IP Optimization for Mobile Users—GlobalProtect Deployments
Focus
Focus
Prisma Access

IP Optimization for Mobile Users—GlobalProtect Deployments

Table of Contents
IP Optimization provides a simpler, deterministic public IP address allow listing experience, improved resiliency, and faster onboarding of Prisma Access tenants.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama)
  • Prisma Access (Managed by Strata Cloud Manager)
  • Prisma Access license
  • Prisma Access version 5.0 or later
IPv6 Support for Public Apps for IP Optimization: requires:
  • 6.2.6 client version for Windows and Macos
  • 6.2.7 for Linux
  • 6.1.7 for Android and IOS
IP Optimization is a set of architectural enhancements that reduce the overall number of IP addresses in your deployment, simplifying your allow listing workflows while improving resiliency and enabling faster onboarding of Prisma Access tenants.
  • Simpler Public IP Address Allow Listing for Mobile Users—GlobalProtect Deployments–Adding a Prisma Access location or experiencing a scaling event at an existing Prisma Access location could lead to new IP addresses being allocated to the mobile user security processing node (MU-SPN).
    It's a best practice to
    retrieve the egress and ingress IP addresses
    that Prisma Access assigns and in your network to avoid SaaS application or corporate firewall disruption. This can result in a situation where you're managing a large number of IP addresses. IP Optimization reduces the number of IP addresses you have to manage.
Make a note of the following additional requirements for IP Optimization:
  • IP Optimization requires Prisma Access 5.0 or later for Mobile Users optimization , and can be enabled when you set up GlobalProtect for the first time.
  • When you set up GlobalProtect for the first time, you’ll be asked whether or not you want to enable Prisma Access IP Optimization.
  • The following functionality is not supported with IP Optimization:

Allow Listing Considerations for IP Optimization Deployments

When you use the API to retrieve Prisma Access IP addresses for IP Optimization, there are two sets of IP addresses you need to add:
  • serviceType of gp_gateway and gp_portal—The egress IP addresses the Prisma Access service uses for the cloud gateways and portals. Add these addresses to your network allow lists to provide access to internet or SaaS apps.
  • addrType of network_load_balancer—The ingress IP addresses that you need to add to your NGFW allow list or client endpoint policies. Internet or SaaS apps do not see these IP addresses; however, you need to add them to your network in the following scenarios:
    • If you have users in a remote site who are behind an on-premises perimeter NGFW, add the network_load_balancer IP addresses to the NGFW security policies to allow those users to connect to Prisma Access.
    • To allow ingress IP access across Windows, macOS, and Linux systems, add the network_load_balancer IP addresses to your endpoint security controls, including:
      • Windows Defender or Firewall allow list rules
      • macOS application firewall exceptions
      • Linux firewall allow list rules