<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN tunnel moving from Palto-ASA to Palto-Palto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-moving-from-palto-asa-to-palto-palto/m-p/14563#M10693</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Sep 2013 18:27:07 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2013-09-11T18:27:07Z</dc:date>
    <item>
      <title>VPN tunnel moving from Palto-ASA to Palto-Palto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-moving-from-palto-asa-to-palto-palto/m-p/14560#M10690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running PANOS 4.0.x and have a tunnel with a Cisco ASA peer.&amp;nbsp; I had to create multiple IPSEC tunnels to work around the Proxy ID limitation of 10 per tunnel interface.&amp;nbsp; This Cisco peer will be moving to a Palo Alto box running 5.0.x.&amp;nbsp; If the far end Palto running 5.0.x just matches my Proxy ID's, then I should be good correct?&amp;nbsp; And that 5.0.x Palto will not have to be configured with multiple tunnel interfaces, either.&amp;nbsp; I recall reading somewhere that VPN tunnels between Palto's didn't need Proxy ID's defined.&amp;nbsp; Just looking for clarification.&amp;nbsp; Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 19:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-moving-from-palto-asa-to-palto-palto/m-p/14560#M10690</guid>
      <dc:creator>iguarino</dc:creator>
      <dc:date>2013-09-10T19:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel moving from Palto-ASA to Palto-Palto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-moving-from-palto-asa-to-palto-palto/m-p/14561#M10691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Iguarino,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct. PAN firewall will take &lt;SPAN class="GINGER_SOFATWARE_correct"&gt;0.0.0.0&lt;/SPAN&gt;/0 as proxy ID by default. So, if both ends are PAN firewall then need not to define the Proxy ID's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI:-&lt;/P&gt;&lt;P&gt;1. Define a proxy ID on PAN firewall for more control over the traffic, define the traffic that needs to be Encrypted or the Interested traffic for an IPSEC tunnel.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;2. This&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; behavior is same for JUNIPER SRX firewall as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hope this helps. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 23:29:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-moving-from-palto-asa-to-palto-palto/m-p/14561#M10691</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-10T23:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel moving from Palto-ASA to Palto-Palto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-moving-from-palto-asa-to-palto-palto/m-p/14562#M10692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks HULK.&amp;nbsp; So in this case, the 4.0 side will simply add destination routes to the proper tunnel interface (although limited to 10).&amp;nbsp; The 5.0 side could add up to 250 destination routes pointing to its proper tunnel interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 13:02:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-moving-from-palto-asa-to-palto-palto/m-p/14562#M10692</guid>
      <dc:creator>iguarino</dc:creator>
      <dc:date>2013-09-11T13:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel moving from Palto-ASA to Palto-Palto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-moving-from-palto-asa-to-palto-palto/m-p/14563#M10693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 18:27:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-tunnel-moving-from-palto-asa-to-palto-palto/m-p/14563#M10693</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-11T18:27:07Z</dc:date>
    </item>
  </channel>
</rss>

