<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536320#M110186</link>
    <description>&lt;P&gt;/29 will be for BGP peering.&lt;/P&gt;
&lt;P&gt;/24 will be advertised to ISP and ISP will advertise it further.&lt;/P&gt;
&lt;P&gt;You can get default route from ISP through BGP or have static route to ISP next hop in /29 range.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Important is to ask ISP to filter only default route to you and not send whole internet routing table down to your Palo.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Mar 2023 12:58:25 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-03-24T12:58:25Z</dc:date>
    <item>
      <title>Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/535617#M110167</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;I am using a pair of PA-3250 in HA and have 17 S2S VPNs using my outside interface that has /24 public IP assigned to it. Due to ongoing issues with our current internet, we have decided to move to a different internet platform (DIA) and enhance our redundancy (enable BGP).&lt;BR /&gt;However, with this new setup, the ISP must give us a new /29 block to exchange BGP. As a result, the current /24 subnet and the IP we use for VPN peering will sit behind this new IP block on the same PA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Someone mentioned to me the 17 S2S tunnels will not work and IPSec tunnels must be terminated on the interface closet to the remote peer.&lt;SPAN&gt;&amp;nbsp;VPN traffic cannot enter the firewall on one interface, cross the backplane and then be delivered to a second interface.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="inherit"&gt;Any feedback and possible work around will be appreciated.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="inherit"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 22:01:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/535617#M110167</guid>
      <dc:creator>highmiles</dc:creator>
      <dc:date>2023-03-23T22:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536315#M110184</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/279278"&gt;@highmiles&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Am I understand you correctly - you plan to connect second ISP to your firewall using new public range, but you want to keep your IPsec tunnels using the existing/old public range for local peer address?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my humble opinion Palo FW is your least concern in such setup...&lt;/P&gt;
&lt;P&gt;- How do you plan to route old-ISP public /24 to point to your new-ISP public /29?&lt;/P&gt;
&lt;P&gt;- How do you plan to route the return traffic from old-ISP interface back over new-ISP interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why do you even want to do this way?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you plan to completely migrate from old-ISP to new-ISP, just change your IPsec tunnels to use new-ISP interface as local peer.&lt;/P&gt;
&lt;P&gt;If you plan to have ISP redundancy and want to failover IPsec tunnel over each ISP depending on the path, you will need to create additional tunnels over the new-ISP to all 17 remote sites&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 12:45:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536315#M110184</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-03-24T12:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536319#M110185</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;Someone mentioned to me the 17 S2S tunnels will not work and IPSec tunnels must be terminated on the interface closet to the remote peer."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This someone was incorrect.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can run IPSec tunnels anywhere.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Even on loopback interfaces.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 12:54:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536319#M110185</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-24T12:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536320#M110186</link>
      <description>&lt;P&gt;/29 will be for BGP peering.&lt;/P&gt;
&lt;P&gt;/24 will be advertised to ISP and ISP will advertise it further.&lt;/P&gt;
&lt;P&gt;You can get default route from ISP through BGP or have static route to ISP next hop in /29 range.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Important is to ask ISP to filter only default route to you and not send whole internet routing table down to your Palo.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 12:58:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536320#M110186</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-24T12:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536347#M110189</link>
      <description>&lt;P&gt;Both old IP block and new address block will be on the same PA, the new block will have a new Zone name.&lt;/P&gt;
&lt;P&gt;My question was specifically regarding my VPNs peer address that i am currently using, will it work if i move it one hop (on the same PA) behind the new IP block?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:05:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536347#M110189</guid>
      <dc:creator>highmiles</dc:creator>
      <dc:date>2023-03-24T17:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536351#M110190</link>
      <description>&lt;P&gt;Yes it will work.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:07:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536351#M110190</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-24T17:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536354#M110191</link>
