<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I can reach a subnet trough a tunnel without proxy ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171049#M54155</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Could you explain the point with the performance advantages with proxy IDs?&lt;/P&gt;</description>
    <pubDate>Thu, 10 Aug 2017 16:02:17 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-08-10T16:02:17Z</dc:date>
    <item>
      <title>I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/170986#M54139</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´m having a strange behavior after configuring an IPSec tunnel, the situation is that I can ping a subnet trough the&amp;nbsp;tunnel which hasn´t a proxy ID. This subnet has an entry in the virtual router and the tunnel interface points to it, there´s also a&lt;BR /&gt;security policy which allows this traffic but as far as I know if this subnet has no&amp;nbsp;proxy ID the communication trough the tunnel wouldn´t be possible. In summary:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To reach the subnet A.B.C.X trough an IPSec tunnel I configured:&lt;BR /&gt;- IPSec tunnel (IKE Gateway, IPSec Crypto Profile, tunnel interface, ---&amp;gt; Proxy ID)&lt;BR /&gt;- Security rule&lt;BR /&gt;- virtual router&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The strange behavior is that I can ping a subnet A.B.C.Y trough the same tunnel, but there isnt ProxyID for this subnet in the tunnel, only a route in the virtual router with the tunnel interface pointing to the subnet A.B.C.Y&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas about why this may be happening??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance,&lt;/P&gt;&lt;P&gt;Marcos.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 10:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/170986#M54139</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2017-08-10T10:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/170994#M54140</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PAN-OS version?&lt;/LI&gt;&lt;LI&gt;IKEv1 or v2?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you already have one proxy ID configured and traffic is also flowing between subnets without proxy ID? Did you check the tunnel status and the IPSec SAs on the cli to see what phase 2 tunnel is established?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 11:37:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/170994#M54140</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-10T11:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/170995#M54141</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA uses interface (route-based) to encrypt all traffic or going into the tunnel. Proxy IDs are needed to establish P2 and if peer side is policy-based VPN FW/Router. Is your peer configured for policy or route based VPN?&amp;nbsp;&lt;/P&gt;&lt;P&gt;You still have an option to deny that traffic with the security policy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 11:41:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/170995#M54141</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-10T11:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171013#M54145</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Whatever your peer is appears to also be a route based system, which means you don't really&amp;nbsp;&lt;EM&gt;need&lt;/EM&gt; proxy IDs. My current list of route-based is&amp;nbsp;&lt;STRONG&gt;Firewalls that support route-based Firewalls: Palo Alto Firewalls, Juniper SRX, Juniper Netscreen, and Checkpoint&amp;nbsp;&lt;/STRONG&gt;but there could be more that I simply haven't come across yet.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 13:42:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171013#M54145</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-10T13:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171021#M54147</link>
      <description>&lt;P&gt;Yes, with route based VPN Proxy IDs aren't needed but if you do have one configured, there shouldn't be an SA in addition to the configured proxy ID. Of course route based with 0.0.0.0/0 is the best way to configure it, but thats, as I understood, not the point.&lt;/P&gt;&lt;P&gt;And because of the described situation I assume &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;uses IKEv2&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 14:35:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171021#M54147</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-10T14:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171047#M54153</link>
      <description>&lt;P&gt;As mentioned you don't need Proxy ID with Palo.&lt;/P&gt;&lt;P&gt;If you leave it blank it will still send it over but in form of 0.0.0.0/0&lt;/P&gt;&lt;P&gt;If you want to seperate different subnet traffic into different tunnels you can still use Proxy ID with between 2 route based VPN devices also as it might give some performance advantages &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 15:55:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171047#M54153</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-08-10T15:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171048#M54154</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thank you all for answering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´m using IKEv1 with route-based peers, thank to your answers I can confirm that I don´t need Proxy IDs for this scenario.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks and Regards,&lt;BR /&gt;Marcos.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 15:56:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171048#M54154</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2017-08-10T15:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171049#M54155</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Could you explain the point with the performance advantages with proxy IDs?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 16:02:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171049#M54155</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-10T16:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171051#M54156</link>
      <description>&lt;P&gt;Different SA associations can be processed by different CPUs in the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 16:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171051#M54156</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-08-10T16:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171052#M54157</link>
      <description>&lt;P&gt;Ah ok, so only something to consider with the bigger PA series &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 16:06:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171052#M54157</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-10T16:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171061#M54160</link>
      <description>&lt;P&gt;I would not worry about it yes.&lt;/P&gt;&lt;P&gt;With PA200 and single core does not have any reason.&lt;/P&gt;&lt;P&gt;Also low vpn volume is not worth effort to play with ProxyID.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 16:12:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171061#M54160</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-08-10T16:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: I can reach a subnet trough a tunnel without proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171063#M54162</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Am I right that this only matters starting with the 5000 series and for example on a 5050 is you have more than 2 Gbps of IPsec traffic (-&amp;gt; more than half of the platform max IPsec throughput of 4 Gbps) and all this in one VPN connection&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 16:29:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-can-reach-a-subnet-trough-a-tunnel-without-proxy-id/m-p/171063#M54162</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-10T16:29:57Z</dc:date>
    </item>
  </channel>
</rss>

