Use SC-NAT support for Dynamic Privilege Access (DPA) if you use DPA and have
created service connections to access private apps in your data center or
headquarters location. Multiple projects in your DPA environment can experience
IP address exhaustion if the IP addresses of the infrastructure subnet overlap.
To fix this issue, Prisma Access can implement source NAT (SNAT) for IP
addresses, which:
- Lets Prisma Access map a single IP address for a mobile user accessing
private apps using a service connection
- Provides you with SNAT for easy routing
- Eliminates IP Pool overlap
- Eliminates IP Pool IPv4 exhaustion between Prisma Access and your data
center or headquarters location
DPA customers can onboard client locations to Prisma Access using service
connections. However, multiple projects may have large IP pools on multiple data
centers, leading to potential exhaustion of private IP pools. To solve this
issue, Dynamic Privilege Access in Prisma Access offers support for SC-NAT with
defined pools. Customers have the option to use SC-NAT instead of the
infrastructure subnet in order to divide up the IP pools. If you enable SC-NAT
for a service connection corporate access node (SC-CAN), SC-NAT will always be
supported for that service connection.
With DPA enabled, you can turn SC-NAT on (to use SC-NAT) or off (to use the
Infrastructure Subnet) per project.
- In Strata Cloud Manager, select .
- Select a service connection from the Service
Connections table.
- Click the check box for Data Traffic Source NAT.
- After you click the Data Traffic Source NAT check
box, you see the mandatory IP Pool field. Enter the
subnets for which you want to enable SC-NAT.
- Save your changes.