Q: How long does it take for
dedicated IP addresses to become available?
A: The
process typically takes a few minutes to complete across all supported
regions.
Q: Can I use the same IP addresses across
multiple tenants?
A: No, each tenant receives unique
dedicated IP addresses to ensure proper isolation and security. For
organizations managing multiple tenants, including all relevant IP addresses
in the conditional access configuration is crucial.
Q:
How long will the IP addresses remain reserved?
A:
The system allocates your dedicated IP address to your tenant for as long as
your tenant remains active as long as the Dedicated IP Addresses
feature is enabled.
Q: Which platforms support the
Authentication Gateway?
A: The feature is available
for both Prisma Access Browser for desktop and mobile.
Q:
What is the expected behavior if the dedicated Authentication Gateways
is configured, but the user has an old browser version?
A: Old browser versions will keep sending traffic to the legacy
Authentication Gateway (“shared proxy”) until the browser is up to date. For
desktop browsers, the extension version should be automatically updated
immediately after the next browser launch. For the Mobile Browser, ensure
that users update to a supported version.
Q: What does
the traffic flow look like if I configure “route all traffic to Prisma
Access”?
A: When you enable the authentication
routing, the authentication traffic will be routed through the
authentication proxy regardless of the general traffic routing to Prisma
Access.
Q: What happens if a region becomes
unavailable?
A: The system or browser automatically
routes users to the second-nearest available region to maintain service
continuity.
Q: Can I see all the Traffic logs in
SLS?
A: Currently this isn’t available.
Q: My tenant is in a different region than the Authentication
Gateways. What will happen?
A: Authentication
traffic will be routed through the region nearest to the user.
Q: Can
I use a dedicated authenticated gateway with an Eval/Lab license?A:
The creation of dedicated egress IP addresses is a feature of paid
subscriptions. If you're on a trial or require access through a different
arrangement, contact your account team.