<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: its possible have the same ip on proxy id on ipsectunnel and interface in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/its-possible-have-the-same-ip-on-proxy-id-on-ipsectunnel-and/m-p/1231221#M5964</link>
    <description>&lt;P&gt;thanks for ask my question&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Jun 2025 15:43:03 GMT</pubDate>
    <dc:creator>DSilva102984</dc:creator>
    <dc:date>2025-06-06T15:43:03Z</dc:date>
    <item>
      <title>its possible have the same ip on proxy id on ipsectunnel and interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/its-possible-have-the-same-ip-on-proxy-id-on-ipsectunnel-and/m-p/1230993#M5959</link>
      <description>&lt;P&gt;good afternon&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for example my ISP give me data link with ip address 192.168.20.2/28 this interface i connect to my interface 1/1 ok this work like my WAN, when i create ipsec tunnel i put same ip address on proxy ID 192.168.20/2/28 peer 10.10.10.10 this its possible ? work o have some issues with routing because en static route i have 0.0.0.0/0 next hop 192.168.20.2/28&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 23:02:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/its-possible-have-the-same-ip-on-proxy-id-on-ipsectunnel-and/m-p/1230993#M5959</guid>
      <dc:creator>DSilva102984</dc:creator>
      <dc:date>2025-06-04T23:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: its possible have the same ip on proxy id on ipsectunnel and interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/its-possible-have-the-same-ip-on-proxy-id-on-ipsectunnel-and/m-p/1231076#M5960</link>
      <description>&lt;P&gt;the proxyID is only used to negotiate tunnel SAs so doesn't impact routing&lt;/P&gt;
&lt;P&gt;you can put anything you like in there, if it makes sense to put it there in the first place&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;will connections go into the ipsec tunnel that originate from the 192.168.20.0/28 subnet ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ProxyID is set to negotiate which source subnet (clients) is allowed to communicate over the tunnel with a destination subnet (servers), so typically your local 'trust' and the remote 'trust' subnets are in the proxyID, while the untrust IP is only used in the IKE Gateway object to negotiate the tunnel itself&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 10:07:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/its-possible-have-the-same-ip-on-proxy-id-on-ipsectunnel-and/m-p/1231076#M5960</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-06-05T10:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: its possible have the same ip on proxy id on ipsectunnel and interface</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/its-possible-have-the-same-ip-on-proxy-id-on-ipsectunnel-and/m-p/1231221#M5964</link>
      <description>&lt;P&gt;thanks for ask my question&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2025 15:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/its-possible-have-the-same-ip-on-proxy-id-on-ipsectunnel-and/m-p/1231221#M5964</guid>
      <dc:creator>DSilva102984</dc:creator>
      <dc:date>2025-06-06T15:43:03Z</dc:date>
    </item>
  </channel>
</rss>

