Hi everyone, I’ve been trialing Prisma Access for a small deployment and noticed something strange in our traffic logs.
Our users and a test server are physically in Sydney, Australia, but the logs show traffic exiting the service through Singapore locations. This adds noticeable latency. Is this expected behavior? I checked our portal config and don't see a specific region override. Could it be a capacity thing, or have I missed a setting? Thanks for any insights—really appreciate this community's help.
Yes, this is expected behavior and you haven't missed a setting. The Prisma Access network uses aggregated 'Service Connections' and a hub-and-spoke model for optimal traffic distribution. Even with users in Sydney, the egress point for a given session is determined by the nearest major data hub with sufficient capacity and the most efficient path to the destination's own network. For many Asia-Pacific routes, especially those destined for global SaaS platforms hosted in the US or Europe, Singapore often serves as the primary hub.
You can verify the rationale by checking the path your test traffic takes to a specific public IP. The latency penalty is the trade-off for the aggregated security inspection and the deterministic routing Palo Alto uses for threat prevention consistency. For a trial, it's worth raising a support case to request a review of your specific deployment's routing logic; they can sometimes provide placement guidance based on your expected traffic patterns.
Migrate slow, validate fast.