What are service connections used for?
As we already touched upon at the beginning of this book, service connections, or SC-CANs, represent a data center connection, an extension of the data center into the cloud. Because of this function, the SC-CAN has some distinctive characteristics, some shared with remote network security processing nodes (RN-SPN), some unique to SC-CAN.
Figure 4.1 – Prisma Access overall architecture
A service connection is established by creating an IPSec VPN tunnel between a Prisma Access CAN and a data center. The resulting tunnel is a service connection. All traffic up and down between the data center and Prisma Access will traverse this VPN tunnel.
Unlike an SPN, there is no security enforcement on the CAN. Therefore, even though the remote VPN peer can be any IPSec-capable device, it is recommended to have a security-capable device such as a next-generation firewall (NGFW) that can enforce security policies and perform...