      <description>&lt;P&gt;I like this answer! The IPSec will still work even if I used Loopbacks interfaces, interesting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, this guy we hired (from a well-known Paloalto partner) tells me otherwise, and he has 15+ years of experience.&lt;/P&gt;
&lt;P&gt;He suggested i purchase VPN concentrators! (Something i don't want to do).&lt;/P&gt;
&lt;P&gt;I am really puzzeled &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:11:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536354#M110191</guid>
      <dc:creator>highmiles</dc:creator>
      <dc:date>2023-03-24T17:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536355#M110192</link>
      <description>&lt;P&gt;You should find better partner to work with.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:17:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536355#M110192</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-24T17:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536357#M110193</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Radio_Rattameister&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I am not worried about the architecture of this as much as I am worried about the VPNs.&lt;/P&gt;
&lt;P&gt;So the new /29 block will be used between me and the ISP, my current /24 block willl still be on the same PA but one hop behind.&lt;/P&gt;
&lt;P&gt;All of this is being done to enable fail-over the /24 block to my other data center in case of a DR.&lt;/P&gt;
&lt;P&gt;Maybe there is trick or certain feature we have to enable for the IPSec to work if we introduce a new block Infront or the current public IP we use for VPN peering.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;He said the same thing about my Global Protect for remote access (which runs on a separate PA), they will also be impacted.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a guide or link on how to setup S2S (L2L) VPN IPsec on an interface that is not facing the public?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:19:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536357#M110193</guid>
      <dc:creator>highmiles</dc:creator>
      <dc:date>2023-03-24T17:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536361#M110195</link>
      <description>&lt;P&gt;You just go to IKE gateways and change local interface.&lt;/P&gt;
&lt;P&gt;Same with GlobalProtect.&lt;/P&gt;
&lt;P&gt;You need to change interface on Portal and Gateway config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example below of working tunnels on non-public facing interface.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1679678828128.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49008i2F162746D9B4EEDD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1679678828128.png" alt="Raido_Rattameister_0-1679678828128.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:27:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536361#M110195</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-24T17:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536366#M110196</link>
      <description>&lt;P&gt;Why would i change my IKE gateway's local interface? That is what i am trying to prevent in the first place.&lt;/P&gt;
&lt;P&gt;I need to keep using the current VPN peer IP. (currently set to 204.x.x.10/24 and directly facing internet)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will Introduce a new /30 block (or /29) between me and ISP and start distributing/propagating my /24 to ISP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My /24 will now be behind this new /29 and peering to my 204.x.x.10/24 will be one hop away from internet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:40:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536366#M110196</guid>
      <dc:creator>highmiles</dc:creator>
      <dc:date>2023-03-24T17:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536368#M110197</link>
      <description>&lt;P&gt;Assuming you currently have&amp;nbsp;&lt;SPAN&gt;204.x.x.10/24 configured on ethernet1/1 and you move it to ethernet1/2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You need to change local interface droppdown from ethernet1/1 to ethernet1/2 because IP address&amp;nbsp;204.x.x.10/24 will move between interfaces.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1679679877886.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49009iEDF3AF5E648B6A3A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1679679877886.png" alt="Raido_Rattameister_0-1679679877886.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:44:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536368#M110197</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-03-24T17:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can you setup a S2S VPN behind your Outside (untrusted) interface on same firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536369#M110198</link>
      <description>&lt;P&gt;ok, i see, got it, this is assuming i am moving my /24 block. But i am not moving it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; .&lt;/P&gt;
&lt;P&gt;I will simply create new Zone and assign to new interfaces for the new /30.&lt;/P&gt;
&lt;P&gt;I appreciate your input, let me go back to the consultant and challenge his theory, not sure if i will succeed, he is the expert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 17:51:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-you-setup-a-s2s-vpn-behind-your-outside-untrusted-interface/m-p/536369#M110198</guid>
      <dc:creator>highmiles</dc:creator>
      <dc:date>2023-03-24T17:51:02Z</dc:date>
    </item>
  </channel>
</rss>

