<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN - PA to PA - need internet traffic to go through additional device one hop inside PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18246#M13305</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank for the update. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Aug 2014 19:31:03 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-08-08T19:31:03Z</dc:date>
    <item>
      <title>VPN - PA to PA - need internet traffic to go through additional device one hop inside PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18240#M13299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Remote site has a PA-200&lt;/P&gt;&lt;P&gt;HQ has a PA-2020.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the VPN setup between the two so that they are connected to each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I need the internet traffic from the remote site to pass through our content filter that is connected to the PA-2020 at the HQ.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the content filter is not seen by any devices, it is transparent to all devices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic flow from a laptop at the remote site to the internet would look like this:&lt;/P&gt;&lt;P&gt;Laptop --&amp;gt; PA-200 -----VPN----&amp;gt;&amp;nbsp; PA-2020 (HQ) ----&amp;gt; content filter (transparent) ----&amp;gt;&amp;nbsp; HQ core switch&amp;nbsp;&amp;nbsp; ------&amp;gt;&amp;nbsp;&amp;nbsp; content filter (transparent)&amp;nbsp; ----&amp;gt;&amp;nbsp;&amp;nbsp; PA-2020 (HQ) ----&amp;gt; internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does that make sense?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Thanks for any assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2014 13:29:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18240#M13299</guid>
      <dc:creator>MattShuter</dc:creator>
      <dc:date>2014-07-29T13:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN - PA to PA - need internet traffic to go through additional device one hop inside PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18241#M13300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks good to me. Since, traffic traversing through PAN firewall twice, we may need to perform a source NAT for this traffic at HQ core switch. A source NAT with ensuring the symmetric return of the traffic through the HQ core switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Network-diagram.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14743_Network-diagram.jpg" style="height: 431px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;As per my understanding, your traffic is flowing like above mentioned diagram. The green line is for return traffic from internet. So, only a source NAT in your HQ core switch can ensure the return traffic to go back to HQ core through &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;content filter&lt;/SPAN&gt;. Otherwise, if you perform NAT on PAN firewall, return traffic will not &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;travese&lt;/SPAN&gt; through HQ core and content filter, since PAN firewall will identify the direct route to reach remote user's subnet through VPN tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2014 14:31:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18241#M13300</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-29T14:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN - PA to PA - need internet traffic to go through additional device one hop inside PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18242#M13301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The internet traffic is not hitting the core switch, only the internal traffic.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Do I need to adjust my route table on the remove VPN to direct traffic to the core switch ip instead of the PA-2020?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I am going to try this to see what it does...but I don't think it will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What if I had another device on the other side of the core switch?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a vpn concentrator, or even another PA box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would it be possible to simply NAT (bi-directional)&amp;nbsp; the VPN traffic from public ip on PA-2020 to internal ip of other device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; remote site PA-200 public ip ----&amp;gt;&amp;nbsp;&amp;nbsp; PA-2020 public IP ----&amp;gt;&amp;nbsp;&amp;nbsp; (NAT) -----&amp;gt; PA-200 internal ip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; then, internet traffic would go out via the core, pass through the content filter, and then back in...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2014 17:59:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18242#M13301</guid>
      <dc:creator>MattShuter</dc:creator>
      <dc:date>2014-08-05T17:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN - PA to PA - need internet traffic to go through additional device one hop inside PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18243#M13302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;or...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; how do I setup the PA200 split traffic...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; internal, 10.x.x.x via the VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; internet, 0.0.0.0 except 10.x, via the internet connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tried two routes, but they didn't split the traffic, everything still going over the vpn...unless I didn't get the right combination of interface/route/next hop/etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2014 19:15:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18243#M13302</guid>
      <dc:creator>MattShuter</dc:creator>
      <dc:date>2014-08-05T19:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN - PA to PA - need internet traffic to go through additional device one hop inside PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18244#M13303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to configure a specific route through VPN tunnel &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;based on destination) and a default route for all internet traffic. The PAN firewall will search for a longer match first &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;through the &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;tinnel&lt;/SPAN&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2014 19:36:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18244#M13303</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-05T19:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN - PA to PA - need internet traffic to go through additional device one hop inside PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18245#M13304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to get this to work, the traffic split between VPN and local internet access...realized I was using the wrong next hop address for my internet traffic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2014 19:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18245#M13304</guid>
      <dc:creator>MattShuter</dc:creator>
      <dc:date>2014-08-08T19:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN - PA to PA - need internet traffic to go through additional device one hop inside PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18246#M13305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank for the update. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2014 19:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-pa-to-pa-need-internet-traffic-to-go-through-additional/m-p/18246#M13305</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-08T19:31:03Z</dc:date>
    </item>
  </channel>
</rss>

