<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Where to add Proxy ID with multiple tunnels? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/530391#M885</link>
    <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;We have 3 firewalls:&lt;/P&gt;
&lt;P&gt;C1 = Cisco FW - Policy based S2S VPN -- subnet behind it 10.1.0.0/24&lt;/P&gt;
&lt;P&gt;P2 = Palo FW - Route based S2S VPN&amp;nbsp;-- subnet behind it 172.16.50.0/24&lt;/P&gt;
&lt;P&gt;C3 = Cisco FW - Policy based S2S VPN&amp;nbsp;-- subnet behind it 192.168.20.0/24&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have S2S tunnels as: C1 &amp;lt;---- tunnel.1---&amp;gt; P2 &amp;lt;-----tunnel.2-----&amp;gt; C3&lt;/P&gt;
&lt;P&gt;Proxy ID on P2 are:&lt;/P&gt;
&lt;P&gt;For tunnel.1 = local:&amp;nbsp;172.16.50.0/24, remote:&amp;nbsp;10.1.0.0/24&lt;/P&gt;
&lt;P&gt;For tunnel.2 = local:&amp;nbsp;172.16.50.0/24, remote: 192.168.20.0/24&lt;/P&gt;
&lt;P&gt;Routing is all static.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now 10.1.0.50 wants to reach 192.168.20.79. There cannot be a direct tunnel between C1 and C3 and hence this needs to go through P2. This is currently now working. If I add the both the remote proxy ids to both the tunnels, then atleast 1 tunnel and sometimes both go down.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I get this working? Where and how do I add Proxy IDs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Feb 2023 23:33:03 GMT</pubDate>
    <dc:creator>rjdahav163</dc:creator>
    <dc:date>2023-02-08T23:33:03Z</dc:date>
    <item>
      <title>Where to add Proxy ID with multiple tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/530391#M885</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;We have 3 firewalls:&lt;/P&gt;
&lt;P&gt;C1 = Cisco FW - Policy based S2S VPN -- subnet behind it 10.1.0.0/24&lt;/P&gt;
&lt;P&gt;P2 = Palo FW - Route based S2S VPN&amp;nbsp;-- subnet behind it 172.16.50.0/24&lt;/P&gt;
&lt;P&gt;C3 = Cisco FW - Policy based S2S VPN&amp;nbsp;-- subnet behind it 192.168.20.0/24&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have S2S tunnels as: C1 &amp;lt;---- tunnel.1---&amp;gt; P2 &amp;lt;-----tunnel.2-----&amp;gt; C3&lt;/P&gt;
&lt;P&gt;Proxy ID on P2 are:&lt;/P&gt;
&lt;P&gt;For tunnel.1 = local:&amp;nbsp;172.16.50.0/24, remote:&amp;nbsp;10.1.0.0/24&lt;/P&gt;
&lt;P&gt;For tunnel.2 = local:&amp;nbsp;172.16.50.0/24, remote: 192.168.20.0/24&lt;/P&gt;
&lt;P&gt;Routing is all static.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now 10.1.0.50 wants to reach 192.168.20.79. There cannot be a direct tunnel between C1 and C3 and hence this needs to go through P2. This is currently now working. If I add the both the remote proxy ids to both the tunnels, then atleast 1 tunnel and sometimes both go down.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I get this working? Where and how do I add Proxy IDs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 23:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/530391#M885</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2023-02-08T23:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Where to add Proxy ID with multiple tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/530427#M887</link>
      <description>&lt;P&gt;For tunnel.1 you will have to use local PID # 192.168.20.0/24 , remote 10.1.0.0/24&lt;BR /&gt;For tunnel.2 you will have to use local PID # 10.1.0.0/24 , remote 192.168.20.0/24&lt;BR /&gt;remember to allow communication on your security policy from your VPN_ZONE to VPN_ZONE&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 04:32:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/530427#M887</guid>
      <dc:creator>murali438</dc:creator>
      <dc:date>2023-02-09T04:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Where to add Proxy ID with multiple tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/616480#M4976</link>
      <description>&lt;P&gt;Hello Everyone, what happens when you have more than one subnet on both sides?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Say I have Side A with 10.6.10.0/24 and 10.6.20.0/24 and on side B I have 10.1.10.0/24 and 10.1.20.0/24.&amp;nbsp; Nothing overlaps, but please tell me what the proxy ID's would look like.&lt;/P&gt;
&lt;P&gt;I just have a single tunnel created between them.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Nov 2024 18:15:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/616480#M4976</guid>
      <dc:creator>RusselMoos</dc:creator>
      <dc:date>2024-11-10T18:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Where to add Proxy ID with multiple tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/616482#M4977</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1643922715"&gt;@RusselMoos&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assuming that you need connectivity between all you distant subnet, then your Proxy-ID will have 4 rules, as follows for side A:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CosminM_0-1731263641659.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63884iC07D486E9FDFA3F1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CosminM_0-1731263641659.png" alt="CosminM_0-1731263641659.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Nov 2024 18:35:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/616482#M4977</guid>
      <dc:creator>CosminM</dc:creator>
      <dc:date>2024-11-10T18:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Where to add Proxy ID with multiple tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/616484#M4978</link>
      <description>&lt;P&gt;Thank you Cosmin!&amp;nbsp; I will give that a try.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Nov 2024 18:42:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/where-to-add-proxy-id-with-multiple-tunnels/m-p/616484#M4978</guid>
      <dc:creator>RusselMoos</dc:creator>
      <dc:date>2024-11-10T18:42:52Z</dc:date>
    </item>
  </channel>
</rss>

