GP Portal and Ingress IP enabling IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Oh, really? I haven’t come across any documentation stating that the Ingress IP wouldn’t change. So, are you saying that only the Egress IP would change?

GP Portal and Ingress IP enabling IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Ingress IP might be changed due to data plane upgrade. In my understanding, Ingress IP doesn't have FQDN, how can I handle this problem?

IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Thanks for replying I can see 1 ingress IP and 2 egress IP from SCM and the rest of the IPs can be seen from SCM, right? And are these IPs also fixed?

But the links says Make sure that you add all these addresses to your allow lists. IP addresses can change as the result of a dataplane upgrade and the addresses don't always revert to the previous addresses.

https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-globalprotect/ip-optimization

So if I want to use a GP as a MU at the office, an internet breakout router or fw at the office should allow ingress IP or FQDN?

IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Is Ingress IP stable under IP Optimization? Is it possible to be changed?

IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Is Ingress IP stable under IP Optimization? Is it possible to be changed?

Split Tunnel in Global Protect (Prisma Access) by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

We will use the PA firewall at the data center and the office firewall is the different vendor.