<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deploying LSVPN ( Large Scale VPN) with NAT !!! in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30010#M21918</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A drawing of what you're trying to accomplish might help us understand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I think from what I've read, a static NAT from a public IP on your router to an inside IP on your PA device should solve the problem of having the PA "behind" the router, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encrypted traffic can be NAT'd... why do you think that encrypted traffic from the PA can't be NAT'd by your edge router?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Apr 2013 14:09:04 GMT</pubDate>
    <dc:creator>ericgearhart</dc:creator>
    <dc:date>2013-04-03T14:09:04Z</dc:date>
    <item>
      <title>Deploying LSVPN ( Large Scale VPN) with NAT !!!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30008#M21916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm newcomer with Palo Alto. I have project to deploy PA using LSVPN . But there is a problem because The Internet Link from ISP &amp;amp; MPLS must Via Router Cisco.&lt;/P&gt;&lt;P&gt;But I wonder , when using Router at Border , that means you must NAT Public IP to Private IP of PA. &lt;/P&gt;&lt;P&gt;So when deploy LSVPN, Traffic is encryped , that mean Router cann't NAT . So how to solve that problem. &lt;/P&gt;&lt;P&gt;I cann't deploy VPN with IPSEC VPN site-to-site because we have many Connection , many HUB &amp;amp; Spoke. &lt;/P&gt;&lt;P&gt;Please help me with answer. &lt;/P&gt;&lt;P&gt;Thanks alot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Apr 2013 03:44:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30008#M21916</guid>
      <dc:creator>MinhTuan</dc:creator>
      <dc:date>2013-04-02T03:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying LSVPN ( Large Scale VPN) with NAT !!!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30009#M21917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SO, i wait for longtime. No one has deployed LSVPN yet ? I have confused what kind of LSVPN Deployment , just like SSL VPN or IPSec VPN,&amp;nbsp; and however, if i use with Router, so what Port i need to Allow for LS VPN.&lt;/P&gt;&lt;P&gt;thank so much .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 14:04:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30009#M21917</guid>
      <dc:creator>MinhTuan</dc:creator>
      <dc:date>2013-04-03T14:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying LSVPN ( Large Scale VPN) with NAT !!!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30010#M21918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A drawing of what you're trying to accomplish might help us understand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I think from what I've read, a static NAT from a public IP on your router to an inside IP on your PA device should solve the problem of having the PA "behind" the router, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encrypted traffic can be NAT'd... why do you think that encrypted traffic from the PA can't be NAT'd by your edge router?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 14:09:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30010#M21918</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-04-03T14:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying LSVPN ( Large Scale VPN) with NAT !!!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30011#M21919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, i have uploaded my Topology .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="GSO-Overral-V6.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6161_GSO-Overral-V6.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;We have 3 site. 1 is HQ, 2 Branch.&lt;/P&gt;&lt;P&gt;Every Bratnch have two Connection to HQ via MPLS &amp;amp; Internet.&lt;/P&gt;&lt;P&gt;Now we want to Make VPN to secure Connection . We using LSVPN .But we still have Router infront of PaloAlto&lt;/P&gt;&lt;P&gt;PaloAlto have function like VPN Gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some questions:&lt;/P&gt;&lt;P&gt;1 . If we config Static NAT 1-to-1 on Router , is this true ?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Actually, i don't know what kind of LSVPN , SSL or IPSec, because&amp;nbsp; IF that is IPSec , we will NAT in Router with Port 500 &amp;amp;4500 , IF SSL VPN, how ?&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; When configuring GlobalProtect ,&amp;nbsp; IP when we configure GlobalPortal &amp;amp; GlobalGateway&amp;nbsp; is using Private IP of Palo Alto or using Public IP which provided by ISP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 15:05:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30011#M21919</guid>
      <dc:creator>MinhTuan</dc:creator>
      <dc:date>2013-04-03T15:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying LSVPN ( Large Scale VPN) with NAT !!!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30012#M21920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have test that LAB. I have answer for my question .&lt;/P&gt;&lt;P&gt;In router , we make Static NAT 1-to-1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When configure GlobalProtect in HUB. , some infomations are very important.&lt;/P&gt;&lt;P&gt;1. When generating Certificate from CA , you must using Common Name is Public IP of HUB . In this scenaro is 222.0.0.1&lt;/P&gt;&lt;P&gt;2. When configure Global Portal from HUB,&amp;nbsp; in Satellite Configuration --- Gateway is : Private IP of Hub . In this scenaro is 192.168.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When configure in Spoke ... make IPSec tunnel., IP of Portal is : Public IP of HUB&amp;nbsp; . In this scenaro is 222.0.0.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Apr 2013 10:16:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30012#M21920</guid>
      <dc:creator>MinhTuan</dc:creator>
      <dc:date>2013-04-04T10:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying LSVPN ( Large Scale VPN) with NAT !!!</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30013#M21921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice! Thanks for sharing your final solution. I haven't done anything with LSVPN yet, but it's in the back of my mind if/when we start deploying remote PA firewalls to some of our remote offices.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Apr 2013 14:16:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/deploying-lsvpn-large-scale-vpn-with-nat/m-p/30013#M21921</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-04-04T14:16:24Z</dc:date>
    </item>
  </channel>
</rss>

