<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to route internet traffic through a tunnel interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46097#M33862</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...You configured 2 things here: 'set the default route (0.0.0.0) to the tunnel interface, and set the next hop to the gateway for the tunnel interface.'&amp;nbsp; I would recommend testing only one: set the default route 0.0.0.0/0 to the tunnel interface and leave the next hop at &amp;lt;none&amp;gt;.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Feb 2012 15:59:12 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-02-06T15:59:12Z</dc:date>
    <item>
      <title>How to route internet traffic through a tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46093#M33858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What's the best way to route all internet traffic (except IPSec VPN tunnels) through a IPSec VPN tunnel interface?&lt;/P&gt;&lt;P&gt;We want to have a single point where all internet traffic passes through and uses the same policies for web and applications.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2012 11:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46093#M33858</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2012-02-03T11:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to route internet traffic through a tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46094#M33859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...You can try defining a default route and set the next-hop to be the tunnel interface.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2012 15:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46094#M33859</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-03T15:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to route internet traffic through a tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46095#M33860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've already tried to set the default route (0.0.0.0) to the tunnel interface, and set the next hop to the gateway for the tunnel interface. But it seems like this configuration is not working with the logic/processing flowchart of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the remote PA firewall I've added a rule from the VPN zone to Untrust and NAT rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another possible solution is to add static routes to the remote IP of the firewall with a next hop to the gateway, and then route default gateway through the tunnel. I haven't had chance to try this out as this is in a production environment. Anyone have a lab setup they could test this? Or even better, anyone else actually routing default gateway through a tunnel interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 07:32:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46095#M33860</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2012-02-06T07:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to route internet traffic through a tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46096#M33861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your previous mail, you said :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another possible solution is to add static routes to the remote IP of the firewall with a next hop to the gateway, and then route default gateway through the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, that's the only way to solve your issue !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this config, it should work...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hedi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 07:37:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46096#M33861</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-02-06T07:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to route internet traffic through a tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46097#M33862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...You configured 2 things here: 'set the default route (0.0.0.0) to the tunnel interface, and set the next hop to the gateway for the tunnel interface.'&amp;nbsp; I would recommend testing only one: set the default route 0.0.0.0/0 to the tunnel interface and leave the next hop at &amp;lt;none&amp;gt;.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 15:59:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46097#M33862</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-02-06T15:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to route internet traffic through a tunnel interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46098#M33863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi. Not work for PPoE with static address (other in default). Any idea? Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Sep 2012 17:45:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-route-internet-traffic-through-a-tunnel-interface/m-p/46098#M33863</guid>
      <dc:creator>hsnetworks01</dc:creator>
      <dc:date>2012-09-30T17:45:54Z</dc:date>
    </item>
  </channel>
</rss>

