Manage: IP Restrictions
Focus
Focus
Strata Cloud Manager

Manage: IP Restrictions

Table of Contents

Manage: IP Restrictions

Trusted IP Address List for Administrator Access
Where Can I Use This?What Do I Need?
  • Prisma Access
    (with Strata Cloud Manager or Panorama configuration management)
  • NGFWs
    (with Strata Cloud Manager or Panorama configuration management)
  • At least one of these licenses is needed to manage your configuration with Strata Cloud Manager; for unified management of NGFWs and Prisma Access, you'll need both:
    • AIOps for NGFW Premium license (use the Strata Cloud Manager app)
  • (for VM-Series software NGFWs)
→ The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are using.
Specify trusted IP addresses for Prisma Access cloud management administrators. Only administrators that log in from these source IP addresses (and also that successfully authenticate) can access Prisma Access cloud management.
The IP addresses must be public addresses. By default, there aren’t any trusted addresses enforced (the list is set to any).
To get started, go to ManageAccess ControlIP Restrictions.
For IP restrictions, subnet address is not supported. Only IP addresses and range of IP addresses is supported. Do not specify any subnets that overlap with the following IP addresses and subnets, because Prisma Access reserves those IP addresses and subnets for its internal use:
  • 169.254.169.253 and 169.254.169.254
  • 100.64.0.0/10
  • 169.254.201.0/24
  • 169.254.202.0/24
We recommend using an RFC 1918-compliant and RFC 6598-compliant IP address pool. While the use of non-RFC 1918-compliant and RFC 6598-compliant (public) IP addresses is supported, we do not recommend it because of possible conflicts with internet public IP address space.