<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-vpn/m-p/33031#M24204</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;Dear PaloAlto Support,&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;Does Palo Alto support this VPN feature such as&amp;nbsp; Dynamic VPN or Easy VPN? &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;Customer will use&amp;nbsp; Cisco Router at their branches. They want to connect VPN from all&amp;nbsp; branches to their HQ. All branches will have dynamic IP and HQ will have static&amp;nbsp; IP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Jan 2010 07:41:36 GMT</pubDate>
    <dc:creator>Ovan</dc:creator>
    <dc:date>2010-01-11T07:41:36Z</dc:date>
    <item>
      <title>Dynamic VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-vpn/m-p/33031#M24204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;Dear PaloAlto Support,&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;Does Palo Alto support this VPN feature such as&amp;nbsp; Dynamic VPN or Easy VPN? &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;Customer will use&amp;nbsp; Cisco Router at their branches. They want to connect VPN from all&amp;nbsp; branches to their HQ. All branches will have dynamic IP and HQ will have static&amp;nbsp; IP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 07:41:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-vpn/m-p/33031#M24204</guid>
      <dc:creator>Ovan</dc:creator>
      <dc:date>2010-01-11T07:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-vpn/m-p/33032#M24205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ovan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN devices don't support Cisco's proprietary Dynamic Multipoint VPN or Easy VPN.&amp;nbsp; You can configure the PAN to create tunnels with third party security devices, however.&amp;nbsp;&amp;nbsp; Connections between the central site and multiple remote sites would require VPN tunnels for each central-remote site pair and configuration of appropriate policies, DH parameters and encryption algorithms.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 18:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-vpn/m-p/33032#M24205</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-01-11T18:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-vpn/m-p/33033#M24206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank nrice,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But If I want to test Dynamic VPN with 2 PaloAlto appliance, can I?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 line Internet:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; +Line 1:&lt;/P&gt;&lt;P&gt;-IP Public: 123.21.40.167 (dynamic IP)&lt;/P&gt;&lt;P&gt;-Modem's IP: 172.16.1.254/24&lt;/P&gt;&lt;P&gt;-PaloAlto1 Layer 3:&amp;nbsp; Zone-Internet: 172.16.1.120/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Zone-LAN: 192.168.5.0/24&lt;/P&gt;&lt;P&gt;-Modem NAT port 1723 to IP 172.16.1.120&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +Line 2: 222.253.113.230 (static IP)&lt;/P&gt;&lt;P&gt;-Modem's IP: 192.168.81.254/24&lt;/P&gt;&lt;P&gt;-PaloAlto2 Layer 3:&amp;nbsp; Zone-Internet:&amp;nbsp; 192.168.81.98/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Zone-LAN:&amp;nbsp; 192.168.2.0/24&lt;/P&gt;&lt;P&gt;-Modem NAT port 1723 to IP 192.168.81.98&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both 2 PaloAlto, I configured IKE Gateway to point direct 2 IP public (still not use Dynamic option) but when I SSH to PaloAlto, and type 'show vpn flow' the state is init (not inactive) (please refer the attached file: Snapshot VPN-SSH.jpg).&lt;/P&gt;&lt;P&gt;I want to test Dynamic VPN, but I want to ensure that IPSec VPN running well first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I uploaded some snapshots and the configuration file, please refer the attached files and help to solve this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Ovan&lt;/P&gt;&lt;P&gt;Skype: ovan_pham&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jan 2010 04:29:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-vpn/m-p/33033#M24206</guid>
      <dc:creator>Ovan</dc:creator>
      <dc:date>2010-01-15T04:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dynamic-vpn/m-p/33034#M24207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ovan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please contact Support so that they can assist you with your configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jan 2010 22:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dynamic-vpn/m-p/33034#M24207</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-01-15T22:51:45Z</dc:date>
    </item>
  </channel>
</rss>

