<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sub-interface and zone || IPSec tunnel with AWS in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513341#M329</link>
    <description>&lt;P&gt;Hello OtakarKlier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DNAT Policy&lt;/P&gt;
&lt;P&gt;original packet&lt;/P&gt;
&lt;P&gt;----------------------------&lt;/P&gt;
&lt;P&gt;Source Zone - AWS Zone&lt;/P&gt;
&lt;P&gt;Destination Zone - Aws Zone&lt;/P&gt;
&lt;P&gt;Source Address- Peer subnets&lt;/P&gt;
&lt;P&gt;Destination addr - my dmz SUB-interface IP - 10.240.x.x&lt;/P&gt;
&lt;P&gt;Destination interface - tunnel.9&lt;/P&gt;
&lt;P&gt;Services - any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;translated packet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-----------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Destination NAT&lt;/P&gt;
&lt;P&gt;Static&lt;/P&gt;
&lt;P&gt;IP - PRivate ip - 10.34.x.x&lt;/P&gt;
&lt;P&gt;translated port - ---- any ---&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Security policy&lt;/P&gt;
&lt;P&gt;------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Src zone&amp;nbsp; - AWS ZOne&lt;/P&gt;
&lt;P&gt;src addr - peer subnets&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destzone - DMZ ZONE&lt;/P&gt;
&lt;P&gt;dest addr - 10.34.x.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Service - https , http&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Action - allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will this be correct if my traffic is coming from aws tunnel ??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide if m wrong in any part .&lt;/P&gt;</description>
    <pubDate>Tue, 30 Aug 2022 07:28:23 GMT</pubDate>
    <dc:creator>Doyenadmin</dc:creator>
    <dc:date>2022-08-30T07:28:23Z</dc:date>
    <item>
      <title>Sub-interface and zone || IPSec tunnel with AWS</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513194#M315</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2 queries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. I have 2 physical interfaces on which i have configured multiple sub-interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;say for eg eth1/7 - eth1/7.1,&amp;nbsp;eth1/7.2, eth1/7.3&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; eth 1/8 - eth1/8.20,&amp;nbsp;eth1/8.21,&amp;nbsp;eth1/8.22.&lt;/P&gt;
&lt;P&gt;and my both physical and subinterfaces are in same zone - say trust zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now i have an urgent requirement and i cannot addup new physical interface so can i add a new subinterface in either 1/7 or 1/8 eg eth1/7.5 or eth1/8.25 and can i add it to a new zone ?? and create policies or Inbound nat policies on that interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Little confused if that will work. Appreciate if someonce can guide few points on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2nd query.&lt;/P&gt;
&lt;P&gt;---------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am creating IPsec tunnel with AWS CGW, so it ask to create 2 tunnels, and it says to create PBF, NAT-no nat, tunnel monitor, i have created all that but still both of phases are still down, can someone share me documents i can refer to create tunnel with aws cgw.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Aug 2022 05:36:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513194#M315</guid>
      <dc:creator>Doyenadmin</dc:creator>
      <dc:date>2022-08-28T05:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface and zone || IPSec tunnel with AWS</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513287#M321</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;For the first question, yes. The interfaces can be in different zones. For the second question. Sounds like phase 1 and 2 are not configured correctly on both sides.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 19:21:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513287#M321</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-08-29T19:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface and zone || IPSec tunnel with AWS</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513301#M323</link>
      <description>&lt;P&gt;Yes you were right, phase 1 and config was incorrect, also found something strange, customer configured at aws end - Phase 1 as group 5 , sha1, and aes-128-cbc but in the configuration file which is downloaded from aws end shows different config, that is why we configured different parameters on PA end.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now both tunnels are up.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and fir the 1st query - I have question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;lets say i have eth1/7 with multiple subinterfaces&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1/7.1, 1/7.2, 1/7.3 - DMz_1 zone&lt;/P&gt;
&lt;P&gt;1/7.4 Dmz_2 zone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for DMZ 2 zone my actual traffic is coming from tunnel -aws - AWS zone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now i need to DNAT that traffic on private pool IP’s&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how can i create DNT policy for this scenario??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 19:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513301#M323</guid>
      <dc:creator>Doyenadmin</dc:creator>
      <dc:date>2022-08-29T19:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface and zone || IPSec tunnel with AWS</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513305#M324</link>
      <description>&lt;P&gt;Unless you have overlapping subnets, ie same subnet on both sides of the tunnel. I wouldnt nat the traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 20:23:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513305#M324</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-08-29T20:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface and zone || IPSec tunnel with AWS</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513341#M329</link>
      <description>&lt;P&gt;Hello OtakarKlier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DNAT Policy&lt;/P&gt;
&lt;P&gt;original packet&lt;/P&gt;
&lt;P&gt;----------------------------&lt;/P&gt;
&lt;P&gt;Source Zone - AWS Zone&lt;/P&gt;
&lt;P&gt;Destination Zone - Aws Zone&lt;/P&gt;
&lt;P&gt;Source Address- Peer subnets&lt;/P&gt;
&lt;P&gt;Destination addr - my dmz SUB-interface IP - 10.240.x.x&lt;/P&gt;
&lt;P&gt;Destination interface - tunnel.9&lt;/P&gt;
&lt;P&gt;Services - any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;translated packet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-----------------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Destination NAT&lt;/P&gt;
&lt;P&gt;Static&lt;/P&gt;
&lt;P&gt;IP - PRivate ip - 10.34.x.x&lt;/P&gt;
&lt;P&gt;translated port - ---- any ---&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Security policy&lt;/P&gt;
&lt;P&gt;------------------&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Src zone&amp;nbsp; - AWS ZOne&lt;/P&gt;
&lt;P&gt;src addr - peer subnets&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destzone - DMZ ZONE&lt;/P&gt;
&lt;P&gt;dest addr - 10.34.x.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Service - https , http&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Action - allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Will this be correct if my traffic is coming from aws tunnel ??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide if m wrong in any part .&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 07:28:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/513341#M329</guid>
      <dc:creator>Doyenadmin</dc:creator>
      <dc:date>2022-08-30T07:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface and zone || IPSec tunnel with AWS</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/514003#M360</link>
      <description>&lt;P&gt;Subnets are different say one side is 10.34.x.x and another side is 10.2.x.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but still if i want to hide my backend pool IP's I can do the NAT right ?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 07:24:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/514003#M360</guid>
      <dc:creator>Doyenadmin</dc:creator>
      <dc:date>2022-09-06T07:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface and zone || IPSec tunnel with AWS</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/514086#M364</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You can. But can get very complicated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 18:11:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/514086#M364</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-06T18:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: Sub-interface and zone || IPSec tunnel with AWS</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/514087#M365</link>
      <description>&lt;P&gt;Thanks otakarklier. I have tested the same it works successfully.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 18:16:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sub-interface-and-zone-ipsec-tunnel-with-aws/m-p/514087#M365</guid>
      <dc:creator>Doyenadmin</dc:creator>
      <dc:date>2022-09-06T18:16:58Z</dc:date>
    </item>
  </channel>
</rss>

