What is the network impact when a Prisma Access service connection is set as a dedicated service connection for traffic steering?
A.
It maintains its zone as Trust and continues to participate in both internal and external BGP routing.
B.
It changes its zone to Untrust, applies source NAT to forwarded traffic, and no longer participates in BGP routing.
C.
It maintains its zone as Trust; however, it disables all Security policies, allowing unrestricted traffic flow through the dedicated service connection.
D.
It applies destination NAT to forwarded traffic, maintains its BGP routing configurations, and allows traffic from both Trust and Untrust zones.
When a service connection is designated as a dedicated connection specifically for traffic steering — meaning it is repurposed to carry internet-bound traffic out through a customer ' s own data center internet edge rather than functioning as an ordinary path to internal, trusted data center resources — its role in the security architecture fundamentally changes from an internal, trusted path to an internet egress path, and Prisma Access reflects that change by reclassifying its zone from Trust to Untrust. Because the traffic steered through this connection is destined for the internet rather than for internal resources reachable via dynamic routing, the dedicated connection applies source NAT to the forwarded traffic (translating it to an address appropriate for internet egress at the customer ' s edge) and stops participating in the internal BGP routing exchange that governs reachability to genuinely private, internal data center subnets — behavior that would be inappropriate for a connection now functioning as an internet breakout path. This combination of zone reclassification to Untrust, source NAT application, and BGP non-participation is exactly what option B describes. Option A incorrectly asserts the zone remains Trust and BGP participation continues unchanged, which does not reflect the reclassification that occurs. Option C incorrectly claims Security policies are disabled entirely, which would represent an unacceptable and undocumented security posture. Option D describes destination NAT and continued BGP participation, which misattributes the NAT direction and routing behavior actually associated with a dedicated traffic-steering service connection.
[Reference:Prisma Access – Traffic Steering and Dedicated Service Connection Zone/NAT Behavior.]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit