<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Paloalto routing an IPSEC tunnel to another router in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-routing-an-ipsec-tunnel-to-another-router/m-p/1232460#M124648</link>
    <description>&lt;P&gt;Hello, I'm trying to create a tunnel between R1 (OpnSense) and R3 (Sophos), R2 is the Paloalto that NATs a dedicated wan IP to interface1/2 (private TRUST LAN) where is locally connected the Sophos.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;R1 (Opnsense) &amp;lt;-----&amp;gt;&amp;nbsp; R2 (Paloalto NAT 1:1) &amp;lt;-----&amp;gt; R3 (Sophos)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have setup all the IPSEC IKE2 tunnels on R1 and R3,&amp;nbsp; on R2 i did the NAT1:1 with Dinamic IP and Port on both inbound and outbound sides,&amp;nbsp; so the clients on R3 have the Public IP that i set,&amp;nbsp; the NAT is working fine with the TCP ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexcoxie_0-1750750937204.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68154i33EBB3DA5A7687FF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexcoxie_0-1750750937204.png" alt="alexcoxie_0-1750750937204.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Security (86 apps seen)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexcoxie_1-1750751072579.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68155iD6DEF251F2431643/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexcoxie_1-1750751072579.png" alt="alexcoxie_1-1750751072579.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexcoxie_2-1750751152487.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68156i9231AE93363C1D95/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexcoxie_2-1750751152487.png" alt="alexcoxie_2-1750751152487.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexcoxie_3-1750751174390.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68157iB8835492DC8848F2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexcoxie_3-1750751174390.png" alt="alexcoxie_3-1750751174390.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is the the tunnel is not initialized, I can't see any package arriving from the R1 to R2 on UPD 500/4500.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what could be? It is possible to do this configuration ? (R2 routes the tunnel between R1 and R3 only with a NAT?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jun 2025 07:46:39 GMT</pubDate>
    <dc:creator>alexcoxie</dc:creator>
    <dc:date>2025-06-24T07:46:39Z</dc:date>
    <item>
      <title>Paloalto routing an IPSEC tunnel to another router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-routing-an-ipsec-tunnel-to-another-router/m-p/1232460#M124648</link>
      <description>&lt;P&gt;Hello, I'm trying to create a tunnel between R1 (OpnSense) and R3 (Sophos), R2 is the Paloalto that NATs a dedicated wan IP to interface1/2 (private TRUST LAN) where is locally connected the Sophos.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;R1 (Opnsense) &amp;lt;-----&amp;gt;&amp;nbsp; R2 (Paloalto NAT 1:1) &amp;lt;-----&amp;gt; R3 (Sophos)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have setup all the IPSEC IKE2 tunnels on R1 and R3,&amp;nbsp; on R2 i did the NAT1:1 with Dinamic IP and Port on both inbound and outbound sides,&amp;nbsp; so the clients on R3 have the Public IP that i set,&amp;nbsp; the NAT is working fine with the TCP ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexcoxie_0-1750750937204.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68154i33EBB3DA5A7687FF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexcoxie_0-1750750937204.png" alt="alexcoxie_0-1750750937204.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Security (86 apps seen)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexcoxie_1-1750751072579.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68155iD6DEF251F2431643/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexcoxie_1-1750751072579.png" alt="alexcoxie_1-1750751072579.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexcoxie_2-1750751152487.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68156i9231AE93363C1D95/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexcoxie_2-1750751152487.png" alt="alexcoxie_2-1750751152487.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alexcoxie_3-1750751174390.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68157iB8835492DC8848F2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="alexcoxie_3-1750751174390.png" alt="alexcoxie_3-1750751174390.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is the the tunnel is not initialized, I can't see any package arriving from the R1 to R2 on UPD 500/4500.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what could be? It is possible to do this configuration ? (R2 routes the tunnel between R1 and R3 only with a NAT?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 07:46:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-routing-an-ipsec-tunnel-to-another-router/m-p/1232460#M124648</guid>
      <dc:creator>alexcoxie</dc:creator>
      <dc:date>2025-06-24T07:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto routing an IPSEC tunnel to another router</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-routing-an-ipsec-tunnel-to-another-router/m-p/1232491#M124651</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Do you also have the appropriate security policies in place to allow the traffic? Check the Unified logs to see if the traffic is allowed or blocked.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 16:23:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-routing-an-ipsec-tunnel-to-another-router/m-p/1232491#M124651</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-06-24T16:23:30Z</dc:date>
    </item>
  </channel>
</rss>

