<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA to PaloAlto VPN conversion in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50498#M37184</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understand that the vpn's could not be active until we get off of VWire mode, but we are a hospital operating 24/7 with data continually being sent over these tunnels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to have these tunnels generated on the PaloAlto in advance of moving off of VWire so that when I move the cables over to production these tunnels go live with a minimum of effort.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Randy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Aug 2013 11:14:04 GMT</pubDate>
    <dc:creator>rswauger</dc:creator>
    <dc:date>2013-08-07T11:14:04Z</dc:date>
    <item>
      <title>Cisco ASA to PaloAlto VPN conversion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50496#M37182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone developed step by step instructions for migrating site to site VPN's from a Cisco ASA to a PaloAlto 2050?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have approximately 30 VPN's to convert and currently running in VWire mode so all the VPN's will need to be added prior to moving off VWire and eliminating the Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated as far as best practices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 19:05:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50496#M37182</guid>
      <dc:creator>rswauger</dc:creator>
      <dc:date>2013-08-06T19:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA to PaloAlto VPN conversion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50497#M37183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please contact your Sales Engineer or the Dev Centre team to assist you with the migration. In order for you to run the VPNs on the PANFW, you have to convert the vwire to layer 3 interface mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 19:17:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50497#M37183</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-06T19:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA to PaloAlto VPN conversion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50498#M37184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understand that the vpn's could not be active until we get off of VWire mode, but we are a hospital operating 24/7 with data continually being sent over these tunnels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to have these tunnels generated on the PaloAlto in advance of moving off of VWire so that when I move the cables over to production these tunnels go live with a minimum of effort.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Randy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Aug 2013 11:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50498#M37184</guid>
      <dc:creator>rswauger</dc:creator>
      <dc:date>2013-08-07T11:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA to PaloAlto VPN conversion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50499#M37185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning Randy,&lt;/P&gt;&lt;P&gt;You can configure multiple tunnel sub interface for each of the VPNs, assign them to a zone ( like VPN zone ), and configure routes for the remote networks behind each peer, via these tunnel sub interfaces. If the ASA is configured with the&amp;nbsp; Virtual tunnel interfaces ( to use route based VPNs ), the migration should be pretty simple.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You then have to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) Configure the untrust interface on the PANFW, through which the firewall will establish the tunnel, and transmit and receives the ESP packets. Configure a policy from untrust to untrust, permitting applications ike, ipsec ( and ciscovpn if the remote peers happen to be ASA devices )&lt;/P&gt;&lt;P&gt;b) Configure the trust interface/interfaces from where the internal hosts at the PANFW side are reachable on. Configure polices from Trust to VPN and also from VPN to Trust&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Aug 2013 12:33:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50499#M37185</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-07T12:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA to PaloAlto VPN conversion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50500#M37186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can refer to the below link, explaining the VPN configuration. You can also search our documentation on VPN configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1163"&gt;https://live.paloaltonetworks.com/docs/DOC-1163&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Aug 2013 12:57:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-asa-to-paloalto-vpn-conversion/m-p/50500#M37186</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-07T12:57:27Z</dc:date>
    </item>
  </channel>
</rss>

