<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Proxy id between Palo Alto firewall and Cisco ASA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/122011#M46095</link>
    <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA side there are two subnets: 10.0.1.0/24, 10.0.2.0/24 and Cisco side there are also three subnets 172.16.1.0/24 , 172.16.2.0/24.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On PA firewall, I defined the proxy-id as below:&lt;/P&gt;&lt;P&gt;proxy-id1: local:&amp;nbsp;&lt;SPAN&gt;10.0.1.0/24 remote:&amp;nbsp;172.16.1.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;proxy-id2: local:&amp;nbsp;&lt;SPAN&gt;10.0.1.0/24 remote:&amp;nbsp;172.16.2.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;proxy-id3: local:&amp;nbsp;&lt;SPAN&gt;10.0.1.0/24 remote:&amp;nbsp;172.16.1.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;proxy-id4: local:&amp;nbsp;&lt;SPAN&gt;10.0.1.0/24 remote:&amp;nbsp;172.16.2.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;My questions are:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;1- On Cisco side, how I will define the ACL. I mean I will define the four ACL or only one ACL with two source and two destination?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;2- Everytime, if new subnet is added to pass through tunnel. I need to create proxy-id. There is any scalable method for this?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;GR&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Oct 2016 11:17:34 GMT</pubDate>
    <dc:creator>ghostrider</dc:creator>
    <dc:date>2016-10-28T11:17:34Z</dc:date>
    <item>
      <title>Proxy id between Palo Alto firewall and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/122011#M46095</link>
      <description>&lt;P&gt;Hello Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA side there are two subnets: 10.0.1.0/24, 10.0.2.0/24 and Cisco side there are also three subnets 172.16.1.0/24 , 172.16.2.0/24.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On PA firewall, I defined the proxy-id as below:&lt;/P&gt;&lt;P&gt;proxy-id1: local:&amp;nbsp;&lt;SPAN&gt;10.0.1.0/24 remote:&amp;nbsp;172.16.1.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;proxy-id2: local:&amp;nbsp;&lt;SPAN&gt;10.0.1.0/24 remote:&amp;nbsp;172.16.2.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;proxy-id3: local:&amp;nbsp;&lt;SPAN&gt;10.0.1.0/24 remote:&amp;nbsp;172.16.1.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;proxy-id4: local:&amp;nbsp;&lt;SPAN&gt;10.0.1.0/24 remote:&amp;nbsp;172.16.2.0/24&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;My questions are:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;1- On Cisco side, how I will define the ACL. I mean I will define the four ACL or only one ACL with two source and two destination?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;2- Everytime, if new subnet is added to pass through tunnel. I need to create proxy-id. There is any scalable method for this?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;GR&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2016 11:17:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/122011#M46095</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-28T11:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy id between Palo Alto firewall and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/122207#M46117</link>
      <description>&lt;P&gt;Palo does not care about Proxy ID because it uses routing table to decide where to send traffic (route based vpn).&lt;/P&gt;&lt;P&gt;But as to negotiate IPSec configuration needs to match at both sides so Proxy ID in Palo is just to make Cisco happy.&lt;/P&gt;&lt;P&gt;Cisco on the other hand uses policy based vpn and encryption domains there are used to decide if traffic should be routed into tunnel or not.&lt;/P&gt;&lt;P&gt;So yes you have to have all subnets added to Proxy ID to have traffic flowing.&lt;/P&gt;&lt;P&gt;5 subnets at both sides for example means 25 Proxy ID's -&amp;gt; 5x5.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2016 03:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/122207#M46117</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-10-29T03:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy id between Palo Alto firewall and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/122281#M46126</link>
      <description>&lt;P&gt;Hi Raido&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your valueable feedback. I heard in IKEV2, there is some concept of superset like on PA if I define 10/8 and remote as 172.16/16. Can we do something like that? or it is something else&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2016 15:18:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/122281#M46126</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-10-29T15:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy id between Palo Alto firewall and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/123253#M46213</link>
      <description>&lt;P&gt;I have not used IKEV2 so maybe someone who has can help here.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 14:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/123253#M46213</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-11-02T14:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy id between Palo Alto firewall and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/124339#M46299</link>
      <description>&lt;P&gt;Any one here for IKEV2 explaination?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Nov 2016 15:06:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-id-between-palo-alto-firewall-and-cisco-asa/m-p/124339#M46299</guid>
      <dc:creator>ghostrider</dc:creator>
      <dc:date>2016-11-05T15:06:49Z</dc:date>
    </item>
  </channel>
</rss>

