<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Proxy ID in SA? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/121526#M46060</link>
    <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have site to site VPN between HQ PA and branch PA. I used the proxy id on HQ as Local: 172.16.110.0/24 remote: 10.10.10.0/24 and everything is working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now brach office need to access another subnet in HQ that is 172.16.111.0/24. In this case I have to create one more proxy id on both side or just allowing this new subnet in appropriate policies and proper route towards tunnel interface is enough?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My main point is proxy-id is just the parameter to match on both sides while negotiating IPSEC or its has anything to do with actual traffic passing through IPSEC?&lt;/P&gt;</description>
    <pubDate>Wed, 26 Oct 2016 16:38:19 GMT</pubDate>
    <dc:creator>ghostrider</dc:creator>
    <dc:date>2016-10-26T16:38:19Z</dc:date>
    <item>
      <title>Proxy ID in SA?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/121526#M46060</link>
      <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have site to site VPN between HQ PA and branch PA. I used the proxy id on HQ as Local: 172.16.110.0/24 remote: 10.10.10.0/24 and everything is working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now brach office need to access another subnet in HQ that is 172.16.111.0/24. In this case I have to create one more proxy id on both side or just allowing this new subnet in appropriate policies and proper route towards tunnel interface is enough?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My main point is proxy-id is just the parameter to match on both sides while negotiating IPSEC or its has anything to do with actual traffic passing through IPSEC?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 16:38:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/121526#M46060</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-26T16:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ID in SA?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/121546#M46063</link>
      <description>&lt;P&gt;From multiple support cases I've had with TAC on IPSec tunnels on PAs. &amp;nbsp;If the tunnel exists between two PAs Proxy IDs aren't necessary.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 18:50:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/121546#M46063</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-10-26T18:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ID in SA?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/121554#M46065</link>
      <description>&lt;P&gt;Ahh .. Agreed with Brandon. I thought the tunnel is between PA and third party firewall.&amp;nbsp;More info here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Why-use-a-VPN-proxy-ID/ta-p/69524" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Why-use-a-VPN-proxy-ID/ta-p/69524&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 19:33:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/121554#M46065</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-10-26T19:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ID in SA?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/121996#M46094</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So between PA, if proxy-id is local: 10.0.0.0/8 and remote: 172.16.1.0/24 and tunnel is established. Now I need to pass another remote subnet 172.16.2.0/24 then in this case, I do not need to add another proxy-id for 172.16.2.0/24? Just appropirate policy and route towards tunnel for 172.16.2.0/24 is enough?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 10:48:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/121996#M46094</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-28T10:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ID in SA?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/122033#M46096</link>
      <description>&lt;P&gt;It's my understanding that zero proxy-ids are necessary for a PA-PA VPN connection. &amp;nbsp;the PA leverages the routing in your VR to define what traffic brings up your tunnel.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 13:20:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-in-sa/m-p/122033#M46096</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-10-28T13:20:30Z</dc:date>
    </item>
  </channel>
</rss>

