<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN port and default port the same? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24803#M18083</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hallo all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have only one phyical ethernet interface on firewall which is facing the internet. I also want to make this PA firewall as an IPSEC Tunnel endpoint. So all my internal traffic uses this ethernet interface to go to internet. And VPN traffic should terminate on the same interface.&lt;/P&gt;&lt;P&gt;Is this possible? If yes, how can I implement it? Any documentation or procedures?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Oct 2014 08:27:28 GMT</pubDate>
    <dc:creator>Neo.The.One</dc:creator>
    <dc:date>2014-10-22T08:27:28Z</dc:date>
    <item>
      <title>VPN port and default port the same?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24803#M18083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hallo all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have only one phyical ethernet interface on firewall which is facing the internet. I also want to make this PA firewall as an IPSEC Tunnel endpoint. So all my internal traffic uses this ethernet interface to go to internet. And VPN traffic should terminate on the same interface.&lt;/P&gt;&lt;P&gt;Is this possible? If yes, how can I implement it? Any documentation or procedures?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 08:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24803#M18083</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-10-22T08:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN port and default port the same?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24804#M18084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you are using this PAN firewall only to scan traffic. If so, you can implement above mentioned setup. You have to configure different route for both physical interface and through the VPN tunnel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; For all internet traffic through physical interface&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; :&lt;/SPAN&gt; &lt;STRONG&gt;Destination&lt;/STRONG&gt; 0.0.0.0 - &lt;STRONG&gt;next hop&lt;/STRONG&gt; ISP &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ipaddress&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;next hop)&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; For VPN traffic&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; :&lt;/SPAN&gt; &lt;STRONG&gt;Destination&lt;/STRONG&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; :&lt;/SPAN&gt; source subnet behind &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;IPSec tunnel&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ,&lt;/SPAN&gt; &lt;STRONG&gt;interface&lt;/STRONG&gt;- tunnel&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;xx, &lt;STRONG&gt;next hop&lt;/STRONG&gt;- None&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps and let us know the result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 08:56:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24804#M18084</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-22T08:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN port and default port the same?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24805#M18085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok I will try it out and let you know.&lt;/P&gt;&lt;P&gt;Also, in the VR, I should always mention either the Interface or the Next Hop, but not both, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 09:40:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24805#M18085</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-10-22T09:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN port and default port the same?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24806#M18086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can use single ethernet interface towards internet for all functionality: user access to web, IPSEC VPN termination, GlobalProtect portal and gateway, external management of firewall (in that case mgmt port changes to 4443)..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 10:49:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24806#M18086</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-10-22T10:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN port and default port the same?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24807#M18087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can achieve this through static route. You need to create two sort of static route.&lt;/P&gt;&lt;P&gt;1. Default route pointing towards ISP ethernet interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Set of static routes Pointing towards tunnel interace. But for that make sure those routes exist in Proxy IDs of IPsec tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 14:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24807#M18087</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-22T14:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN port and default port the same?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24808#M18088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the VR, you may select both "interface" and "next-hop" at the same time in static route configuration. But, in common scenario&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;,&lt;/SPAN&gt;if IPSec tunnel is not configured with an IP, hence you may only select "interface" &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;[ &lt;/SPAN&gt;Outgoing interface] option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 15:01:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24808#M18088</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-22T15:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN port and default port the same?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24809#M18089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any static route next hop is required just like another vendors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But for static routes for tunnel, you can skip next hope.&amp;nbsp; You can select it as none.&lt;/P&gt;&lt;P&gt;Many customers doesnt configure IP on Tunnel, hence they can just point route to tunnel and skip the next hop.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Tunnel.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16515_Tunnel.png" style="height: 388px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However if tunnel has IP address you can configure it, but its optional. Not a mandatory thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 15:19:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24809#M18089</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-22T15:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN port and default port the same?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24810#M18090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the most part this is typically how most of the users will be using, ie 1 public ip and many services like outbound NAT, IPSec, GlobalProtect, Remote access etc. So this will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For outbound traffic, you will need the following:&lt;/P&gt;&lt;P&gt;-outbound NAT, translate source to the public IP&lt;/P&gt;&lt;P&gt;-appropriate static routes to default gateway as discussed earlier.&lt;/P&gt;&lt;P&gt;-security rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For IPSec, you may follow this document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6791"&gt;How to Configure IPSEC VPN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dileep&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2014 16:29:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-port-and-default-port-the-same/m-p/24810#M18090</guid>
      <dc:creator>dreputi</dc:creator>
      <dc:date>2014-10-22T16:29:31Z</dc:date>
    </item>
  </channel>
</rss>

