Skip to main content
Solved

NPA Website URL Access IP Egress Traffic

  • February 24, 2025
  • 7 replies
  • 142 views

secproceo
Netskope Partner

I have a website URL port 443 configured for NPA due to Geo-restrictions. I have developers that need to access a US site. I have a Publisher in my data center in the US behind a gateway public IP of 168.xxx.xx.x. When my user hits the web URL, they get a 163.xxx.xx.x address. Should the NPA web URL use the local gateway address for egress traffic?

Best answer by venkatesanek

If private app is configured with FQDNs of website properly, then traffic should be intercepted & tunneled via NPA and egress IP will be your datacenter public IP range.

Here in this case, the traffic looks to be steered via SWG tunnel of NS client, hence Netskope egress IP range(163.128.X.X) is used.

Kindly raise a support case with private app details and collect the NS client log bundle with inner pcap & outer pcap during replication.

This topic has been closed for replies.

7 replies

Forum|alt.badge.img+7
  • Netskope Employee
  • Answer
  • February 28, 2025

If private app is configured with FQDNs of website properly, then traffic should be intercepted & tunneled via NPA and egress IP will be your datacenter public IP range.

Here in this case, the traffic looks to be steered via SWG tunnel of NS client, hence Netskope egress IP range(163.128.X.X) is used.

Kindly raise a support case with private app details and collect the NS client log bundle with inner pcap & outer pcap during replication.


secproceo
Netskope Partner
  • Author
  • Netskope Partner
  • February 28, 2025

Thanks for the update. I will raise a ticket. 

I want to confirm if everything is configured properly, the NPA tunnel traffic should show the local gateway IP, not the (163.128.x.x). Is that correct? 


Forum|alt.badge.img+7
  • Netskope Employee
  • February 28, 2025

Yes, if website traffic is steered via NPA, then egress IP should not be part of 163.128.X.X


secproceo
Netskope Partner
  • Author
  • Netskope Partner
  • February 28, 2025

I got it. Do I also need to add the website to a steering bypass so it does not steer traffic through SWG? I was always told NPA takes precedence over SWG. 


Forum|alt.badge.img+7
  • Netskope Employee
  • February 28, 2025

NPA traffic takes precedence over SWG traffic so no need to add steering bypass.


secproceo
Netskope Partner
  • Author
  • Netskope Partner
  • February 28, 2025

Interesting. That is what I thought as well. However, the website configured in NPA continued to give me the 163.128.x.x. address until I added the URL to the steering bypass. I now get the local gateway egress IP. This is exactly what I needed. 

 

This is resolved, however, is there a reason I had to bypass the site in the steering bypass? 

 

Thanks. 


secproceo
Netskope Partner
  • Author
  • Netskope Partner
  • March 1, 2025

This is now resolved.😀 I was able to get the NPA configuration working. Thanks again for your time.