<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto Proxy IDs Bidirectional? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563569#M114121</link>
    <description>&lt;P&gt;Can you share screenshot of your NAT policy as well but I would say that destination needs to be&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;152.2.0.0/16&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Oct 2023 16:56:26 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-10-30T16:56:26Z</dc:date>
    <item>
      <title>Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/562980#M114025</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;I am a bit confused about proxy IDs when it comes to tunnel negotiation. Lets say I have a tunnel I am building with a vendor. My encryption domain will be 192.168.1.0/24 and my vendor will have 192.168.2.0/24. So lets also say the vendor has an ASA so I will add this proxy id to my phase 2 config: Source 192.168.1.0/24 Destination 192.168.2.0/24. Here is my question: Lets say I need the vendor to also be able to send traffic to me as well as receive my traffic. Is my proxy id bi-directional for the purpose of the vendor being able to initiate/negotiate the tunnel? OR do I need another proxy id as such: Source 192.168.2.0/24 Destination 192.168.1.0/24&lt;/P&gt;
&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 18:03:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/562980#M114025</guid>
      <dc:creator>JTDMHSUPPORT</dc:creator>
      <dc:date>2023-10-24T18:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/562982#M114026</link>
      <description>&lt;P&gt;ProxyID is not source/destination but local/remote instead.&lt;/P&gt;
&lt;P&gt;It means they are bi-directional.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 18:19:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/562982#M114026</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-10-24T18:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563280#M114085</link>
      <description>&lt;P&gt;Thank you. One additional question:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lets say I have the following proxyIDs built:&lt;/P&gt;
&lt;P&gt;ProxyID1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; LOCAL 192.168.2.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; REMOTE 10.1.1.0/24&lt;/P&gt;
&lt;P&gt;ProxyID2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; LOCAL 192.168.10.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;REMOTE 10.50.1.0/24&lt;/P&gt;
&lt;P&gt;Here is my question, for LOCAL 192.168.10.0 to be able to pass traffic back and forth with REMOTE 10.1.1.0, do I need a separate proxy ID such as this: LOCAL 192.168.10.0 REMOTE 10.1.1.0 ?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 17:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563280#M114085</guid>
      <dc:creator>JTDMHSUPPORT</dc:creator>
      <dc:date>2023-10-26T17:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563287#M114087</link>
      <description>&lt;P&gt;Palo don't care but other end is most likely policy based firewall that routes traffic based on those ProxyID's / encryption domains so most likely yes you need ProxyID for every pair of subnets.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 19:05:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563287#M114087</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-10-26T19:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563545#M114116</link>
      <description>&lt;P&gt;Hi again Raido, thanks for all of your help. I ran across something else I am questioning in my PA440 config. When there is a NAT rule created for an ipsec tunnel for example: Source address 192.168.1.0/24 Destination address 152.2.0.0/16 Source translation 10.77.120.212 and bidirectional is yes. I only need a static route for the PRE-NAT ip address correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 15:06:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563545#M114116</guid>
      <dc:creator>JTDMHSUPPORT</dc:creator>
      <dc:date>2023-10-30T15:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563548#M114117</link>
      <description>&lt;P&gt;Palo virtual router will route based on POST-NAT destination IP.&lt;/P&gt;
&lt;P&gt;In your example you don't seem to change destination IP but source IP so destination PRE-NAT and POST-NAT IPs are the same (unless I misunderstand your requirement to also NAT destination IP).&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 15:43:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563548#M114117</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-10-30T15:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563553#M114118</link>
      <description>&lt;P&gt;I am creating a source nat rule and setting it to bi-directional so the destination nat rule is auto created by the firewall. This means when I view nat rules from command line i see this:&lt;/P&gt;
&lt;P&gt;"Example1; index: 86" {&lt;BR /&gt;nat-type ipv4;&lt;BR /&gt;from inside;&lt;BR /&gt;source 192.168.1.0;&lt;BR /&gt;to l2lvpn;&lt;BR /&gt;to-interface ;&lt;BR /&gt;destination 152.2.0.0/16;&lt;BR /&gt;service 0:any/any/any;&lt;BR /&gt;translate-to "src: 10.77.120.212 (static-ip) (pool idx: 24)";&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;"Example1; index: 87" {&lt;BR /&gt;nat-type ipv4;&lt;BR /&gt;from any;&lt;BR /&gt;source any;&lt;BR /&gt;to l2lvpn;&lt;BR /&gt;to-interface ;&lt;BR /&gt;destination 10.77.120.212;&lt;BR /&gt;service 0:any/any/any;&lt;BR /&gt;translate-to "dst: 192.168.1.0";&lt;BR /&gt;terminal no;&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;My question is, when I create my static routes for the tunnel, do I need a static route for 152.2.0.0 or for my source nat address 10.77.120.212&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 15:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563553#M114118</guid>
      <dc:creator>JTDMHSUPPORT</dc:creator>
      <dc:date>2023-10-30T15:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563556#M114119</link>
      <description>&lt;P&gt;I usually prefer not to use bi-directional NAT rules and create 2 rules myself for better control due how bi-directional option messes up zones.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your example shows that one way source zone is "inside" and destination zone is "&lt;SPAN&gt;l2lvpn"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Other way source zone is "any" and destination zone is "l2lvpn"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But if you don't have&amp;nbsp;10.77.120.212 in your routing table then destination zone should be "outside" instead for nat policy to match for traffic initiated from peer side.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 16:28:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563556#M114119</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-10-30T16:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563564#M114120</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JTDMHSUPPORT_0-1698684783012.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54749i23716050F93671F2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JTDMHSUPPORT_0-1698684783012.png" alt="JTDMHSUPPORT_0-1698684783012.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JTDMHSUPPORT_1-1698684818985.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54750i3D2D4102D3C6FBE8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JTDMHSUPPORT_1-1698684818985.png" alt="JTDMHSUPPORT_1-1698684818985.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which one of these would be correct given my nat rule example? Sorry, I do not do enough networking to be well versed with it =(&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 16:54:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563564#M114120</guid>
      <dc:creator>JTDMHSUPPORT</dc:creator>
      <dc:date>2023-10-30T16:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563569#M114121</link>
      <description>&lt;P&gt;Can you share screenshot of your NAT policy as well but I would say that destination needs to be&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;152.2.0.0/16&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 16:56:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563569#M114121</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-10-30T16:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563575#M114122</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JTDMHSUPPORT_2-1698686226287.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54751iC558FBF0589312F2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="JTDMHSUPPORT_2-1698686226287.png" alt="JTDMHSUPPORT_2-1698686226287.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 17:17:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563575#M114122</guid>
      <dc:creator>JTDMHSUPPORT</dc:creator>
      <dc:date>2023-10-30T17:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563586#M114123</link>
      <description>&lt;P&gt;Do you need to use 10.77.120.212 only or can you use /24 subnet like example below?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1698690022761.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54754i044E38FD9CDF316F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1698690022761.png" alt="Raido_Rattameister_0-1698690022761.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 18:20:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563586#M114123</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-10-30T18:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Proxy IDs Bidirectional?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563587#M114124</link>
      <description>&lt;P&gt;I can use subnet like your example.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 18:22:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-proxy-ids-bidirectional/m-p/563587#M114124</guid>
      <dc:creator>JTDMHSUPPORT</dc:creator>
      <dc:date>2023-10-30T18:22:34Z</dc:date>
    </item>
  </channel>
</rss>

