<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New RN-SPN in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/new-rn-spn/m-p/1240916#M1225</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;Today I created a new RN-SPN in one of the US location and I see the Service Endpoint Address is being displayed with the FQDN.&lt;/P&gt;
&lt;P&gt;Have created multiple nodes before and never saw an FQDN and it use to be IP address always.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just wanted to confirm if this is something which is new and will the IP address the FQDN resolving now will be static or will it change frequently?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Oct 2025 19:42:24 GMT</pubDate>
    <dc:creator>Sanjay_Ramaiah</dc:creator>
    <dc:date>2025-10-29T19:42:24Z</dc:date>
    <item>
      <title>New RN-SPN</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/new-rn-spn/m-p/1240916#M1225</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;Today I created a new RN-SPN in one of the US location and I see the Service Endpoint Address is being displayed with the FQDN.&lt;/P&gt;
&lt;P&gt;Have created multiple nodes before and never saw an FQDN and it use to be IP address always.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just wanted to confirm if this is something which is new and will the IP address the FQDN resolving now will be static or will it change frequently?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2025 19:42:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/new-rn-spn/m-p/1240916#M1225</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2025-10-29T19:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: New RN-SPN</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/new-rn-spn/m-p/1241056#M1227</link>
      <description>&lt;P&gt;I suggest seeing&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-articles/prisma-access-sase-extra-security-tips-and-features/ta-p/516045" target="_blank" rel="noopener"&gt;Prisma Access SASE Extra Security Tips and Features | Palo Alto Networks&lt;/A&gt;&amp;nbsp;point 8. Now there is Network LB infront of the MU-SPN and I suspect the same is for RN-SPN as when there is auto scale event the LB will have more SPN added. If this changes often it could depend on AWS or GCP as Prisma Access uses those and their Network LB. Is the FQDN aws or gcp one maybe that will give a clue as if not then Prisma uses AWS Route 53 or the GCP similar service and not the native FQDN given to a Network LB ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also if it was an IP address then as mentioned in&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/get-notifications-when-prisma-access-ip-addresses-change" target="_blank"&gt;Get Notifications When Prisma Access IP Addresses Change&lt;/A&gt;&amp;nbsp;you needed to monitor when there is a change as there is no predefined window like every 6 months etc&amp;nbsp; while with DNS this seems much simpler and it is mentioned in&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/remote-networks-service-ip-and-egress-ip-address-allocation" target="_blank"&gt;Remote Networks: Service Endpoint Address and Egress IP Address Allocation&lt;/A&gt;&amp;nbsp;you can either get ip (probably legacy) or FQDN.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 15:45:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/new-rn-spn/m-p/1241056#M1227</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2025-10-31T15:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: New RN-SPN</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/new-rn-spn/m-p/1242364#M1235</link>
      <description>&lt;P&gt;Just to correct myself an LB seems to be used only in&amp;nbsp;&lt;SPAN&gt;MU-SPN as users VPN traffic can be load balanced to different instances.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Still the rest for the DNS is the same as even if the IP changes the DNS stays the same and with a small DNS TTL your device will make new requests to get the new IP, Just need to check that your on-prem device does not just resolve one time DNS FQDN but I think all new on-prem routers or Firewalls now work normally and will do a new request after the DNS TTL&amp;nbsp; is over.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 07:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/new-rn-spn/m-p/1242364#M1235</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2025-11-21T07:41:19Z</dc:date>
    </item>
  </channel>
</rss>

