Use the following recommendations and requirements when you add an infrastructure
subnet for Prisma Access:
Use an RFC 1918-compliant subnet. While the use of non-RFC 1918-compliant
(public) IP addresses is supported, we don't recommend it because of possible
conflicts with the internet public IP address space.
Do not specify any subnets that overlap with the 169.254.0.0/16 and 100.64.0.0/10 subnet range because Prisma Access
reserves those IP addresses and subnets for its internal use.
This subnetwork is an extension to your existing network and therefore,
cannot overlap with any IP subnets that you use within your corporate
network or with the IP address pools that you assign for Prisma Access for
users or Prisma Access for networks.
Because the service infrastructure requires a large number of IP addresses,
you must designate a /24 subnetwork (for example, 172.16.55.0/24).
If you use dynamic routing for your remote networks or service connections,
you must also configure an RFC 6996-compliant BGP Private AS number.