<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practices for Site-to-Site IP/Interfaces? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165860#M53241</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Anothing thing to think about when using zones, is that you can have one VPN zone and still seperate the traffic by IP address's. This way you dont run low on zones or try to keep them all seperated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i.e.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source IP range x.x.x.x/x zone VPN&lt;/P&gt;&lt;P&gt;Source IP range y.y.y.y/y zone VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you would like me to expand on that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jul 2017 15:37:59 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2017-07-11T15:37:59Z</dc:date>
    <item>
      <title>Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/164717#M53094</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've currently got a site-to-site VPN tunnel already configured for one of our cloud services but we've got a request to add another service from another provider. &amp;nbsp;Our current config has a single floating IP address with the associated tunnel configuration and assigned to a "Site-to-Site" security zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering what best practices are concerning multiple site-to-site configurations. &amp;nbsp;I've already started creating separate Crypto configs and, obviously, I'll need a separate actual IPSec Tunnel config. &amp;nbsp;What I'm wondering is if it is best practicles to re-use the same public floating IP, loopback, tunnel interface, etc. or is best practices or common just to create a whole new setup?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 18:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/164717#M53094</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-07-05T18:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/164727#M53096</link>
      <description>&lt;P&gt;I keep the public IP the same, other than that I modify everything else specific to that tunnel besides the zone as I have one IPSec zone that terminates all site-to-sites. I'm not sure if that is really the 'proper' way to do it but I find it easy enough to manage and it hasn't given me any issues so far.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 18:13:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/164727#M53096</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-05T18:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/164749#M53100</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;so you keep the public IP and the associated virtual loopback interface the same but create a new virtual tunnel interface (configured with no IP... just used in the IPSec Tunnel config)?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 19:11:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/164749#M53100</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-07-05T19:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/164750#M53101</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39461"&gt;@jsalmans&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I actually don't use the loopback interface and assign the tunnel interface a private IP address strictly for monitoring. The tunnels all have one shared local public IP address. I imagine that you could do the same thing without issue utilizing the loopback instead.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 19:23:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/164750#M53101</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-05T19:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165055#M53128</link>
      <description>&lt;P&gt;You can have a single public IP that represents your systems and then have this IP address as the "local-address" crossing into multiple VPN tunnels. &amp;nbsp;Each site-to-site VPN tunnel should terminate into it's own interface and it's own zone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tunnel.1 = zone VPN-PartnerName1&lt;/P&gt;&lt;P&gt;tunnel.2 = zone VPN-PartnerName2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This allows you to write specific security rules and NAT rules that match your traffic. &amp;nbsp;This gives you full control over each tunnel and won't allow traffic to cross from tunnel to tunnel. &amp;nbsp;Putting them into a single zone could allow the u-turn or hair-pin type traffic and could allow VPN to VPN flows (inadvertently).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each VPN tunnel will have a Phase2 configuration (IPSec Tunnels in the PA). &amp;nbsp;On the PROXY-ID's tab, this is where you create your interesting traffic list (think crypto map for vendor VPN's). &amp;nbsp;Your Local entry will be the public "local-address" (from above) and the Remote will be the unique IP address that your VPN partner is using. &amp;nbsp;This is what allows you to re-use your single IP into mutiple tunnels.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 19:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165055#M53128</guid>
      <dc:creator>davanderson</dc:creator>
      <dc:date>2017-07-06T19:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165193#M53148</link>
      <description>&lt;P&gt;Thanks for the feedback guys. &amp;nbsp;I have the loopback involved mainly because it is tied to a floating IP since we're running A/A.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had originally thought to do all Site-to-Site as the same zone and do the policy rules all according to IP addresses but I can definitely see how having them in separate zones will make things a little clearer and provide an extra layer of functionality against accidental or unintended traffic flow.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 13:27:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165193#M53148</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-07-07T13:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165221#M53155</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39461"&gt;@jsalmans&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not sure of your platform but before you start assigning every single site-to-site a new security zone specific to that tunnel I would look at your max zone capability and how many tunnels you actually plan on forming during the expected lifetime of your firewalls. I've had to help a few people cut zone count retroactively because they haven't thought about it being a ceiling for them, it's not a very fun process.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 14:23:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165221#M53155</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-07T14:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165223#M53157</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're on the PAN-5060 platform. &amp;nbsp;It looks like it supports 900 security zones and we've only got 10 or so now I think.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 14:27:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165223#M53157</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-07-07T14:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165224#M53158</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39461"&gt;@jsalmans&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Sweet that should be good to go then. Some of the smaller firewalls have insanely limited zone counts where you could easily hit the max if you start setting up site-to-sites like this. Once you get past the 3000 series it really becomes a non-issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 14:31:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165224#M53158</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-07T14:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165860#M53241</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Anothing thing to think about when using zones, is that you can have one VPN zone and still seperate the traffic by IP address's. This way you dont run low on zones or try to keep them all seperated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i.e.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source IP range x.x.x.x/x zone VPN&lt;/P&gt;&lt;P&gt;Source IP range y.y.y.y/y zone VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you would like me to expand on that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 15:37:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165860#M53241</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-07-11T15:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Site-to-Site IP/Interfaces?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165895#M53246</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;for the info.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is actually how I was originally planning on doing it but I ended up liking the suggesting of creating security zones for the other site-to-site configs we add. &amp;nbsp;They can all use the same public IP (and associated loopback that I use for the floating IP HA part) and then everything else is different. &amp;nbsp;I feel like this gives me some extra control and options when designing security policy and with 900 maximum security zones on our platform I don't have to worry about running out any time soon.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 17:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-practices-for-site-to-site-ip-interfaces/m-p/165895#M53246</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2017-07-11T17:41:13Z</dc:date>
    </item>
  </channel>
</rss>

