<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Traffic to Internet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/556955#M113043</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We have a requirement. Our PA Firewall has internet connectivity and VPN set to one of the peer end Forcepoint device.&lt;/P&gt;
&lt;P&gt;VPN is up and running. Traffic from Forcepoint LAN to MPLS connected to PA is all working over the VPN.&lt;/P&gt;
&lt;P&gt;Now the requirement is ANY traffic from Forcepoint site will reach PA firewall for both its internet and MPLS access.&lt;/P&gt;
&lt;P&gt;May i know what needs to be done on PA to allow the access. Default route is pointing to the internet facing interface. ACLs from Site subnet to Internet is allowed. But in the Proxy ID config i have allowed only Site Subnet to MPLS subnet access. Is there anything else needs to be added in the Proxy ID please suggest or anything else i am missing here?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2023 09:28:13 GMT</pubDate>
    <dc:creator>Sanjay_Ramaiah</dc:creator>
    <dc:date>2023-09-07T09:28:13Z</dc:date>
    <item>
      <title>VPN Traffic to Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/556955#M113043</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We have a requirement. Our PA Firewall has internet connectivity and VPN set to one of the peer end Forcepoint device.&lt;/P&gt;
&lt;P&gt;VPN is up and running. Traffic from Forcepoint LAN to MPLS connected to PA is all working over the VPN.&lt;/P&gt;
&lt;P&gt;Now the requirement is ANY traffic from Forcepoint site will reach PA firewall for both its internet and MPLS access.&lt;/P&gt;
&lt;P&gt;May i know what needs to be done on PA to allow the access. Default route is pointing to the internet facing interface. ACLs from Site subnet to Internet is allowed. But in the Proxy ID config i have allowed only Site Subnet to MPLS subnet access. Is there anything else needs to be added in the Proxy ID please suggest or anything else i am missing here?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 09:28:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/556955#M113043</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2023-09-07T09:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Traffic to Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/557172#M113068</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking at the details given, you need to make sure,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Modify the proxy IDs and Add ForcePoint LAN subnet to ANY (0.0.0.0) entry. This will match internet as well as LAN/MPLS traffic networks. But make sure you have similar VPN encryption domain on other site firewall also.&lt;/LI&gt;
&lt;LI&gt;You need to check if there is required NAT policy configured on PA to NAT ForcePoint LAN network when going towards Internet.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;With this, traffic will hit PA via IPSEC. Once traffic is decrypted on the PA, it should match the internet policy, NAT and do the routing. Response traffic from internet will come back to PA and again pointed to source network routing i.e. on tunnel interface. Here, latency to the internet is expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, I would recommend you to make changes under maintenance window as there are chances of some outage during the changes and you should be in the position to get some time to t’shoot it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it isn’t working post changes, you can check below checks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;What is the status of tunnel ? Is Phase-1 &amp;amp; Phase-2 is up or down?&lt;/LI&gt;
&lt;LI&gt;In case of any of the phase-2 down, look for system logs filtered with VPN. This will give you some details on reason behind VPN SA down. In such cases, there are chances of having Phase-2 down if there is mismatch in the Proxy ID configuration. It should be identical on both sides.&lt;/LI&gt;
&lt;LI&gt;If tunnel is up ( both phases ), then check further whether traffic matching right policies for MPLS and Internet, etc.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps! Please let me know if you still need any additional help on it, I would be happy to help.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 12:33:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/557172#M113068</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2023-09-08T12:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Traffic to Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558013#M113188</link>
      <description>&lt;P&gt;hi, running into similar problem with&amp;nbsp; watchguard firebox being at remote, PA 7050 at DC end. Tunnel terminates in distinct zone on PA; traffic from remote to on prem works fine but cannot get traffic from remote to Internet which transits tunnel to work. Attempted to update NAT rule to permit tunnel zone without success. Missing something obvious. Topology&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;watchguard f/b----------public internet--------pa7050-----on premise nets&lt;/P&gt;
&lt;P&gt;net 10.255.0.0/23&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;tun zone&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; internal zone&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; internet zone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 20:28:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558013#M113188</guid>
      <dc:creator>frocchio1</dc:creator>
      <dc:date>2023-09-14T20:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Traffic to Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558128#M113201</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72950"&gt;@frocchio1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;When you look at the logs on your PA-7050, do you see the watchguard sending internet destined traffic through the tunnel at all? First thing I'd do here is validate that you're getting that traffic across the tunnel properly, because once that's done it's just a matter of ensuring NAT, security, and routing is all setup properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 13:23:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558128#M113201</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-09-15T13:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Traffic to Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558181#M113213</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;On the IKE Gateway config -&amp;gt;Advanced tab, do you have NAT Traversal enabled?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="Concept" summary=""&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="Table_Cell"&gt;
&lt;DIV class="Table_Cell"&gt;&lt;A name="ID0EIOQU" target="_blank"&gt;&lt;/A&gt;Enable NAT Traversal&lt;/DIV&gt;
&lt;/TD&gt;
&lt;TD class="Table_Cell"&gt;
&lt;DIV class="Table_Cell"&gt;&lt;A name="ID0ESOQU" target="_blank"&gt;&lt;/A&gt;Click to have UDP encapsulation used on IKE and UDP protocols, enabling them to pass through intermediate NAT devices.&lt;/DIV&gt;
&lt;DIV class="Table_Cell"&gt;&lt;A name="ID0EWOQU" target="_blank"&gt;&lt;/A&gt;Enable NAT Traversal if Network Address Translation (NAT) is configured on a device between the IPSec VPN terminating points&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also maker sure you have the proper security policies to allow the traffic to flow from the VPN Zone to the 'Untrust" internet Zone. Along with the proper NAT policy. Sometimes the NAT policy is not in high enough, the firewall reads it top-down, left to right, just like the security policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 20:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558181#M113213</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-09-15T20:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Traffic to Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558185#M113216</link>
      <description>&lt;P&gt;I hear you but that specific tunnel never comes up so the answer would be no, I don't see any traffic&amp;nbsp; destined to public coming thru tunnel. There are three other SA's using the same tunnel and all three come up without an issue. This fourth one is using default and not coming up. Are defaults 0.0.0.0/0 a no-mo with proxy ID's? Here is my proxy-id config that matches on both ends of this delightful set up.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-09-15 at 4.14.04 PM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53775i878CB16226C3275E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-09-15 at 4.14.04 PM.png" alt="Screenshot 2023-09-15 at 4.14.04 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 20:16:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558185#M113216</guid>
      <dc:creator>frocchio1</dc:creator>
      <dc:date>2023-09-15T20:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Traffic to Internet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558201#M113219</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would not use 0.0.0.0/0 since that would not bring the tunnel up. The Proxy-ID's are like the 'interesting traffic' in the Cisco world. Only the subnets that are on the Far side LAN should be in the proxy ID's, if applicable, and they should match on both sides otherwise the tunnel will not come up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you know if the Watchguard is a route based or zone based VPN?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clh5CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clh5CAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 21:06:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-traffic-to-internet/m-p/558201#M113219</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-09-15T21:06:07Z</dc:date>
    </item>
  </channel>
</rss>

