Is it possible to specify a source address for certain destinations when using Prisma Access?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Is it possible to specify a source address for certain destinations when using Prisma Access?

L3 Networker

Some of our partners or vendors require us to specify a source IP address in order to be able to access their systems on the public Internet. Currently we just make their destination part of our split tunnel destination to our data center PANs and then the traffic takes on that source network IP. Is the same possible when you are using Prisma access?

1 accepted solution

Accepted Solutions

L6 Presenter

It is possible to see the source public ip addresses that your traffic will use on the Internet that will be given to you and retrive it API script then you can use it:

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-ov...

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-ov...

 

 

The prisma access IP addresses can change after time, so see the workaround  at:

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-ov...

 

 

Also you have the option "Enable Source NAT for Mobile Users—GlobalProtect IP pool addresses, IP addresses in the Infrastructure Subnet, or both." under a Service connection but maybe dissable that so the Data Center can see the real user ip addresses. Check this:

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-pris...

 

 

Prisma Acess for now can't insert XFF (X-Forwarded-For) header which will make life easier as then you can use the real ip addresses but it is what it is.

 

 

For inbound traffic you can dissable SNAT this way you will see the real client ip addresses.

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-ad...

 

As you will starting to work with Prisma Access better take the Palo Alto training as to have the needed knowedge or atleast to see the youtube training EDU-118 that is old but still you will have some basic idea:

 

 

https://www.youtube.com/results?search_query=Prisma+Access+EDU-118

 

 

https://www.youtube.com/watch?v=1mRLEEV3CwM

 

https://www.youtube.com/watch?v=VX9an7QMGqE

 

https://www.youtube.com/watch?v=VX9an7QMGqE

 

 

That is it from me 🙂

 

View solution in original post

1 REPLY 1

L6 Presenter

It is possible to see the source public ip addresses that your traffic will use on the Internet that will be given to you and retrive it API script then you can use it:

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-ov...

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-ov...

 

 

The prisma access IP addresses can change after time, so see the workaround  at:

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-ov...

 

 

Also you have the option "Enable Source NAT for Mobile Users—GlobalProtect IP pool addresses, IP addresses in the Infrastructure Subnet, or both." under a Service connection but maybe dissable that so the Data Center can see the real user ip addresses. Check this:

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-pris...

 

 

Prisma Acess for now can't insert XFF (X-Forwarded-For) header which will make life easier as then you can use the real ip addresses but it is what it is.

 

 

For inbound traffic you can dissable SNAT this way you will see the real client ip addresses.

 

https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prisma-access-ad...

 

As you will starting to work with Prisma Access better take the Palo Alto training as to have the needed knowedge or atleast to see the youtube training EDU-118 that is old but still you will have some basic idea:

 

 

https://www.youtube.com/results?search_query=Prisma+Access+EDU-118

 

 

https://www.youtube.com/watch?v=1mRLEEV3CwM

 

https://www.youtube.com/watch?v=VX9an7QMGqE

 

https://www.youtube.com/watch?v=VX9an7QMGqE

 

 

That is it from me 🙂

 

  • 1 accepted solution
  • 1438 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!