<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN peer ID in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-peer-id/m-p/1252316#M6848</link>
    <description>&lt;P&gt;I am confused about the meaning of this topic. Could you explain the issue related to the real IP address of a third party? Consider this IP as a dynamic peer type and develop the configuration based on that, as mentioned in the provided link. &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIGCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIGCA0&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2026 11:15:32 GMT</pubDate>
    <dc:creator>abayoumi21</dc:creator>
    <dc:date>2026-04-16T11:15:32Z</dc:date>
    <item>
      <title>VPN peer ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-peer-id/m-p/1252080#M6841</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have a 3rd party VPN peer who must set the&amp;nbsp;&lt;SPAN&gt;Peer Identification value, the tunnel works fine, but on their side the tunnel ID IP address can change depending on whether they are on their active or standby firewall, and that means we need to update config and push policy to get it online (this is a regular occurrence)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I thought about using an fqdn entry, and updating the A record as needed as its a bit less touch than a firewall change. But I am wondering, can we have the fqdn point to an A record that resolves to 2 IP addresses? I know DNS side its fine but any idea if the palo will work, I somewhat suspect it will only take the first returned address and ignore the second but interested to know if anyone has tried it, Its a prod tunnel so I cant really test it myself&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 05:21:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-peer-id/m-p/1252080#M6841</guid>
      <dc:creator>speedy_1s</dc:creator>
      <dc:date>2026-04-13T05:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN peer ID</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-peer-id/m-p/1252316#M6848</link>
      <description>&lt;P&gt;I am confused about the meaning of this topic. Could you explain the issue related to the real IP address of a third party? Consider this IP as a dynamic peer type and develop the configuration based on that, as mentioned in the provided link. &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIGCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIGCA0&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2026 11:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-peer-id/m-p/1252316#M6848</guid>
      <dc:creator>abayoumi21</dc:creator>
      <dc:date>2026-04-16T11:15:32Z</dc:date>
    </item>
  </channel>
</rss>

