<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic In an environment where IP Optimization is enabled, what are the conditions under which the Egress IP increases or decreases? in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/in-an-environment-where-ip-optimization-is-enabled-what-are-the/m-p/1223551#M1118</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IP Optimization for Mobile Users—GlobalProtect Deployments&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/retrieve-ip-addre" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/retrieve-ip-addre&lt;/A&gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IP Optimization for Mobile Users&lt;BR /&gt;&lt;A href="https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu" target="_blank" rel="nofollow noopener noreferrer"&gt;https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question about the conditions under which the number of egress IPs increases in an environment where IP Optimization is enabled as described in the above document.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1)&lt;BR /&gt;&lt;A href="https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu" target="_blank" rel="nofollow noopener noreferrer"&gt;https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu&lt;/A&gt;&lt;BR /&gt;This document states the following:&lt;/P&gt;
&lt;P&gt;-------&lt;BR /&gt;When IP Optimization for Mobile Users is enabled on a tenant and that tenant deploys more than one MU-SPN in a compute region, Prisma Access deploys an ingress NLB layer for the MU-SPNs and deploys a pair of NAT instances to form a NAT layer for internet-bound traffic.&lt;BR /&gt;-------&lt;/P&gt;
&lt;P&gt;Therefore, even in an environment where IP Optimization is enabled, if a single MU-SPN is used, NLB/NAT is not configured, but if multiple MU-SPNs are used, it automatically transitions to an NLB/NAT configuration. Is this correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2)&lt;BR /&gt;Assuming that 1) above is correct, am I correct in understanding that immediately after migrating to an NLB/NAT configuration, there will be two Egress IPs in the NAT layer?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3)&lt;BR /&gt;Please tell me the conditions under which the Egress IPs increase.&lt;BR /&gt;Does this apply to an increase in the number of sessions, an increase in the number of connected users, an increase in the amount of calculations in the NAT instance, etc.?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4)&lt;BR /&gt;Am I correct in understanding that the Egress IPs increase one at a time?&lt;BR /&gt;For example, if there are two Egress IPs, will the next increase be two, resulting in four Egress IPs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5)&lt;BR /&gt;Please tell me whether the Egress IPs increase or decrease dynamically.&lt;BR /&gt;Can an Egress IP that has been increased once never decrease?&lt;/P&gt;</description>
    <pubDate>Wed, 12 Mar 2025 09:37:20 GMT</pubDate>
    <dc:creator>sawjain</dc:creator>
    <dc:date>2025-03-12T09:37:20Z</dc:date>
    <item>
      <title>In an environment where IP Optimization is enabled, what are the conditions under which the Egress IP increases or decreases?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/in-an-environment-where-ip-optimization-is-enabled-what-are-the/m-p/1223551#M1118</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IP Optimization for Mobile Users—GlobalProtect Deployments&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/retrieve-ip-addre" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/retrieve-ip-addre&lt;/A&gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IP Optimization for Mobile Users&lt;BR /&gt;&lt;A href="https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu" target="_blank" rel="nofollow noopener noreferrer"&gt;https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question about the conditions under which the number of egress IPs increases in an environment where IP Optimization is enabled as described in the above document.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1)&lt;BR /&gt;&lt;A href="https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu" target="_blank" rel="nofollow noopener noreferrer"&gt;https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu&lt;/A&gt;&lt;BR /&gt;This document states the following:&lt;/P&gt;
&lt;P&gt;-------&lt;BR /&gt;When IP Optimization for Mobile Users is enabled on a tenant and that tenant deploys more than one MU-SPN in a compute region, Prisma Access deploys an ingress NLB layer for the MU-SPNs and deploys a pair of NAT instances to form a NAT layer for internet-bound traffic.&lt;BR /&gt;-------&lt;/P&gt;
