<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec Tunnel with Loopback and NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-with-loopback-and-nat/m-p/514317#M106780</link>
    <description>&lt;P&gt;Nice work!&lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2022 19:44:05 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2022-09-08T19:44:05Z</dc:date>
    <item>
      <title>IPsec Tunnel with Loopback and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-with-loopback-and-nat/m-p/513970#M106717</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have 2 questions.&lt;/P&gt;
&lt;P&gt;1. I want to create an IPSec tunnel, using a loopback interface.&lt;/P&gt;
&lt;P&gt;This removes a dependency on the main interface ip. ie if the loopback ip is :3.4.5.2, and the main internet ip is changed from 3.4.5.1 to 3.4.5.30, this then doesn't impact the IPSec tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the IPSec tunnel is online.&lt;/P&gt;
&lt;P&gt;2. I want to NAT the communication from different ip's across several internal subnets to a specific 10.x.x.x/24 subnet as the new "source". This subnet is then used to communicate to Site B's internal subnets. This masks Site A internal subnets and removes additional configuration requirements from Site B, when additional Site A subnets are enabled.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CherieWatts_3-1662410895804.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43676i2F6CAFA0845D14F8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CherieWatts_3-1662410895804.png" alt="CherieWatts_3-1662410895804.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Can anyone direct me to the pertinent doco to look up how to do my NAT, ie question 2?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Doesn't anyone see any major issues with this design?&lt;/P&gt;
&lt;P&gt;Thanks for any feedback&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2022 20:55:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-with-loopback-and-nat/m-p/513970#M106717</guid>
      <dc:creator>CherieWatts</dc:creator>
      <dc:date>2022-09-05T20:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Tunnel with Loopback and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-with-loopback-and-nat/m-p/514092#M106731</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;So since the traffic is sourced from site A and you are putting the NAT into site A's firewall. You can use a Source NAT, if you are putting the NAT rules in firewall B, then use a Destination NAT.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/source-nat-and-destination-nat/source-nat" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/source-nat-and-destination-nat/source-nat&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 18:55:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-with-loopback-and-nat/m-p/514092#M106731</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-06T18:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Tunnel with Loopback and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-with-loopback-and-nat/m-p/514194#M106760</link>
      <description>&lt;P&gt;Hi OtakarKlier,&lt;/P&gt;
&lt;P&gt;I implemented the site-to-site vpn yesterday and its all working correctly.&lt;/P&gt;
&lt;P&gt;I am really happy.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Cherie&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 21:27:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-with-loopback-and-nat/m-p/514194#M106760</guid>
      <dc:creator>CherieWatts</dc:creator>
      <dc:date>2022-09-07T21:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Tunnel with Loopback and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-with-loopback-and-nat/m-p/514317#M106780</link>
      <description>&lt;P&gt;Nice work!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 19:44:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-with-loopback-and-nat/m-p/514317#M106780</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-08T19:44:05Z</dc:date>
    </item>
  </channel>
</rss>

