Palo Alto Networks Strata Cloud Manager Configuration
Before configuring the Security Service Edge (SSE) automation, you must first configure IKE and IPsec profiles to be used by the SSE automation. This is required for initiating the tunnel from the Edge to Prisma Cloud. This is a one-time manual configuration that must be performed in the Palo Alto Networks Strata Cloud Manager portal.
There is no dedicated location in the Palo Alto Networks Strata Cloud Manager portal to configure the IKE and IPsec profiles. Hence, this configuration must be done in the Remote Networks configuration section.
- AES 128 CBC
- DH Group 14 (IKE Crypto Profile)
- PFS configured (same as the DH Group value)
- SHA 256
- IKE SA Lifetime 1440 min
- IPsec SA Lifetime 480 min
Follow the below steps to configure IKE and IPsec profiles:
You may now log into the Orchestrator to configure the Security Service Edge (SSE) and initiate the automation. For more information, see the topic Security Service Edge (SSE).









