<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ikev2 site to site VPN to sites with multiple public ip addresses(used for failover) in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576301#M2129</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is a watchguard a route based or zone based firewall? Palo Alto is route based.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 06 Feb 2024 18:05:31 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2024-02-06T18:05:31Z</dc:date>
    <item>
      <title>ikev2 site to site VPN to sites with multiple public ip addresses(used for failover)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576113#M2119</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider fx byc ceg cer ces cet ceu cev cew cex cey cez cfa cfb cfc cfd cfe cff cfg cfh cfi cfj cfk cfl cfm cfn cfo cfp cfq cfr cfs cft cfu cfv cfw"&gt;for a client, i created these many tunnel interfaces for each of their sites. Now, for all these sites, they have 2-3 public ip addresses(for failover purposes). So, will i have to create new tunnel interfaces or should I just create new Ike gateways and ipsec tunnels and point them to the tunnels which I created earlier(shown on the screenshot below)? Please help&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="msdphi_0-1707168908909.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/57359iBF77108C05E4BEE3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="msdphi_0-1707168908909.png" alt="msdphi_0-1707168908909.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 21:35:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576113#M2119</guid>
      <dc:creator>msdphi</dc:creator>
      <dc:date>2024-02-05T21:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: ikev2 site to site VPN to sites with multiple public ip addresses(used for failover)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576116#M2120</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I think your answer would depend on how you plan to use the tunnel interfaces. You can assign multiple IP's to a singe interface. However for me, I use the interfaces for OSPF routing and to see if the tunnel is up, via 3rd party monitoring since the tunnels connect via different providers.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 22:46:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576116#M2120</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-02-05T22:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: ikev2 site to site VPN to sites with multiple public ip addresses(used for failover)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576299#M2128</link>
      <description>&lt;P&gt;I want to know how to configure policy based site to site VPN from our Palo Alto to a site which has a watchguard firewall and has 3 public ip addresses(used for failover).&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 17:51:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576299#M2128</guid>
      <dc:creator>msdphi</dc:creator>
      <dc:date>2024-02-06T17:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: ikev2 site to site VPN to sites with multiple public ip addresses(used for failover)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576301#M2129</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is a watchguard a route based or zone based firewall? Palo Alto is route based.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 18:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576301#M2129</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-02-06T18:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: ikev2 site to site VPN to sites with multiple public ip addresses(used for failover)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576306#M2130</link>
      <description>&lt;P&gt;I am not sure about that. That is on the client's side.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 18:28:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576306#M2130</guid>
      <dc:creator>msdphi</dc:creator>
      <dc:date>2024-02-06T18:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: ikev2 site to site VPN to sites with multiple public ip addresses(used for failover)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576307#M2131</link>
      <description>&lt;P&gt;I am just configuring on panorama. I have already configured VPN to their primary public IP. I am not sure if I can point the same tunnel to the newly created ike gateways and ipsec tunnels for their branch sites.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 18:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576307#M2131</guid>
      <dc:creator>msdphi</dc:creator>
      <dc:date>2024-02-06T18:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: ikev2 site to site VPN to sites with multiple public ip addresses(used for failover)</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576309#M2132</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You should be able to, however make sure your routing is set so that its not going to use multiple tunnels unless you are using ECMP.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 18:37:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/ikev2-site-to-site-vpn-to-sites-with-multiple-public-ip/m-p/576309#M2132</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-02-06T18:37:29Z</dc:date>
    </item>
  </channel>
</rss>

