<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-To-Site VPN Question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591603#M117812</link>
    <description>&lt;P&gt;That is what I was wanting to do is to have my remote site pass everything to my main site. These are very small remote sites and our main site is hardly using much resources of the PA it maybe peaks CPU load 10% sometimes but other than that its 2-4% averaging. How easy is passing is it to accomplish passing everything to the main site with a tunnel?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, are there better alternatives than a tunnel if we are wanting to direct all traffic to our main site?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2024 15:35:56 GMT</pubDate>
    <dc:creator>DuggiFresh</dc:creator>
    <dc:date>2024-07-10T15:35:56Z</dc:date>
    <item>
      <title>Site-To-Site VPN Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591487#M117784</link>
      <description>&lt;P&gt;If we deploy a Site-To-Site VPN to one of our remote locations with a Palo Alto NGFW will our main hub firewall control the Threat/URL, etc... and Security/NAT rules for the other Palo Alto?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 16:25:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591487#M117784</guid>
      <dc:creator>DuggiFresh</dc:creator>
      <dc:date>2024-07-09T16:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Site-To-Site VPN Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591502#M117788</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/247570"&gt;@DuggiFresh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Creating a tunnel to a remote site does not give the hub control over the remote site's&amp;nbsp;&lt;SPAN&gt;subscriptions/services as the remote fw will have its own subscriptions/services. You will still need to configure the security policies on the remote site that allow traffic to the hub along with the security profiles you have access to.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 19:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591502#M117788</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-07-09T19:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Site-To-Site VPN Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591524#M117800</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/247570"&gt;@DuggiFresh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The answer to your question is ... it depends. &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt; is correct in that the answer to this question is generally no. If your goal with this setup is to have the remote site pass &lt;EM&gt;everything &lt;/EM&gt;to your main site and using those subscriptions for all traffic and managing all rules from a single node, you &lt;EM&gt;&lt;STRONG&gt;could &lt;/STRONG&gt;&lt;/EM&gt;have the remote site send everything across the tunnel and process everything on the main site. This would have the main site have full control over all traffic, handle any NAT for the remote site, and generally be treated as an extension of the main site.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's some consequences with this sort of configuration however. The configuration on both sides is slightly more complex to handle everything correctly, it's an abnormal configuration for someone coming into the environment, and you'll have additional latency tunneling all of that traffic back and forth from the main site when accessing resources that don't actually require the use of the tunnel (IE: all normal internet traffic).&lt;/P&gt;
&lt;P&gt;That may or may not be a large concern for your environment depending on requirements and the added latency when going across the tunnel for everything.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 02:13:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591524#M117800</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-07-10T02:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Site-To-Site VPN Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591603#M117812</link>
      <description>&lt;P&gt;That is what I was wanting to do is to have my remote site pass everything to my main site. These are very small remote sites and our main site is hardly using much resources of the PA it maybe peaks CPU load 10% sometimes but other than that its 2-4% averaging. How easy is passing is it to accomplish passing everything to the main site with a tunnel?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, are there better alternatives than a tunnel if we are wanting to direct all traffic to our main site?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 15:35:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591603#M117812</guid>
      <dc:creator>DuggiFresh</dc:creator>
      <dc:date>2024-07-10T15:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Site-To-Site VPN Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591714#M117827</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would recommend the tunnel as it is the most secure option without spending additional money on a point2point circuit. Just route all traffic out of your 'hub' to control the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisa.gov/resources-tools/resources/trusted-internet-connections-tic-30-core-guidance-documents" target="_blank"&gt;https://www.cisa.gov/resources-tools/resources/trusted-internet-connections-tic-30-core-guidance-documents&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This helps greatly in managing and supporting the users when they have issues accessing an internet resource.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 14:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591714#M117827</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-07-11T14:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Site-To-Site VPN Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591862#M117844</link>
      <description>&lt;P&gt;What are some good resources on how to do that? Would I just need to create a static route from the remote site to the IPsec vpn tunnel? I don't want to use those remote sites for managing any of the policies and only use the hub to manage the policies.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 16:27:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591862#M117844</guid>
      <dc:creator>DuggiFresh</dc:creator>
      <dc:date>2024-07-12T16:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Site-To-Site VPN Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591863#M117845</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If you only have the one VPN tunnel and way to get to the hub device, then yes a static route would be the easiest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 16:30:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-question/m-p/591863#M117845</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-07-12T16:30:03Z</dc:date>
    </item>
  </channel>
</rss>

