key traffic handled by the LLM Gateway.
- Registered MCP traffic handled by the MCP Gateway.
Establish certificate trust
Sign the Forge subordinate certificate with your enterprise CA so managed devices can trust the Forge Gateway.- Select Start certificate setup.
- Download the signing package.
- Sign the included CSR with your enterprise CA according to the requirements in the package.
- Return one PEM file containing the signed Forge subordinate certificate first, followed by any non-root intermediate certificates.
- Approve the certificate for Gateway inspection and select Return signed certificate.
Review and activate
Forge activates forwarding only after the private tunnel, protected people, automatic Gateway routes, and certificate trust are ready.
When active, PAN-OS forwards traffic only when:
- It comes from a current GlobalProtect session for a protected person.
- Its destination is included in the current Forge routing set.
Native access policies
Forge can also compile Access policies into PAN-OS security controls:
If applications are omitted, Forge can infer a narrow App-ID set from supported
provider or domain conditions. Forge does not widen an untranslatable policy
into an unrestricted application match.
Native rules execute in PAN-OS and do not require Gateway routing. Use them for
broad destination access control when prompt, response, or tool-level policy
evaluation is not required.
Traffic evidence
Forge can collect PAN-OS traffic evidence after network enforcement:
PAN-OS traffic logs prove network activity and enforcement. They do not prove
prompt, response, or tool content. Content visibility requires a verified
route through the matching Forge native, LLM Gateway, or MCP Gateway runtime.
Standalone troubleshooting
Forge cannot connect
- Confirm the management URL is reachable over HTTPS.
- Confirm the API key is current and has the required access.
- Confirm the administrator name matches the API key owner.
- If requested, confirm the management certificate fingerprint.
No GlobalProtect network appears
- Confirm tunnel mode is enabled on the GlobalProtect gateway.
- Confirm the gateway has a tunnel interface and IPv4 client pool.
- Confirm the tunnel interface belongs to one zone and one virtual router.
- Return to Forge and select Check PAN-OS again.
No live session appears
- Connect the device through GlobalProtect.
- Confirm its username matches a protected person in Forge.
- Check current identity status again.
Forwarding is not active
Confirm that the private tunnel, protected people, automatic Gateway routes, and certificate trust all show as ready. Configure forwarding shows the remaining issue.Panorama-managed Prisma Access Explicit Proxy
Use this path when Panorama manages an existing Prisma Access Explicit Proxy. Prisma decrypts the selected traffic and chains it to Forge over TLS. For traffic that reaches Forge, the same supported Forge policies and activity processing apply. This path attributes activity to the person and does not claim device identity.Setup at a glance
Connect Panorama, configure the Explicit Proxy chain, match Prisma usernames to Forge people, then verify forwarding and activity for the protected group.Before you start
Have these items ready:- A Prisma Access Mobile User license, Prisma Access 5.2.2, and PAN-OS dataplane 11.2.6, as required by Palo Alto Networks for proxy chaining.
- An existing Mobile Users—Explicit Proxy deployment.
- The Panorama management address and a dedicated XML API key with read access to system, Cloud Services, and security rulebase configuration.
- The exact Explicit Proxy device group and, for multi-tenant Panorama, the exact Prisma tenant name.
- The IPv4 egress CIDRs Prisma uses for upstream proxy connections.
- Directory users synchronized into Forge and the people or groups to protect.
- The Forge Prisma ingress hostname.
1. Connect Panorama in Forge
Open Settings > Integrations > Palo Alto Networks.- Select Panorama-managed Prisma Access.
- Select the Panorama tenancy mode and enter the tenant name when required.
- Enter the exact Explicit Proxy device group.
- Enter the Trusted Prisma source CIDRs, one IPv4 CIDR per line.
- Enter the Panorama name, HTTPS management address, and XML API key.
- Add the management certificate fingerprint when Panorama uses a private or self-signed certificate.
- Select Connect Panorama.
2. Configure Prisma in Panorama
For the protected scope:- Enable Explicit Proxy authentication.
- Select only the approved AI destinations in the forwarding profile and decryption policy.
- Add an App-ID
quicdeny and a UDP/443 deny above the applicable allow rules so traffic cannot bypass the proxy over HTTP/3. - Create an upstream proxy profile for the Forge hostname on port
443with TLS enabled. - Share
X-Authenticated-UserandX-Forwarded-Forat the HTTP layer. - Add an enabled upstream proxy rule for only the protected users and approved destinations with Failclose as the fallback action.
- Commit in Panorama and push to the Explicit Proxy device group.
Create and push the Prisma decryption, chaining, and QUIC rules in Panorama.
Forge validates the Panorama connection and relevant rule coverage.
3. Choose people in Forge
- Open People and groups for the Palo Alto connection.
- Choose the username format Prisma sends in
X-Authenticated-User. - Review the directory matches and add an exact override only when required.
- Select the people or groups to protect.
- Select Save and check.
4. Verify and roll back
- Send a protected person’s approved AI traffic through Prisma.
- Confirm the activity appears in Forge for the correct person.
- Confirm an unselected person and unrelated destinations keep their existing path.
- Confirm the selected traffic cannot reach the provider directly over QUIC.
- Repeat with another approved destination.
Prisma troubleshooting
- Panorama connects but traffic is not forwarded: confirm the exact tenant, device group, source CIDRs, and API read permissions, then select Save and check again.
- Forge denies the request: confirm the source CIDR, one
X-Authenticated-Uservalue, directory match, protected-user selection, and decrypted destination. - Traffic works but is absent from Forge: confirm the App-ID
quicand UDP/443 denies are enabled and above the allow rules. - Prisma cannot reach Forge: use the Forge hostname rather than its IP and
confirm port
443, TLS, IPv4 resolution, and public certificate trust.
Related pages
LLM Gateway
Govern routed model and supported browser AI traffic.
MCP Gateway
Control MCP discovery, tools, authentication, and runtime access.
Policies
Define access and content controls applied at supported enforcement points.
Architecture
Review agentless routing, native enforcement, and endpoint control paths.