How to get a static public IP from CF when connected to CF VPN

Hi, I have zero trust setup working. My tunnel shows connected. When I am connected to the VPN, I get a public IP from 104.28.220.x range. My colleagues get VPN public IP from 104.16.0.0./12 range. I need to allow this CIDR in security group otherwise we cannot access certain public facing apps that we have hosted.

How do I configure a static public IP so that anyone connecting to VPN through that tunnel will get the static public IP.
Was this page helpful?