<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: need to configure IP-SEC VPN between 2 sites with overlapping networks problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-configure-ip-sec-vpn-between-2-sites-with-overlapping/m-p/17957#M13070</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your NAT policies should like below:&lt;/P&gt;&lt;P&gt;&lt;IMG class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/12175_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that routing for 192.168.98.5/32 and 172.16.0.0/16 points to tunnel interface.&lt;/P&gt;&lt;P&gt;Assuming Out destination zone points to Tunnel interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your security policies should like below:&lt;/P&gt;&lt;P&gt;&lt;IMG class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/12185_pastedImage_1.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Mar 2014 04:02:24 GMT</pubDate>
    <dc:creator>hyadavalli</dc:creator>
    <dc:date>2014-03-18T04:02:24Z</dc:date>
    <item>
      <title>need to configure IP-SEC VPN between 2 sites with overlapping networks problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-configure-ip-sec-vpn-between-2-sites-with-overlapping/m-p/17954#M13067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;scenario&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;Site A&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;Any equipment IPSec firewall&lt;BR /&gt;internal interface: 172.16.0.1 255.255.0.0&lt;BR /&gt;external Interface:20.1.1.10&lt;BR /&gt;Internal Network: 172.0.0.0/8&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;VPN proxy ID&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;BR /&gt;&lt;BR /&gt;Local: 172.16.0.0/16&lt;BR /&gt;Remote: 192.168.98.5/32&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;Site B&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;Equipment PA-2050&lt;BR /&gt;internal interface: 172.22.6.245&lt;BR /&gt;external Interface: 20.1.1.20&lt;BR /&gt;Internal Network: 172.0.0.0/8&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;VPN proxy IP&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;BR /&gt;Local: 172.22.0.0/16&lt;BR /&gt;Remote: 192.168.98.5&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;BR /&gt;A host 172.16.0.x in Site A needs access server (172.22.6.244) in Site B by IPSec VPN Tunnel &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;Problem 1: The internal networks in Site A has a Vlan with 172.22.0.0/8&lt;BR /&gt;Problem 2: The internal networks in Site B has a Vlan with 172.16.0.0/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;How it works today with Cisco ASA: &lt;BR /&gt;&lt;BR /&gt;- The host in site A initiates connection to the IP 192.168.98.5 &lt;BR /&gt;- The PA-2050 perfoms dynamic NAT with source 172.16.0.0/24 para o IP 192.168.98.5&lt;BR /&gt;- O PA-2050 perfoms a static NAT with source 172.22.6.244 para 192.168.98.5&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;NAT ASA&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal" style="margin-bottom: 10pt;"&gt;&lt;SPAN lang="EN" style="line-height: 115%; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;&lt;IMG 12133="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT PA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="12129" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/12129_pastedImage_3.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;My problem&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt;"&gt; &lt;SPAN class="hps"&gt;is&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;that&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;NAT&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;not&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;return&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;this&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;worked&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Static&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;NAT&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;not&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;working properly&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;in&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;this&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt;"&gt;Paloalto!!!!!!!!&lt;IMG __jive_id="_topologia1.png'" style="width: 620px; height: 344px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2014 13:36:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-configure-ip-sec-vpn-between-2-sites-with-overlapping/m-p/17954#M13067</guid>
      <dc:creator>Netsul</dc:creator>
      <dc:date>2014-03-14T13:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: need to configure IP-SEC VPN between 2 sites with overlapping networks problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-configure-ip-sec-vpn-between-2-sites-with-overlapping/m-p/17955#M13068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Netsul,&lt;/P&gt;&lt;P&gt;Could you please follow the doc &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1594"&gt;Configuring route based IPSec with overlapping networks&lt;/A&gt; for the same. Specially the NAT part of the PAN firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2014 16:20:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-configure-ip-sec-vpn-between-2-sites-with-overlapping/m-p/17955#M13068</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-14T16:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: need to configure IP-SEC VPN between 2 sites with overlapping networks problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-configure-ip-sec-vpn-between-2-sites-with-overlapping/m-p/17956#M13069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;Hi&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="hps"&gt;Hulk&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;verificaquei&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the document&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;did not work&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;over&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;NAT&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;return&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2014 16:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-configure-ip-sec-vpn-between-2-sites-with-overlapping/m-p/17956#M13069</guid>
      <dc:creator>Netsul</dc:creator>
      <dc:date>2014-03-14T16:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: need to configure IP-SEC VPN between 2 sites with overlapping networks problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-to-configure-ip-sec-vpn-between-2-sites-with-overlapping/m-p/17957#M13070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your NAT policies should like below:&lt;/P&gt;&lt;P&gt;&lt;IMG class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/12175_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that routing for 192.168.98.5/32 and 172.16.0.0/16 points to tunnel interface.&lt;/P&gt;&lt;P&gt;Assuming Out destination zone points to Tunnel interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your security policies should like below:&lt;/P&gt;&lt;P&gt;&lt;IMG class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/12185_pastedImage_1.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hari Yadavalli&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Mar 2014 04:02:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-to-configure-ip-sec-vpn-between-2-sites-with-overlapping/m-p/17957#M13070</guid>
      <dc:creator>hyadavalli</dc:creator>
      <dc:date>2014-03-18T04:02:24Z</dc:date>
    </item>
  </channel>
</rss>

