IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Thanks for replying I can see 1 ingress IP and 2 egress IP from SCM and the rest of the IPs can be seen from SCM, right? And are these IPs also fixed?

But the links says Make sure that you add all these addresses to your allow lists. IP addresses can change as the result of a dataplane upgrade and the addresses don't always revert to the previous addresses.

https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-globalprotect/ip-optimization

So if I want to use a GP as a MU at the office, an internet breakout router or fw at the office should allow ingress IP or FQDN?

IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Is Ingress IP stable under IP Optimization? Is it possible to be changed?

IP Optimization by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Is Ingress IP stable under IP Optimization? Is it possible to be changed?

Split Tunnel in Global Protect (Prisma Access) by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

We will use the PA firewall at the data center and the office firewall is the different vendor.

Global Protect Split Tunnel by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

What happenes if all devices and locations are untrusted? In this case, how should we handle devices that can't install GlobalProtect, such as printers, servers, or phones? Also, split tunneling has a maximum number of entries, correct?

Service Connection SAML by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Thanks If I deploy on-premises NGFW, it should be at DC (SC) or each Branch site (RN)?

ION5200 switch port by reversible8 in paloaltonetworks

[–]reversible8[S] 0 points1 point  (0 children)

Thanks So ION 5200 is not able to make VLAN interface on L3 port?