<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic questions while creating first IPsec tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/questions-while-creating-first-ipsec-tunnel/m-p/599988#M119267</link>
    <description>&lt;P&gt;We have our egress on Eth1/1 with a public IP assigned by our provider. &lt;BR /&gt;We also own a separate public subnet. &lt;BR /&gt;We have the internet working and want to add an IPsec tunnel from our PAN to a partner also running PAN. &lt;BR /&gt;I'm told to continue using the Eth1/1 interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see problems with this solution? Diagram attached.&lt;/P&gt;
&lt;P&gt;Eth1/1 is untrust. It has IP 4.4.4.4. &lt;BR /&gt;We add a second public IP to Eth1/1 from the subnet we own (5.5.5.5)&lt;BR /&gt;Create a new zone for IPSec. &lt;BR /&gt;Create a tunnel.1 interface. Assign it to the IPSec zone. &lt;BR /&gt;Create an IKE Gateway Profile that uses our 5.5.5.5 and the public Peer IP 6.6.6.6. &lt;BR /&gt;Then we define the IPSec Tunnel to be Tunnel.1 and the IKE Gateway Profile. &lt;BR /&gt;Lastly, we configure static route to forward destination traffic to Tunnel.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would this work? Are there better ways to set this up?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phase 2 plan would be to add additional tunnel interfaces for other partners.&lt;/P&gt;
&lt;P&gt;tunnel.2, etc. with 5.5.5.5 being our source IP. 7.7.7.7 being the peer. &lt;BR /&gt;But what happens if two partners use the same internal subnets in their respective tunnels? How do you route LAN traffic to the correct tunnel?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2024 21:34:41 GMT</pubDate>
    <dc:creator>1treelanedrv</dc:creator>
    <dc:date>2024-10-09T21:34:41Z</dc:date>
    <item>
      <title>questions while creating first IPsec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-while-creating-first-ipsec-tunnel/m-p/599988#M119267</link>
      <description>&lt;P&gt;We have our egress on Eth1/1 with a public IP assigned by our provider. &lt;BR /&gt;We also own a separate public subnet. &lt;BR /&gt;We have the internet working and want to add an IPsec tunnel from our PAN to a partner also running PAN. &lt;BR /&gt;I'm told to continue using the Eth1/1 interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see problems with this solution? Diagram attached.&lt;/P&gt;
&lt;P&gt;Eth1/1 is untrust. It has IP 4.4.4.4. &lt;BR /&gt;We add a second public IP to Eth1/1 from the subnet we own (5.5.5.5)&lt;BR /&gt;Create a new zone for IPSec. &lt;BR /&gt;Create a tunnel.1 interface. Assign it to the IPSec zone. &lt;BR /&gt;Create an IKE Gateway Profile that uses our 5.5.5.5 and the public Peer IP 6.6.6.6. &lt;BR /&gt;Then we define the IPSec Tunnel to be Tunnel.1 and the IKE Gateway Profile. &lt;BR /&gt;Lastly, we configure static route to forward destination traffic to Tunnel.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would this work? Are there better ways to set this up?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phase 2 plan would be to add additional tunnel interfaces for other partners.&lt;/P&gt;
&lt;P&gt;tunnel.2, etc. with 5.5.5.5 being our source IP. 7.7.7.7 being the peer. &lt;BR /&gt;But what happens if two partners use the same internal subnets in their respective tunnels? How do you route LAN traffic to the correct tunnel?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 21:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-while-creating-first-ipsec-tunnel/m-p/599988#M119267</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2024-10-09T21:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: questions while creating first IPsec tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/questions-while-creating-first-ipsec-tunnel/m-p/600913#M119358</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This looks correct. I didnt review all of your policies in the pictures, but the steps are correct. If the partners have the same IP's on their internal networks, you'll need to read the following:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUFCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUFCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 20:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/questions-while-creating-first-ipsec-tunnel/m-p/600913#M119358</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-10-15T20:55:15Z</dc:date>
    </item>
  </channel>
</rss>

