<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Route to IPSec Tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/route-to-ipsec-tunnel/m-p/549555#M112125</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I need to add a route pointing to a Tunnel interface. As the peer has dynamic IP have created the IPsec tunnel with Dynamic IP Peer Identification as its Hostname.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To Add route in the VR as we do not have IP address if i just point it to the tunnel interface and select IP address as none would be enough?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is there any other way to configure it?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jul 2023 10:57:34 GMT</pubDate>
    <dc:creator>Sanjay_Ramaiah</dc:creator>
    <dc:date>2023-07-17T10:57:34Z</dc:date>
    <item>
      <title>Route to IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-to-ipsec-tunnel/m-p/549555#M112125</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I need to add a route pointing to a Tunnel interface. As the peer has dynamic IP have created the IPsec tunnel with Dynamic IP Peer Identification as its Hostname.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To Add route in the VR as we do not have IP address if i just point it to the tunnel interface and select IP address as none would be enough?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is there any other way to configure it?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 10:57:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-to-ipsec-tunnel/m-p/549555#M112125</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-07-17T10:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Route to IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-to-ipsec-tunnel/m-p/549593#M112128</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;To add a static route you would specify the tunnel next-hop along with the destination prefix. For the purpose of routing via the tunnel you do not worry about the remote end having a dynamic address, it is the encapsulated address that you are interested in and this will be static.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IP address, next-vr and FQDN are valid values for the mandatory next-hop field. Specifying the outbound interface is optional. It is worth noting that creating a static route without a next-hop address comes with the addtional baggage of increasing the ARP table. At least that is the case on other routing platforms, thankfully Palo Alto doesn't let you! I wrote a blog post about it if you are interested:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://cs7networks.co.uk/2022/01/10/static-route-next-hop/" target="_blank"&gt;Static route next-hop – CS7 Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 15:24:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-to-ipsec-tunnel/m-p/549593#M112128</guid>
      <dc:creator>seb_rupik</dc:creator>
      <dc:date>2023-07-17T15:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Route to IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-to-ipsec-tunnel/m-p/549633#M112129</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;When entering the static route, Enter the following:&lt;/P&gt;
&lt;P&gt;Name: &amp;lt;whatever name you choose&amp;gt;&lt;/P&gt;
&lt;P&gt;Destination: &amp;lt;Your ip/subnet in CIDR&amp;gt;&lt;/P&gt;
&lt;P&gt;Interface: &amp;lt;Your tunnel interface&amp;gt;&lt;/P&gt;
&lt;P&gt;Next Hope: NONE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully there is a corresponding route on the other side to get traffic back.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 21:41:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-to-ipsec-tunnel/m-p/549633#M112129</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-07-17T21:41:46Z</dc:date>
    </item>
  </channel>
</rss>

