: Configure Service Provider IP Address Pools Through the Strata Multitenant Cloud Manager
Focus
Focus

Configure Service Provider IP Address Pools Through the Strata Multitenant Cloud Manager

Table of Contents

Configure Service Provider IP Address Pools Through the Strata Multitenant Cloud Manager

Learn how to configure Service Provider IP address pools through the Strata Multitenant Cloud Manager
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
  • Prisma Access license or SASE bundle license
  • Identity & Access role: Multitenant Superuser or Multitenant IAM Administrator or IAM Administrator or Auditor
After you activate a Service Provider license for your top-most, root-level, parent tenant, add Service Provider (SP) Backbones and connections, you can configure IP address pools. Service Provider Backbones enable service providers to offer granular Prisma Access egress traffic routes to their customers through public cloud providers for network backbone traffic. Alternatively, you can add a specific IP address pool to leverage your own IP addresses for egress traffic instead.
General steps follow for configuring a Prisma Access IP address pool or configuring your own IP address pool.
  1. Access the Prisma SASE Multitenant Portal and select ManageService Provider Backbones.
  2. Navigate to the IP Pool Configurations tab, where you have the choice of GCP or AWS tabs.
  3. Select Add IP pool.
  4. Enter an IP Pool Name.
  5. Select a Compute Region.
  6. (GCP only) Select a Backup Region.
  7. Choose an IP Pool Type of Prisma Access IP or Bring your own IP and complete based on the steps that follow for your scenario.

Configure a Prisma Access IP Address Pool

Offer granular Prisma Access egress traffic routes to your customers through public cloud providers for network backbone traffic.
  1. Complete the preceding general configuration steps.
  2. Enter an SP Partner Email address.
    This is the email address where a Palo Alto Networks SRE will contact you with information about the IP addresses that you have been assigned.

Configure Your Own IP Address Pool

Offer granular Prisma Access egress traffic routes to your customers through your own IP address pool for network backbone traffic.
  1. Complete the preceding general configuration steps.
  2. Select an edge Location.
  3. Enter an IP Pool. Enter multiple values separated by commas (no spaces) or enter an address with a subnet mask of a minimum of /29 to a maximum of /24.
    1. (Optional) You can add another by selecting +Location / IP Pool.
      • The maximum limit is 10 subnets per region.
      • After the IP subnet is consumed, you can't change it.
  4. Submit.

View IP Configuration Status

After you configure an IP address pool, this page offers the following table:
Title
Description
IP Pool Name
The name you assigned to the IP address pool.
IP Provider
Compute Region
The region you assigned to the IP address pool.
Backup Region (GCP only)
The backup region you assigned to the IP address pool.
Location
The location you assigned to the IP address pool.
IP Pool SubnetsThe IP address pool you added. For a Palo Alto Networks IP address pool, this displays "N/A" before assignment and it displays "PANW Assigned IP" after assignment.
Status
  • Active — The backbone has at least one active connection, so is considered active.
  • Pending — The SP must do the configurations for BGP peering and work with the Palo Alto Networks SRE.
  • Error — Edit or delete the connection details and try again.
Assign to Region
This begins as a button. After you configure an IP pool, you can assign the pool to a region. After you assign the pool to a region, the button changes to a status.
Actions
Can’t use the actions while the status is pending.
  • Delete — You need to have at least one address pool. If you have configured multiple pools, you can't delete them all.
  • Edit — Once an IP subnet is consumed, it cannot be changed. But you can add more.