<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo alto Active/passive HA on azure with IPsec VPN tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/556096#M112918</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145300"&gt;@louey11&lt;/a&gt;&amp;nbsp;Did you find the solution as it is a very old thread. If yes, can you please share any suggestions or documentations for using this setup of having external load balancer in front of PA VMs which are in Active/Passive mode. I am still looking for a solution on this. Any help would be appreciated &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Sep 2023 08:00:59 GMT</pubDate>
    <dc:creator>BilalMohd</dc:creator>
    <dc:date>2023-09-01T08:00:59Z</dc:date>
    <item>
      <title>Palo alto Active/passive HA on azure with IPsec VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/333000#M84145</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am deploying an Active/Passive Palo Alto HA VM's on Azure with an external and internal loadbalancer topology (picture below), I know that the NAT is done by the public Loadbalancer so no need for public IP address on the VM's interfaces so need for public IP on interfaces for this purpose, but i need to set a VPN IPsec connections between my PA-VM's and other sites, so how would I configure the VPN IPsec tunnels, should I put the Public IP of the loadBalancer on the peer IP or the private IP of the VM's or should I literally configure my PA-VM's with Public IP on external interfaces.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am really blocked with this point, if anyone could help i will be really grateful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Question forum palo ip public optimized.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26180i762C01D99690471A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Question forum palo ip public optimized.PNG" alt="Question forum palo ip public optimized.PNG" /&gt;&lt;/span&gt;Thank you in advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Louey&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 16:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/333000#M84145</guid>
      <dc:creator>louey11</dc:creator>
      <dc:date>2020-06-11T16:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Active/passive HA on azure with IPsec VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/335534#M84556</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145300"&gt;@louey11&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use the private ip address on the firewall itself but make sure you use local identifier and remote identifier option on both sides of the tunnel to make this work. (imagine if your side ip is dynamic ip then how do you configure, the same way)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHVCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHVCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;Suresh&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 14:11:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/335534#M84556</guid>
      <dc:creator>skumar1</dc:creator>
      <dc:date>2020-06-26T14:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Active/passive HA on azure with IPsec VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/335572#M84564</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145300"&gt;@louey11&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you don't want to use a dynamic configuration, which is by far the easiest, I would recommend that you setup a public IP directly on the PAs and&amp;nbsp;&lt;STRONG&gt;not&amp;nbsp;&lt;/STRONG&gt;go through the load balancer. While it will work, it'll take a bit of tweaking to ensure that the load balancer isn't causing any issues since it'll be considered a long running session.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 18:28:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/335572#M84564</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-26T18:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Active/passive HA on azure with IPsec VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/365112#M88536</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you manage to get this problem resolved? I am going through a similar project at the moment and would appreciate any feedback that you may have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 09:39:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/365112#M88536</guid>
      <dc:creator>Thanjalo_Thankappan</dc:creator>
      <dc:date>2020-11-24T09:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto Active/passive HA on azure with IPsec VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/556096#M112918</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145300"&gt;@louey11&lt;/a&gt;&amp;nbsp;Did you find the solution as it is a very old thread. If yes, can you please share any suggestions or documentations for using this setup of having external load balancer in front of PA VMs which are in Active/Passive mode. I am still looking for a solution on this. Any help would be appreciated &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 08:00:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-active-passive-ha-on-azure-with-ipsec-vpn-tunnel/m-p/556096#M112918</guid>
      <dc:creator>BilalMohd</dc:creator>
      <dc:date>2023-09-01T08:00:59Z</dc:date>
    </item>
  </channel>
</rss>

