SC-NAT Support for Dynamic Privilege Access
Focus
Focus
What's New in the NetSec Platform

SC-NAT Support for Dynamic Privilege Access

Table of Contents

SC-NAT Support for Dynamic Privilege Access

DPA users who create service connections for private apps can use SC-NAT to avoid address exhaustion.
We introduced support for SC-NAT with Dynamic Privilege Access (DPA). This feature is available if you use DPA to enforce service connections that control access to private apps at your headquarters or in your data center. When you have multiple projects in your DPA environment, your network can experience IP address exhaustion when IP addresses in your infrastructure subnet overlap. SC-NAT support enables Prisma Access to implement source NAT (SNAT) for IP addresses to provide the following benefits:
  • Enables Prisma Access to use a service connection to map a single IP address for a mobile user accessing private apps.
  • Provides you with SNAT for easy routing.
  • Eliminates IPv4 address pool overlap.
  • Eliminates IPv4 address pool exhaustion between Prisma Access and your data center or headquarters location.