&lt;P&gt;Therefore, even in an environment where IP Optimization is enabled, if a single MU-SPN is used, NLB/NAT is not configured, but if multiple MU-SPNs are used, it automatically transitions to an NLB/NAT configuration. Is this correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2)&lt;BR /&gt;Assuming that 1) above is correct, am I correct in understanding that immediately after migrating to an NLB/NAT configuration, there will be two Egress IPs in the NAT layer?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3)&lt;BR /&gt;Please tell me the conditions under which the Egress IPs increase.&lt;BR /&gt;Does this apply to an increase in the number of sessions, an increase in the number of connected users, an increase in the amount of calculations in the NAT instance, etc.?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4)&lt;BR /&gt;Am I correct in understanding that the Egress IPs increase one at a time?&lt;BR /&gt;For example, if there are two Egress IPs, will the next increase be two, resulting in four Egress IPs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5)&lt;BR /&gt;Please tell me whether the Egress IPs increase or decrease dynamically.&lt;BR /&gt;Can an Egress IP that has been increased once never decrease?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 09:37:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/in-an-environment-where-ip-optimization-is-enabled-what-are-the/m-p/1223551#M1118</guid>
      <dc:creator>sawjain</dc:creator>
      <dc:date>2025-03-12T09:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: In an environment where IP Optimization is enabled, what are the conditions under which the Egress IP increases or decreases?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/in-an-environment-where-ip-optimization-is-enabled-what-are-the/m-p/1225623#M1127</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/161157"&gt;@sawjain&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/161157"&gt;@sawjain&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IP Optimization for Mobile Users—GlobalProtect Deployments&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/retrieve-ip-addre" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/retrieve-ip-addre&lt;/A&gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IP Optimization for Mobile Users&lt;BR /&gt;&lt;A href="https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu" target="_blank" rel="nofollow noopener noreferrer"&gt;https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question about the conditions under which the number of egress IPs increases in an environment where IP Optimization is enabled as described in the above document.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1)&lt;BR /&gt;&lt;A href="https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu" target="_blank" rel="nofollow noopener noreferrer"&gt;https://svc-desc.paloaltonetworks.com/mobile-users/gp/ip-optimization-mu&lt;/A&gt;&lt;BR /&gt;This document states the following:&lt;/P&gt;
&lt;P&gt;-------&lt;BR /&gt;When IP Optimization for Mobile Users is enabled on a tenant and that tenant deploys more than one MU-SPN in a compute region, Prisma Access deploys an ingress NLB layer for the MU-SPNs and deploys a pair of NAT instances to form a NAT layer for internet-bound traffic.&lt;BR /&gt;-------&lt;/P&gt;
&lt;P&gt;Therefore, even in an environment where IP Optimization is enabled, if a single MU-SPN is used, NLB/NAT is not configured, but if multiple MU-SPNs are used, it automatically transitions to an NLB/NAT configuration. Is this correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2)&lt;BR /&gt;Assuming that 1) above is correct, am I correct in understanding that immediately after migrating to an NLB/NAT configuration, there will be two Egress IPs in the NAT layer?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3)&lt;BR /&gt;Please tell me the conditions under which the Egress IPs increase.&lt;BR /&gt;Does this apply to an increase in the number of sessions, an increase in the number of connected users, an increase in the amount of calculations in the NAT instance, etc.?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4)&lt;BR /&gt;Am I correct in understanding that the Egress IPs increase one at a time?&lt;BR /&gt;For example, if there are two Egress IPs, will the next increase be two, resulting in four Egress IPs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5)&lt;BR /&gt;Please tell me whether the Egress IPs increase or decrease dynamically.&lt;BR /&gt;Can an Egress IP that has been increased once never decrease?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;1) That's right, NLB and NAT layers are deployed for auto-scaled gateway situations/minimum two or more gateways should be available for a region&lt;/P&gt;
&lt;P&gt;2) That is correct, There will be a pair of NAT instances deployed . That means there will be two egress IPs minimum.&lt;/P&gt;
&lt;P&gt;3) NAT Instances supports numerous concurrent connections with scale capabilities, Number of NAT instance may vary depending on the number of MU gateways so on.&lt;/P&gt;
&lt;P&gt;4 &amp;amp; 5) When you enable Optimization It enables a pair of NAT instance first then It shouldn't go from 2 to 4, not like that. It depends on the tenant capacity requirement. I would suggest, to know more granular information related to this you may change please reach out to your respective Customer Success team to help with with identifying the capacity if needed&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 19:14:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/in-an-environment-where-ip-optimization-is-enabled-what-are-the/m-p/1225623#M1127</guid>
      <dc:creator>uthankappanpi</dc:creator>
      <dc:date>2025-04-03T19:14:38Z</dc:date>
    </item>
  </channel>
</rss>

