<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: On-demand ipsec tunnels? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43374#M31818</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi SDorsey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN Tunnel is initiated in two circumstances.&lt;/P&gt;&lt;P&gt;1. In case of interested traffic. &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;Sorry for Cisco Jargon.&lt;/P&gt;&lt;P&gt;2. By using a Test vpn command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now it stays up until SAs life time. Cisco also behaves in exactly same way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a traffic than it stays up and remains up until SA expires. Inbetween if you want to terminate it than clear flows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please tell me more specific information on "On demand" word.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Nov 2014 14:09:14 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-11-12T14:09:14Z</dc:date>
    <item>
      <title>On-demand ipsec tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43367#M31811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible in the PAN to do on-demand vpn tunnels? This is used quite a bit in the Cisco world.. especially for vendors. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They often are setup so the tunnel is configured but when the vendor needs to connect for support, the end-user needs to connect to their ASA and initiate the tunnel basically. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 12:25:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43367#M31811</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-09-04T12:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: On-demand ipsec tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43368#M31812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today you can't disable a VPN in a PA. The only thing you can do is to delete your tunnel&lt;/P&gt;&lt;P&gt;I know there are many request for that. May be introduce in 6.1 version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;v.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 14:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43368#M31812</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-09-04T14:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: On-demand ipsec tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43369#M31813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mackwage&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Are you talking about site to site IPSec VPN tunnel...? The PAN firewall will bring the IPSec VPN tunnel upon interesting traffic by default. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 14:54:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43369#M31813</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-04T14:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: On-demand ipsec tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43370#M31814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt; Get out of here with that "interesting traffic" terminology. That is Cisco jargon. :smileylaugh:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 16:03:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43370#M31814</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-09-04T16:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: On-demand ipsec tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43371#M31815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I control ours by a security policy using two external IP addresses, and disable/enable the security policy as needed. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 16:11:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43371#M31815</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2014-09-04T16:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: On-demand ipsec tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43372#M31816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could try something of the form,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* Configure your security policies such that only outgoing VPN connections are accepted.&lt;/P&gt;&lt;P&gt;* Configure the VPN as passive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you need the VPN, on the CLI use the 'test vpn ipsec-sa tunnel &amp;lt;name&amp;gt;' command to bring the session up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It may not work; but it would be what I'd try to achieve that...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2014 16:40:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43372#M31816</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-09-04T16:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: On-demand ipsec tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43373#M31817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I looking for is a "ON/OFF switch" for site to site IpSec tunnel.&lt;/P&gt;&lt;P&gt;Seem it's not possible neither in 6.0 nor in 6.1 ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx for all your answer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Nov 2014 13:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43373#M31817</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-11-12T13:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: On-demand ipsec tunnels?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43374#M31818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi SDorsey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN Tunnel is initiated in two circumstances.&lt;/P&gt;&lt;P&gt;1. In case of interested traffic. &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;Sorry for Cisco Jargon.&lt;/P&gt;&lt;P&gt;2. By using a Test vpn command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now it stays up until SAs life time. Cisco also behaves in exactly same way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a traffic than it stays up and remains up until SA expires. Inbetween if you want to terminate it than clear flows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please tell me more specific information on "On demand" word.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Nov 2014 14:09:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/on-demand-ipsec-tunnels/m-p/43374#M31818</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-11-12T14:09:14Z</dc:date>
    </item>
  </channel>
</rss>

