<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route-Based VPN between PaloAlto &amp;amp; Strongswan in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/route-based-vpn-between-paloalto-amp-strongswan/m-p/574085#M115400</link>
    <description>&lt;P&gt;You need to follow several steps on both devices for setting up VPN. Here's a breakdown of the process:&lt;/P&gt;
&lt;P&gt;On the Palo Alto firewall:&lt;/P&gt;
&lt;P&gt;1. Create a VPN Tunnel:&lt;/P&gt;
&lt;P&gt;Go to Network &amp;gt; VPN &amp;gt; Tunnels.&lt;BR /&gt;Click Add and configure your VPN tunnel settings:&lt;BR /&gt;Type: IPSec&lt;BR /&gt;Name: Choose a descriptive name for your tunnel.&lt;BR /&gt;Local Interface: Select the interface connected to your internal network.&lt;BR /&gt;Peer Address: Enter the IP address of your VPN gateway/virtual machine running StrongSwan.&lt;BR /&gt;Preshared Key: Define a shared secret for authentication.&lt;/P&gt;
&lt;P&gt;2. Configure Phase 1 and Phase 2:&lt;/P&gt;
&lt;P&gt;Go to Phase 1 and Phase 2 tabs within the tunnel configuration.&lt;BR /&gt;- Define the encryption algorithms, authentication methods, and other relevant security settings for both phases as per your desired security level.&lt;BR /&gt;- Ensure compatibility with the StrongSwan configuration on your VM.&lt;/P&gt;
&lt;P&gt;3. Create Route Policy:&lt;/P&gt;
&lt;P&gt;Go to Network &amp;gt; Route &amp;gt; Policies.&lt;BR /&gt;Click Add and create a route policy for your VPN tunnel:&lt;BR /&gt;Name: Assign a relevant name.&lt;BR /&gt;Source Zone: Select the internal zone(s) where traffic originates for the VPN route.&lt;BR /&gt;Destination Zone: Choose the "VPN" zone associated with your tunnel.&lt;/P&gt;
&lt;P&gt;4. Create Route Tag:&lt;/P&gt;
&lt;P&gt;Go to Network &amp;gt; Tags &amp;gt; Route Tags.&lt;BR /&gt;* Click Add and create a route tag for your specific traffic:&lt;BR /&gt;Name: Choose a descriptive name like.&lt;BR /&gt;Match Criteria: Define criteria to identify the desired traffic.&lt;/P&gt;
&lt;P&gt;5. Apply Route Policy and Tag:&lt;/P&gt;
&lt;P&gt;- Go back to the Route Policy you created.&lt;BR /&gt;- In the Tags tab, add the route tag you created earlier.&lt;BR /&gt;- This associates the specific traffic defined by the tag with the VPN tunnel route policy.&lt;/P&gt;
&lt;P&gt;On the Virtual Machine with StrongSwan:&lt;/P&gt;
&lt;P&gt;1. Install StrongSwan:&lt;/P&gt;
&lt;P&gt;Ensure StrongSwan is installed and configured on your VM.&lt;/P&gt;
&lt;P&gt;2. Configure StrongSwan:&lt;/P&gt;
&lt;P&gt;- Edit your StrongSwan configuration files.&lt;BR /&gt;- Define settings for your connection to the Palo Alto firewall, including:&lt;BR /&gt;- Local/remote addresses.&lt;BR /&gt;- Phase 1 and Phase 2 parameters.&lt;BR /&gt;- Security algorithms and authentication methods.&lt;/P&gt;
&lt;P&gt;3. Bring Up the Connection:&lt;/P&gt;
&lt;P&gt;Use the `ipsec up` command or relevant StrongSwan tools to initiate the VPN connection to the Palo Alto firewall.&lt;/P&gt;
&lt;P&gt;4. Verify Connectivity and Routing:&lt;/P&gt;
&lt;P&gt;Test the VPN connection and validate that the desired traffic from your local network is routed through the tunnel to the VM.&lt;/P&gt;
&lt;P&gt;Additional Notes:&lt;/P&gt;
&lt;P&gt;* Consult the documentation for your specific Palo Alto firewall model and StrongSwan version for detailed configuration instructions and parameter options.&lt;BR /&gt;* Consider applying advanced features of PureVPN or ExpressVPN like split tunneling on the Palo Alto firewall to route only specific traffic through the VPN tunnel.&lt;BR /&gt;* Ensure proper firewall rules are in place on both devices to allow traffic flow.&lt;BR /&gt;* Test and verify the setup thoroughly before putting it into production.&lt;/P&gt;
&lt;P&gt;By following these steps you should be able to establish a VPN tunnel between your Palo Alto firewall and the virtual machine.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jan 2024 12:37:44 GMT</pubDate>
    <dc:creator>GeorgeJay</dc:creator>
    <dc:date>2024-01-23T12:37:44Z</dc:date>
    <item>
      <title>Route-Based VPN between PaloAlto &amp; Strongswan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-based-vpn-between-paloalto-amp-strongswan/m-p/527227#M108932</link>
      <description>&lt;P&gt;Hi!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anyone have some experience about this topic? I need a vpn between our PaloAlto and a virtual machine with strong swan installed. To route some traffic from our local network to this vpn tunnel. How to make this possible?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 15:36:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-based-vpn-between-paloalto-amp-strongswan/m-p/527227#M108932</guid>
      <dc:creator>zloyBarsuk</dc:creator>
