<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Bidirectionnal,IPSEC NAT-T and secondary address problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25456#M18559</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to have a Cisco router establishing an IP SEC Tunnel behind a pao alto firewal configured in L3 Mode.&lt;/P&gt;&lt;P&gt;The tunnel should be established on a secondary address on a sub interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eth 1 Public, Two Sub interface 1.666 and 1.667&lt;/P&gt;&lt;P&gt;eth1.666 address is x.y.z.131/25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and need the tunnel on x.y.z.132 then I do NAT 1-1 rule with option bidirectionnal&amp;nbsp; The source of the tunnel is 10.35.3.253 on eth2.500&lt;/P&gt;&lt;P&gt;The IKE exchange begin but stop in the middle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I use&amp;nbsp; x.y.z.131 no problem, it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I need the 131 address for other things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What should I do for the NAt 1-1 to accept the secondary address ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jean-Luc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 07 Oct 2012 15:37:45 GMT</pubDate>
    <dc:creator>JeanLuc974</dc:creator>
    <dc:date>2012-10-07T15:37:45Z</dc:date>
    <item>
      <title>NAT Bidirectionnal,IPSEC NAT-T and secondary address problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25456#M18559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to have a Cisco router establishing an IP SEC Tunnel behind a pao alto firewal configured in L3 Mode.&lt;/P&gt;&lt;P&gt;The tunnel should be established on a secondary address on a sub interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eth 1 Public, Two Sub interface 1.666 and 1.667&lt;/P&gt;&lt;P&gt;eth1.666 address is x.y.z.131/25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and need the tunnel on x.y.z.132 then I do NAT 1-1 rule with option bidirectionnal&amp;nbsp; The source of the tunnel is 10.35.3.253 on eth2.500&lt;/P&gt;&lt;P&gt;The IKE exchange begin but stop in the middle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I use&amp;nbsp; x.y.z.131 no problem, it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I need the 131 address for other things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What should I do for the NAt 1-1 to accept the secondary address ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jean-Luc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2012 15:37:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25456#M18559</guid>
      <dc:creator>JeanLuc974</dc:creator>
      <dc:date>2012-10-07T15:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Bidirectionnal,IPSEC NAT-T and secondary address problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25457#M18560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the Cisco establishing the VPN tunnel with the Palo Alto firewall or the firewall is just in a pass through stage for ipsec traffic?&lt;/P&gt;&lt;P&gt;It somehow appears from the description the tunnel is terminating on the firewall. Correct me if I am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is the case and from the description of the two ip-addresses in use , you can use the the feature of secondary ip-address on the interface and not the sub-interfaces.&lt;/P&gt;&lt;P&gt;What I mean is the following:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trust Zone:-&amp;nbsp; Internal corporate network&lt;/P&gt;&lt;P&gt;Untrust Zone:-&amp;nbsp; Outside World&lt;/P&gt;&lt;P&gt;VPN zone :-&amp;nbsp; tunnel is in this zone. (VPN users)&lt;/P&gt;&lt;P&gt;&lt;IMG alt="sec-ipppp.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4396_sec-ipppp.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;From above, 10.30.6.59/24 is the interface address. However the VPN ike-gateway address can be set as a secondary ip-address on the interface as 10.30.6.110/32 as seen above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tunnel will be in VPN zone:-&lt;/P&gt;&lt;P&gt;&lt;IMG alt="vpntunnel.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4397_vpntunnel.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;NAT rule should look like the following:-&lt;/P&gt;&lt;P&gt;One rule for the trust users and one for the&amp;nbsp; VPN users (Ip-pool)&lt;/P&gt;&lt;P&gt;&lt;IMG alt="vpm-nat.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4398_vpm-nat.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also make sure you have security rules from VPN to Trust and the other way around.&lt;/P&gt;&lt;P&gt;And there is no explicit deny rule in the security rule base.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 04:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25457#M18560</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-08T04:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Bidirectionnal,IPSEC NAT-T and secondary address problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25458#M18561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PA-200 is just pass-through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the problem is that the response is not correctly forwarded to the Cisco router. The IKE exchange get stuck in the middle :&lt;/P&gt;&lt;P&gt;From one side it says : MM_NO_STATE and from the other MM_SA_SETUP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will make a schema and post it.&lt;/P&gt;&lt;P&gt;could it be related to the two public link on the same physical interface ? If absolutely necessary I can ask to have the the two sub interface on two physical one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thnaks trying to help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jean-Luc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 05:28:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25458#M18561</guid>
      <dc:creator>JeanLuc974</dc:creator>
      <dc:date>2012-10-08T05:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Bidirectionnal,IPSEC NAT-T and secondary address problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25459#M18562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is the case, we would like see the configuration and review logs on the firewall.&lt;/P&gt;&lt;P&gt;Does the second sub-interface have the ip-address in the same subnet as the first?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 05:43:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25459#M18562</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-08T05:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Bidirectionnal,IPSEC NAT-T and secondary address problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25460#M18563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Here is the schema:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="REseau1.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4399_REseau1.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this can help understanding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I prefer to terminate the tunnel on the cisco router because we have vrf-lite configuration on it. And if we terminate the VPN on the Palo-Alto, they will not be vrf-aware&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 05:44:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25460#M18563</guid>
      <dc:creator>JeanLuc974</dc:creator>
      <dc:date>2012-10-08T05:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Bidirectionnal,IPSEC NAT-T and secondary address problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25461#M18564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bug from ISP, excuse for the trouble&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jean-Luc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 14:06:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-bidirectionnal-ipsec-nat-t-and-secondary-address-problem/m-p/25461#M18564</guid>
      <dc:creator>JeanLuc974</dc:creator>
      <dc:date>2012-10-09T14:06:40Z</dc:date>
    </item>
  </channel>
</rss>

