<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LSVPN not working when NAtted via Loopback in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/532057#M109701</link>
    <description>&lt;P&gt;That was a good idea to use 2 VR's. Thanks for the update.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2023 04:13:17 GMT</pubDate>
    <dc:creator>ksalustro</dc:creator>
    <dc:date>2023-02-23T04:13:17Z</dc:date>
    <item>
      <title>LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/340786#M85501</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got the following problem:&lt;/P&gt;&lt;P&gt;We have a running LSVPN with primary and secondary tunnel, which are connected on the hub on two different VRs, which sync themselves via iBGP - everything fine so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the satellite sites got two ISP lines, which should be used active/passive for redundancy.&lt;/P&gt;&lt;P&gt;Binding the IPSec tunnel on the physical interface is not possible, because when this link goes down (because provider got a problem or sth else), the down-interface won't try to establish a VPN - I need to use a loopback IP, which is natted and routed to the active ISP line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did it, and the first impression was, that this is working, BUT: After 1h, when the IPSec SA dies, the renegotiation is taking too long and the users got problems via VoIP, SAP and so on.&lt;/P&gt;&lt;P&gt;When checking the hub and GW firewall, I noticed, that the SSL connection to Portal was built up from Satellite to Hub (as expected), but the IPSec tunnel was built up from Hub to Satellite.&lt;/P&gt;&lt;P&gt;That's why I'm confused - here I'm in the position of doing the NAT myself and both providers are direct public IPs, the PAN can use, but this wouldn't work, when sitting behind a provider Internet box, which does the Natting for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anybody know, if it's even supported, to have the LSVPN satellite IPsec sitting on a loopback interface and using an active/passive Internet redundancy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm happy for any inputs here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chacko&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 08:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/340786#M85501</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2020-07-27T08:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/341189#M85611</link>
      <description>&lt;P&gt;could you please share rough sketch.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 08:17:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/341189#M85611</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2020-07-29T08:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/341200#M85614</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Chacko42_0-1596018814080.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27070i57394472CD261244/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Chacko42_0-1596018814080.png" alt="Chacko42_0-1596018814080.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;That's the setup.&lt;/P&gt;&lt;P&gt;Default Route is with metric 10 to ISP-A with Path-Monitoring, Default-Route with metric 20 is to next vr vr-secondary.&lt;/P&gt;&lt;P&gt;Loopback.1 is the source interface for lsvpn ipsec tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When configuring the ipsec tunnel directly on ethernet1/1 without nat - tunnel works.&lt;/P&gt;&lt;P&gt;When configuring the ipsec tunnel on loopback with static-nat to ISP-A, the Portal connection is initiated via Satellite, but the IPSec is initiated via Hub&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 10:35:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/341200#M85614</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2020-07-29T10:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/341223#M85621</link>
      <description>&lt;P&gt;how do you check in lsvpn if hub is intiator ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 12:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/341223#M85621</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2020-07-29T12:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/341224#M85622</link>
      <description>&lt;P&gt;when I have a look at the session table on the sateliite, I can see an outgoing session via SSL to LSVPN-Portal.&lt;/P&gt;&lt;P&gt;But the IPSec tunnel is incoming with source of the LSVPN-GW and that cannot be right.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this special case, I can do a static nat, but if this is an ISP box with dynamic ip and we are just a box behind it, incoming IPSec is not possible and not by LSVPN design.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 12:47:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/341224#M85622</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2020-07-29T12:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/343873#M86057</link>
      <description>&lt;P&gt;TAC confirmed:&lt;/P&gt;&lt;P&gt;This request is not possible with LSVPN.&lt;/P&gt;&lt;P&gt;When trying to achive ISP redundancy on satellite side, a workaround would be a parallel classical VPN tunnel with different metrics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A feature request was created for this:&lt;/P&gt;&lt;P&gt;FR ID 12468&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 07:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/343873#M86057</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2020-08-14T07:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/480182#M103984</link>
      <description>&lt;P&gt;adding to that confusion...&lt;/P&gt;&lt;P&gt;the hub is not the initiator!&lt;/P&gt;&lt;P&gt;it just looks that way because the firewall does not recognize the incoming traffic, not seeing the outgoing traffic in the logs adds to that confusion&lt;/P&gt;&lt;P&gt;anyhow, according to Palo, as everyone can write anything in these forums, it shouldn't be taken seriously if someone writes that palo said something is not supported...&lt;/P&gt;&lt;P&gt;at least we were promised that this is a supported and working feature (at least working under lab conditions), as for the working part... still working with palo TAC on it who also referred me to this thread &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 14:56:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/480182#M103984</guid>
      <dc:creator>CLIq</dc:creator>
      <dc:date>2022-04-13T14:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/531620#M109633</link>
      <description>&lt;P&gt;Hi, does anyone have any updates? I tried LSVPN using a loopback on the satellite and it doesn't work for me. Packets go into the tunnel but don't come out on the other end.&lt;/P&gt;
&lt;P&gt;Did PA ever do the feature request?&lt;/P&gt;
&lt;P&gt;-Keith&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 21:42:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/531620#M109633</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2023-02-17T21:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/531867#M109674</link>
      <description>&lt;P&gt;I talked to Palo about this and after understanding how this works, I can say that they do not plan to implement this.&lt;/P&gt;
&lt;P&gt;I worked around this by creating two LSVPNs on the same firewall, one as backup in a different virtual router but both times using the actual external interface, not a loopback.&lt;/P&gt;
&lt;P&gt;The goal of redundancy was still achieved with that for me.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 14:26:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/531867#M109674</guid>
      <dc:creator>CLIq</dc:creator>
      <dc:date>2023-02-21T14:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN not working when NAtted via Loopback</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/532057#M109701</link>
      <description>&lt;P&gt;That was a good idea to use 2 VR's. Thanks for the update.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 04:13:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-not-working-when-natted-via-loopback/m-p/532057#M109701</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2023-02-23T04:13:17Z</dc:date>
    </item>
  </channel>
</rss>

