<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Build IPsec connection without using Public IP at Branch Site in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564572#M114239</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Does&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Branch Site have static IP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-Yes, branch office have static IP but with internal IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have capability to configure port forwarding on ISP router?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-I have done configure port forward in my ISP router. (udp500,4500,4510,4511)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm new to PaloAlto, so I not sure the details setting in PaloAlto. I had see some discussion about the setting needed in IPsec when one of the site using an internal IP as wan IP. After trying the step mentioned, but failed. So may share to me the detail setting at both site? we need enable&amp;nbsp;NAT-Traversal at both site? we need usingaggresive mode at both site? what need to configure in local &amp;amp; peer identification at both site?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Nov 2023 00:44:55 GMT</pubDate>
    <dc:creator>zlling</dc:creator>
    <dc:date>2023-11-07T00:44:55Z</dc:date>
    <item>
      <title>How to Build IPsec connection without using Public IP at Branch Site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564510#M114228</link>
      <description>&lt;P&gt;I want build IPsec connection bwtween HQ and Branch Office.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HQ using Public IP with fixed.&lt;/P&gt;
&lt;P&gt;Branch Office using Internal IP with fixed. (have one ISP router above firewall)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May know the details setting?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and i need create port forward udp500,4500 on my ISP router?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 13:46:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564510#M114228</guid>
      <dc:creator>zlling</dc:creator>
      <dc:date>2023-11-06T13:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to Build IPsec connection without using Public IP at Branch Site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564524#M114231</link>
      <description>&lt;P&gt;Does&amp;nbsp;&lt;SPAN&gt;Branch Site have static IP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have capability to configure port forwarding on ISP router?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 15:18:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564524#M114231</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-06T15:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to Build IPsec connection without using Public IP at Branch Site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564572#M114239</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Does&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Branch Site have static IP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-Yes, branch office have static IP but with internal IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have capability to configure port forwarding on ISP router?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;-I have done configure port forward in my ISP router. (udp500,4500,4510,4511)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm new to PaloAlto, so I not sure the details setting in PaloAlto. I had see some discussion about the setting needed in IPsec when one of the site using an internal IP as wan IP. After trying the step mentioned, but failed. So may share to me the detail setting at both site? we need enable&amp;nbsp;NAT-Traversal at both site? we need usingaggresive mode at both site? what need to configure in local &amp;amp; peer identification at both site?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 00:44:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564572#M114239</guid>
      <dc:creator>zlling</dc:creator>
      <dc:date>2023-11-07T00:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to Build IPsec connection without using Public IP at Branch Site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564574#M114240</link>
      <description>&lt;P&gt;You need to NAT only udp/500 and udp/4500.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On "Advanced Options" tab check "Enable NAT Traversal" checkbox and you are done.&lt;/P&gt;
&lt;P&gt;You do not need aggressive mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1699321537581.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54999i76D55658F33B077F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1699321537581.png" alt="Raido_Rattameister_0-1699321537581.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 01:48:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564574#M114240</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-07T01:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to Build IPsec connection without using Public IP at Branch Site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564576#M114241</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had try this way. IPsec connection still failed to build.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does IPsec function need license?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 03:13:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564576#M114241</guid>
      <dc:creator>zlling</dc:creator>
      <dc:date>2023-11-07T03:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to Build IPsec connection without using Public IP at Branch Site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564577#M114242</link>
      <description>&lt;P&gt;No license needed.&lt;/P&gt;
&lt;P&gt;How do you identify that tunnel fails to build?&lt;/P&gt;
&lt;P&gt;Do you see anything in system log?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you enter command below and check System logs on other side what do you see?&lt;/P&gt;
&lt;P&gt;test vpn ipsec-sa tunnel name-of-the-ipsec-tunnel&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 03:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-build-ipsec-connection-without-using-public-ip-at-branch/m-p/564577#M114242</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-07T03:23:09Z</dc:date>
    </item>
  </channel>
</rss>