      <dc:date>2023-01-16T15:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: Route-Based VPN between PaloAlto &amp; Strongswan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-based-vpn-between-paloalto-amp-strongswan/m-p/527345#M108956</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/267938"&gt;@zloyBarsuk&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No personal experience but there has been a previous discussion about this you might want to check into.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-strongswan-opensource/td-p/50705" target="_blank" rel="noopener"&gt;site-to-site-vpn-with-strongswan-opensource&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 17 Jan 2023 08:30:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-based-vpn-between-paloalto-amp-strongswan/m-p/527345#M108956</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-01-17T08:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Route-Based VPN between PaloAlto &amp; Strongswan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/route-based-vpn-between-paloalto-amp-strongswan/m-p/574085#M115400</link>
      <description>&lt;P&gt;You need to follow several steps on both devices for setting up VPN. Here's a breakdown of the process:&lt;/P&gt;
&lt;P&gt;On the Palo Alto firewall:&lt;/P&gt;
&lt;P&gt;1. Create a VPN Tunnel:&lt;/P&gt;
&lt;P&gt;Go to Network &amp;gt; VPN &amp;gt; Tunnels.&lt;BR /&gt;Click Add and configure your VPN tunnel settings:&lt;BR /&gt;Type: IPSec&lt;BR /&gt;Name: Choose a descriptive name for your tunnel.&lt;BR /&gt;Local Interface: Select the interface connected to your internal network.&lt;BR /&gt;Peer Address: Enter the IP address of your VPN gateway/virtual machine running StrongSwan.&lt;BR /&gt;Preshared Key: Define a shared secret for authentication.&lt;/P&gt;
&lt;P&gt;2. Configure Phase 1 and Phase 2:&lt;/P&gt;
&lt;P&gt;Go to Phase 1 and Phase 2 tabs within the tunnel configuration.&lt;BR /&gt;- Define the encryption algorithms, authentication methods, and other relevant security settings for both phases as per your desired security level.&lt;BR /&gt;- Ensure compatibility with the StrongSwan configuration on your VM.&lt;/P&gt;
&lt;P&gt;3. Create Route Policy:&lt;/P&gt;
&lt;P&gt;Go to Network &amp;gt; Route &amp;gt; Policies.&lt;BR /&gt;Click Add and create a route policy for your VPN tunnel:&lt;BR /&gt;Name: Assign a relevant name.&lt;BR /&gt;Source Zone: Select the internal zone(s) where traffic originates for the VPN route.&lt;BR /&gt;Destination Zone: Choose the "VPN" zone associated with your tunnel.&lt;/P&gt;
&lt;P&gt;4. Create Route Tag:&lt;/P&gt;
&lt;P&gt;Go to Network &amp;gt; Tags &amp;gt; Route Tags.&lt;BR /&gt;* Click Add and create a route tag for your specific traffic:&lt;BR /&gt;Name: Choose a descriptive name like.&lt;BR /&gt;Match Criteria: Define criteria to identify the desired traffic.&lt;/P&gt;
&lt;P&gt;5. Apply Route Policy and Tag:&lt;/P&gt;
&lt;P&gt;- Go back to the Route Policy you created.&lt;BR /&gt;- In the Tags tab, add the route tag you created earlier.&lt;BR /&gt;- This associates the specific traffic defined by the tag with the VPN tunnel route policy.&lt;/P&gt;
&lt;P&gt;On the Virtual Machine with StrongSwan:&lt;/P&gt;
&lt;P&gt;1. Install StrongSwan:&lt;/P&gt;
&lt;P&gt;Ensure StrongSwan is installed and configured on your VM.&lt;/P&gt;
&lt;P&gt;2. Configure StrongSwan:&lt;/P&gt;
&lt;P&gt;- Edit your StrongSwan configuration files.&lt;BR /&gt;- Define settings for your connection to the Palo Alto firewall, including:&lt;BR /&gt;- Local/remote addresses.&lt;BR /&gt;- Phase 1 and Phase 2 parameters.&lt;BR /&gt;- Security algorithms and authentication methods.&lt;/P&gt;
&lt;P&gt;3. Bring Up the Connection:&lt;/P&gt;
&lt;P&gt;Use the `ipsec up` command or relevant StrongSwan tools to initiate the VPN connection to the Palo Alto firewall.&lt;/P&gt;
&lt;P&gt;4. Verify Connectivity and Routing:&lt;/P&gt;
&lt;P&gt;Test the VPN connection and validate that the desired traffic from your local network is routed through the tunnel to the VM.&lt;/P&gt;
&lt;P&gt;Additional Notes:&lt;/P&gt;
&lt;P&gt;* Consult the documentation for your specific Palo Alto firewall model and StrongSwan version for detailed configuration instructions and parameter options.&lt;BR /&gt;* Consider applying advanced features of PureVPN or ExpressVPN like split tunneling on the Palo Alto firewall to route only specific traffic through the VPN tunnel.&lt;BR /&gt;* Ensure proper firewall rules are in place on both devices to allow traffic flow.&lt;BR /&gt;* Test and verify the setup thoroughly before putting it into production.&lt;/P&gt;
&lt;P&gt;By following these steps you should be able to establish a VPN tunnel between your Palo Alto firewall and the virtual machine.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 12:37:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/route-based-vpn-between-paloalto-amp-strongswan/m-p/574085#M115400</guid>
      <dc:creator>GeorgeJay</dc:creator>
      <dc:date>2024-01-23T12:37:44Z</dc:date>
    </item>
  </channel>
</rss>

