<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Add second ip to tunnel interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/add-second-ip-to-tunnel-interface/m-p/20593#M15036</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering if it is possible to add a second IP to a tunnel interface. I want to add some extra IPs to a tunnel interface (/28 subnet). To allow a remote party to connect to some servers in our internal network using NAT over IPsec tunnel. I have been looking at both CLI and GUI both cannot find it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Oct 2012 07:56:49 GMT</pubDate>
    <dc:creator>jorgdc</dc:creator>
    <dc:date>2012-10-08T07:56:49Z</dc:date>
    <item>
      <title>Add second ip to tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-second-ip-to-tunnel-interface/m-p/20593#M15036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering if it is possible to add a second IP to a tunnel interface. I want to add some extra IPs to a tunnel interface (/28 subnet). To allow a remote party to connect to some servers in our internal network using NAT over IPsec tunnel. I have been looking at both CLI and GUI both cannot find it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 07:56:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-second-ip-to-tunnel-interface/m-p/20593#M15036</guid>
      <dc:creator>jorgdc</dc:creator>
      <dc:date>2012-10-08T07:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Add second ip to tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-second-ip-to-tunnel-interface/m-p/20594#M15037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you are taking about the proxy id's here, correct me if I am wrong.&lt;/P&gt;&lt;P&gt;Tunnel Monitoring is used to keep a VPN tunnel communicating with the other VPN endpoint. If a tunnel monitor profile is created it will specify one of two action options if the tunnel is not available; wait-recover or fail-over.&lt;/P&gt;&lt;P&gt;For&amp;nbsp; tunnel monitoring, under Network&amp;gt; Ipsec Tunnels &amp;gt; Advance Options, the destination ip-address would be a single Ip-address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondary ip-address cannot be configure on the tunnel interface under Network &amp;gt; Interfaces &amp;gt; Tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, you can set proxy ids to achieve this where you can keep the local private subnet in "local" field and the remote private subnet under "remote" field.&amp;nbsp; The same proxy ids also need to be set on the other side but the local and the peer subnets would be reversed.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="proxy.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4402_proxy.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 09:03:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-second-ip-to-tunnel-interface/m-p/20594#M15037</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-08T09:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Add second ip to tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-second-ip-to-tunnel-interface/m-p/20595#M15038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The tunnel was allready setup and working and filled in the proxy ids for remote and local.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have added one IP to tunnel inferface which we use for source nat to the other party. Works allready.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4403_Capture.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;We just now want to make some servers accessible to the other party on a couple of IPs in the same /28 range. On our previous firewall we needed to create the interface first on every tunnel before we could destination nat. Is this also the case for PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 09:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-second-ip-to-tunnel-interface/m-p/20595#M15038</guid>
      <dc:creator>jorgdc</dc:creator>
      <dc:date>2012-10-08T09:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Add second ip to tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-second-ip-to-tunnel-interface/m-p/20596#M15039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Jorg,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can define the subnet (/28) in the IP address section of the tunnel interface. Now from that subnet you use the rest of the other IP addresses to create the Destination NAT policies based on the requirements. I have tested this in my lab and everything works as expected. Let us know if you have any questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Khubaib &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 20:03:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-second-ip-to-tunnel-interface/m-p/20596#M15039</guid>
      <dc:creator>kalavi</dc:creator>
      <dc:date>2012-10-08T20:03:18Z</dc:date>
    </item>
  </channel>
</rss>

