<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic IP at Spoke site in PAN-OS SD-WAN Hub/Spoke topology in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-at-spoke-site-in-pan-os-sd-wan-hub-spoke-topology/m-p/1237321#M6262</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am new to PAN-OS SD-WAN and need to clarify Internet service requirement at new spoke site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My client has PAN-OS SD-WAN hub-and-spoke topology, the hub PA firewall has a static public IP for its internet service.&lt;/P&gt;&lt;P&gt;All spoke PA firewalls also use static public IPs, but we now will have a new spoke with a dynamic public IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am hoping to confirm my understanding is correct -&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;In a hub/spoke topology, spoke firewalls always initiate the IPsec tunnel to the hub. (Hub never initiate tunnels to spoke)&lt;/LI&gt;&lt;LI&gt;Therefore, new spoke with a dynamic IP should be able to connect to the hub and join the SD-WAN cluster without requiring DDNS on its interface.&lt;/LI&gt;&lt;LI&gt;Based on the admin guide below, it states "Using &lt;STRONG&gt;DHCP on a hub&lt;/STRONG&gt; requires the Palo Alto Networks DDNS service". so I assume &lt;STRONG&gt;DHCP on a branch&lt;/STRONG&gt; doesn't require DDNS service.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From Admin guide -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although DHCP Client is supported for a hub or branch interface, on a hub interface it’s preferable for you to assign a &lt;SPAN class=""&gt;Static&lt;/SPAN&gt; address instead of DHCP Client. &lt;STRONG&gt;Using DHCP on a hub requires the Palo Alto Networks DDNS service.&lt;/STRONG&gt; Using a Static address at the hub site creates a more stable environment because DDNS isn’t involved when resolving the DHCP IP address changes, and because the DDNS service can take a few minutes to register the new IP address when it changes. If you have multiple branch sites connecting to a hub site, having stability is critical to keeping the network up and running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Sep 2025 07:36:32 GMT</pubDate>
    <dc:creator>ahwang2929</dc:creator>
    <dc:date>2025-09-05T07:36:32Z</dc:date>
    <item>
      <title>Dynamic IP at Spoke site in PAN-OS SD-WAN Hub/Spoke topology</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-at-spoke-site-in-pan-os-sd-wan-hub-spoke-topology/m-p/1237321#M6262</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am new to PAN-OS SD-WAN and need to clarify Internet service requirement at new spoke site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My client has PAN-OS SD-WAN hub-and-spoke topology, the hub PA firewall has a static public IP for its internet service.&lt;/P&gt;&lt;P&gt;All spoke PA firewalls also use static public IPs, but we now will have a new spoke with a dynamic public IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am hoping to confirm my understanding is correct -&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;In a hub/spoke topology, spoke firewalls always initiate the IPsec tunnel to the hub. (Hub never initiate tunnels to spoke)&lt;/LI&gt;&lt;LI&gt;Therefore, new spoke with a dynamic IP should be able to connect to the hub and join the SD-WAN cluster without requiring DDNS on its interface.&lt;/LI&gt;&lt;LI&gt;Based on the admin guide below, it states "Using &lt;STRONG&gt;DHCP on a hub&lt;/STRONG&gt; requires the Palo Alto Networks DDNS service". so I assume &lt;STRONG&gt;DHCP on a branch&lt;/STRONG&gt; doesn't require DDNS service.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From Admin guide -&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although DHCP Client is supported for a hub or branch interface, on a hub interface it’s preferable for you to assign a &lt;SPAN class=""&gt;Static&lt;/SPAN&gt; address instead of DHCP Client. &lt;STRONG&gt;Using DHCP on a hub requires the Palo Alto Networks DDNS service.&lt;/STRONG&gt; Using a Static address at the hub site creates a more stable environment because DDNS isn’t involved when resolving the DHCP IP address changes, and because the DDNS service can take a few minutes to register the new IP address when it changes. If you have multiple branch sites connecting to a hub site, having stability is critical to keeping the network up and running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 07:36:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-at-spoke-site-in-pan-os-sd-wan-hub-spoke-topology/m-p/1237321#M6262</guid>
      <dc:creator>ahwang2929</dc:creator>
      <dc:date>2025-09-05T07:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic IP at Spoke site in PAN-OS SD-WAN Hub/Spoke topology</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-at-spoke-site-in-pan-os-sd-wan-hub-spoke-topology/m-p/1237417#M6267</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/595267999"&gt;@ahwang2929&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;That is correct, using a dynamic IP on a spoke isn't any concern in a hub-spoke topology. It would create an issue if you were using a mesh deployment, but outside of that it won't matter.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 19:54:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-at-spoke-site-in-pan-os-sd-wan-hub-spoke-topology/m-p/1237417#M6267</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-09-05T19:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic IP at Spoke site in PAN-OS SD-WAN Hub/Spoke topology</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-at-spoke-site-in-pan-os-sd-wan-hub-spoke-topology/m-p/1237427#M6270</link>
      <description>&lt;P&gt;Thanks, could you please also confirm if DHCP on a branch doesn't require DDNS service in hub/spoke topology?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 23:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-at-spoke-site-in-pan-os-sd-wan-hub-spoke-topology/m-p/1237427#M6270</guid>
      <dc:creator>ahwang2929</dc:creator>
      <dc:date>2025-09-05T23:42:46Z</dc:date>
    </item>
  </channel>
</rss>

