<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create a p2p tunnel from Palo Alto with static ip to Palo Alto with dhcp (with public ip) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186470#M56882</link>
    <description>&lt;P&gt;Hello BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have to postpone the migration 2 weeks, but I might be able to ask if we can install a spare laptop&amp;nbsp;@ location to do some testing next time during the migration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2017 15:54:47 GMT</pubDate>
    <dc:creator>fortigatefan</dc:creator>
    <dc:date>2017-11-10T15:54:47Z</dc:date>
    <item>
      <title>How to create a p2p tunnel from Palo Alto with static ip to Palo Alto with dhcp (with public ip)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186015#M56831</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for a way to get a site2site tunnel working between a Palo Alto with static public ip and a Palo Alto with a "dynamic" endpoint (public ip through dhcp)&lt;/P&gt;&lt;P&gt;The tunnel shows as status green in the GUI and also on CLI it shows up, but no traffic is passing. I found a how to through the Palo Alto pages, and I am using the User FQDN instead of ip peer address.&lt;/P&gt;&lt;P&gt;Do I need to use a proxy id between the 2 Palo Alto's or can I use static for the tunnel at both ends? Or perhaps both?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 16:33:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186015#M56831</guid>
      <dc:creator>fortigatefan</dc:creator>
      <dc:date>2017-11-08T16:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a p2p tunnel from Palo Alto with static ip to Palo Alto with dhcp (with public ip)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186051#M56840</link>
      <description>&lt;P&gt;Hi Mate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the traffic logs ?&lt;/P&gt;&lt;P&gt;is the traffic going down the tunnel when it should ?&lt;/P&gt;&lt;P&gt;have ye set a static route for the traffic thats needed to go down the tunnel?&lt;/P&gt;&lt;P&gt;Do you need nat traversal enabled?&lt;/P&gt;&lt;P&gt;Don't need the proxy id's. few links below should help ye research further.&amp;nbsp;&lt;/P&gt;&lt;P&gt;dynamic dds can help when you don't have a static address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Why-Use-a-VPN-Proxy-ID/ta-p/69524" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Why-Use-a-VPN-Proxy-ID/ta-p/69524&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/IPSec-VPN-Tunnel-with-NAT-Traversal/ta-p/66188" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/IPSec-VPN-Tunnel-with-NAT-Traversal/ta-p/66188&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-IPSec-VPN/ta-p/56535" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-IPSec-VPN/ta-p/56535&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/tac-p/59191#M985" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/tac-p/59191#M985&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Advanced-VPN-IPSec-troubleshooting-8-0-enable-debugging-per-VPN/ta-p/169303" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Advanced-VPN-IPSec-troubleshooting-8-0-enable-debugging-per-VPN/ta-p/169303&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/The-IPSEC-Tunnel-Comes-Up-But-Hosts-Behind-Peer-Are-Not/ta-p/61110" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/The-IPSEC-Tunnel-Comes-Up-But-Hosts-Behind-Peer-Are-Not/ta-p/61110&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 21:57:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186051#M56840</guid>
      <dc:creator>DonohoeRobert</dc:creator>
      <dc:date>2017-11-08T21:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a p2p tunnel from Palo Alto with static ip to Palo Alto with dhcp (with public ip)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186173#M56857</link>
      <description>&lt;P&gt;Hello Rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might have found the issue, as since the tunnels are basically inside to inside, the previous engineer didn't add a rule to allow zone internal/inside to internal/inside on the dynamic endpoint side/firewall. I will keep you posted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jeff.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 10:19:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186173#M56857</guid>
      <dc:creator>fortigatefan</dc:creator>
      <dc:date>2017-11-09T10:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a p2p tunnel from Palo Alto with static ip to Palo Alto with dhcp (with public ip)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186438#M56872</link>
      <description>&lt;P&gt;IP connectivity worked between several locations with static public ip and the site with dynamic public ip, however internal websites weren't reachable, whilst the external just worked fine (and outlook). I could reach the laptop from the engineer through RDP, and also the management ip of the Palo Alto was reachable through the GUI. The Palo Alto didn't block any http or https. The Palo Alto has a dhcp pool and 2 dns entries to serve the internal network. The local engineer could also ping the 2 dns ip's.&lt;/P&gt;&lt;P&gt;Although close to a solution, our timewindow ran out, so i had to do a rollback to the PFSense &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Will keep u posted on the progress.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 08:46:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186438#M56872</guid>
      <dc:creator>fortigatefan</dc:creator>
      <dc:date>2017-11-10T08:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a p2p tunnel from Palo Alto with static ip to Palo Alto with dhcp (with public ip)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186467#M56880</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76879"&gt;@fortigatefan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This should be a fairly straightforward configuration. It sounds like you were able to reach resources through the remote firewall, but the remote party was unable to access resources through your own firewall correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that's the case you'll need to verify a couple things.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) There is a security policy in place that actually allows the remote users to access your local resources through the tunnel on both your remote firewall and the local firewall. It sounds like you may have allowed the traffic through to the remote end, but you aren't allowing that remote end through the terminating firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Have you tried reaching these internal sites strickly through IP instead of DNS? You may have allowed HTTP/HTTPS through the firewall, but if the remote locations DNS server doesn't know to point these users to your internal webserver then it's just going to send them out to the external website.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding a little bit of the configuration from both ends might help a little in further troubleshooting, but that's where I would start looking.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 15:29:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186467#M56880</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-11-10T15:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a p2p tunnel from Palo Alto with static ip to Palo Alto with dhcp (with public ip)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186470#M56882</link>
      <description>&lt;P&gt;Hello BPry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have to postpone the migration 2 weeks, but I might be able to ask if we can install a spare laptop&amp;nbsp;@ location to do some testing next time during the migration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 15:54:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-a-p2p-tunnel-from-palo-alto-with-static-ip-to-palo/m-p/186470#M56882</guid>
      <dc:creator>fortigatefan</dc:creator>
      <dc:date>2017-11-10T15:54:47Z</dc:date>
    </item>
  </channel>
</rss>

