<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN between 3 sites in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/95218#M43962</link>
    <description>&lt;P&gt;Hi Javier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you elaborate on what exactly you need&amp;nbsp;assistance ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you try setting up a specific configuration which didn't work or are you wondering if it is conceptually possible ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use siteA as a hub by making sure each remote site has routes for the other remote site's subnet pointing at the tunnel interface, and possibly have matching proxyIDs so each site knows it needs to put traffic destined for the other site into the HQ tunnel, then simply set security policies on the HQ site to allow the traffic&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jul 2016 09:44:10 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-07-07T09:44:10Z</dc:date>
    <item>
      <title>VPN between 3 sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/95063#M43958</link>
      <description>&lt;P&gt;VPN Site to Site&lt;/P&gt;&lt;P&gt;I have communication between site A and site B or site A and Site C, but I have not communication between B y C through A&lt;BR /&gt;Site A (headquarters )&lt;BR /&gt;Site B (Windows Azure)&lt;BR /&gt;Site C (Bank)&lt;BR /&gt;The required communication is the site B to contact C through A.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Can you help me please&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 04:55:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/95063#M43958</guid>
      <dc:creator>javier.brito</dc:creator>
      <dc:date>2016-07-07T04:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between 3 sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/95218#M43962</link>
      <description>&lt;P&gt;Hi Javier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you elaborate on what exactly you need&amp;nbsp;assistance ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you try setting up a specific configuration which didn't work or are you wondering if it is conceptually possible ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use siteA as a hub by making sure each remote site has routes for the other remote site's subnet pointing at the tunnel interface, and possibly have matching proxyIDs so each site knows it needs to put traffic destined for the other site into the HQ tunnel, then simply set security policies on the HQ site to allow the traffic&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 09:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/95218#M43962</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-07-07T09:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between 3 sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/95304#M43963</link>
      <description>&lt;P&gt;I m sorry&amp;nbsp; accept the solution by mistake&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Give me 30 minutes to send more details&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 13:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/95304#M43963</guid>
      <dc:creator>javier.brito</dc:creator>
      <dc:date>2016-07-07T13:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between 3 sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/95382#M43968</link>
      <description>&lt;P&gt;I have a VPN between site "B" and site "A" and and it is working properly&lt;BR /&gt;I have a VPN between site "C" and site "A" and and it is working properly&lt;/P&gt;&lt;P&gt;The problem was that when you send a ping site "B" to site "C" trough site A it did not responded to this&lt;/P&gt;&lt;P&gt;your comments helped me solve the problem.&lt;BR /&gt;I share the details of the solution&lt;BR /&gt;Thank you&lt;/P&gt;&lt;P&gt;Site B&lt;BR /&gt;Firewall Juniper SSG5&lt;BR /&gt;LAN: 192.168.51.0/24&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Site C&lt;BR /&gt;Firewall: PA200&lt;BR /&gt;LAN: 192.168.20.0/20&lt;/P&gt;&lt;P&gt;site A&lt;BR /&gt;Firewall: PA 3020&lt;BR /&gt;172.16.16.0/20&lt;/P&gt;&lt;P&gt;Routing B&lt;BR /&gt;set route 172.16.16.0/20 interface tunnel.1&lt;BR /&gt;set route 192.168.20.0/24 interface tunnel.1&lt;/P&gt;&lt;P&gt;Policies B&lt;BR /&gt;set policy id 3 from "Trust" to "Untrust" "192.168.51.0/24" "172.16.16.0/20" "ANY"&lt;BR /&gt;set policy id 3 from "Trust" to "Untrust" "192.168.51.0/24" "192.168.20.0/24" "ANY"&lt;/P&gt;&lt;P&gt;set policy id 4 from "Untrust" to "Trust" "172.16.16.0/20" "192.168.51.0/20" "ANY"&lt;BR /&gt;set policy id 4 from "Untrust" to "Trust" "192.168.20.0" "192.168.51.0/20" "ANY"&lt;/P&gt;&lt;P&gt;Routing C&lt;/P&gt;&lt;P&gt;destination nexthop metric flags age interface next-AS&lt;BR /&gt;172.16.16.0/20 0.0.0.0 10 A S tunnel.1&lt;BR /&gt;192.168.51.0/24 0.0.0.0 10 A S tunnel.1&lt;/P&gt;&lt;P&gt;Policies C&lt;/P&gt;&lt;P&gt;Site A and B TO site C {&lt;BR /&gt;from Untrust;&lt;BR /&gt;source [ 172.16.16.0/20 192.168.51.0/24 ];&lt;BR /&gt;source-region none;&lt;BR /&gt;to Trust;&lt;BR /&gt;destination 192.168.20.0/24;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service any/any/any/any;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;/P&gt;&lt;P&gt;Routing A&lt;/P&gt;&lt;P&gt;destination nexthop metric flags age interface next-AS&lt;BR /&gt;192.168.51.0/24 0.0.0.0 10 A S tunnel.6&lt;BR /&gt;192.168.20.0/24 0.0.0.0 10 A S tunnel.7&lt;/P&gt;&lt;P&gt;Policies A&lt;/P&gt;&lt;P&gt;Site B-Site C {&lt;BR /&gt;from untrust;&lt;BR /&gt;source 192.168.51.0/24;&lt;BR /&gt;source-region none;&lt;BR /&gt;to untrust;&lt;BR /&gt;destination 192.168.20.0/24;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service any/any/any/any;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Site B-Site A {&lt;BR /&gt;from untrust;&lt;BR /&gt;source 192.168.51.0/24;&lt;BR /&gt;source-region none;&lt;BR /&gt;to trust;&lt;BR /&gt;destination 172.16.16.0/20;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service any/any/any/any;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;Site C- Site A {&lt;BR /&gt;from untrust;&lt;BR /&gt;source 192.168.20.0/24;&lt;BR /&gt;source-region none;&lt;BR /&gt;to trust;&lt;BR /&gt;destination 172.16.16.0/20;&lt;BR /&gt;destination-region none;&lt;BR /&gt;user any;&lt;BR /&gt;category any;&lt;BR /&gt;application/service any/any/any/any;&lt;BR /&gt;action allow;&lt;BR /&gt;icmp-unreachable: no&lt;BR /&gt;terminal yes;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 16:50:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/95382#M43968</guid>
      <dc:creator>javier.brito</dc:creator>
      <dc:date>2016-07-07T16:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between 3 sites</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/96141#M43999</link>
      <description>&lt;P&gt;Is your issue solved? &amp;nbsp;If not:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what you list here, it looks like the VPN from B will not allow traffic with an ip address of C to enter the tunnel and the same seems to be the case in reverse. &amp;nbsp;Your tunnels only seem to capture traffic for the A subnet to these sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There would be two basic options:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1-add the missing subnet to both tunnels (proxy-id pairs) so that traffic will be accepted by the tunnels and forwarded through both. &amp;nbsp;This requries changes to all three VPN setups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2-NAT the traffic between B and C. &amp;nbsp;On the side where the sesssion is initiated NAT the destination to an available address at site A. &amp;nbsp;On site A NAT this address back to the original for the site and forward it on to the existing tunnel.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2016 10:49:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-between-3-sites/m-p/96141#M43999</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-07-10T10:49:45Z</dc:date>
    </item>
  </channel>
</rss>

