<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with IPSEC VPN with overlapping subnets in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-ipsec-vpn-with-overlapping-subnets/m-p/188861#M57256</link>
    <description>&lt;P&gt;Hey Rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I had followed the doc you linked before and it doesn't work. I did get this to work last week by adding a static route to 10.0.0.0 into the tunnel on my side. They also had to add a route for 10.0.1.0 into the tunnel on theirs.&lt;/P&gt;&lt;P&gt;I don't understand why I needed a route added to the tunnel for a local network but it worked and traffic is flowing correctly now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To summarize in case anyone comes across this&amp;nbsp;issue and needs it, see the changes in bold:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto Side:&lt;BR /&gt;&lt;BR /&gt;Source server: 192.168.100.20&lt;BR /&gt;Their Server: 192.168.100.85&lt;BR /&gt;&lt;BR /&gt;My server NAT address: 10.0.0.20&lt;BR /&gt;Their Server NAT address: 10.0.1.85&lt;BR /&gt;&lt;BR /&gt;I've configured a NAT rule that goes from Trust to Tunnel Zone:&lt;BR /&gt;&lt;BR /&gt;Dest Interface: Tunnel.10&lt;BR /&gt;Source IP: 192.168.100.20 all ports&lt;BR /&gt;Destination IP: 10.0.1.85 all ports&lt;BR /&gt;Source Translation Static NAT: 10.0.0.20&lt;BR /&gt;Bi-Directional NAT - Checked&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;My routes:&lt;/P&gt;&lt;P&gt;10.0.1.85/24 routed into Tunnel.10&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;10.0.0.20/24 routed into Tunnel.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Their routes:&lt;/P&gt;&lt;P&gt;10.0.0.20/24 routed into Tunnel.10&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;10.0.1.85/24 routed into Tunnel.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My firewall policies:&lt;BR /&gt;&lt;BR /&gt;Trust to Tunnel Zone:&lt;BR /&gt;Allow 192.168.100.20 to reach 10.0.1.85&lt;BR /&gt;Allow 10.0.0.20 to reach 10.0.1.85&lt;BR /&gt;&lt;BR /&gt;Tunnel to Trust Zone:&lt;BR /&gt;Allow 10.0.1.85 to reach 192.168.100.20&lt;BR /&gt;Allow 10.0.1.85 to reach 10.0.0.20&lt;BR /&gt;&lt;BR /&gt;Proxy IDs:&lt;BR /&gt;&lt;BR /&gt;Allow 10.0.0.20 to 10.0.1.85&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2017 20:19:31 GMT</pubDate>
    <dc:creator>portugueese</dc:creator>
    <dc:date>2017-11-27T20:19:31Z</dc:date>
    <item>
      <title>Help with IPSEC VPN with overlapping subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-ipsec-vpn-with-overlapping-subnets/m-p/187281#M57012</link>
      <description>&lt;P&gt;I'm working with a vendor to setup an IPSEC VPN but we have an overlapping host address. My side has a PA500 and their side is a Sonicwall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto Side:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source server: 192.168.100.20&lt;/P&gt;&lt;P&gt;Their Server: 192.168.100.85&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My server NAT address: 10.0.0.20&lt;/P&gt;&lt;P&gt;Their Server NAT address: 10.0.1.85&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've configured a NAT rule that goes from Trust to Tunnel Zone:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dest Interface: Tunnel.10&lt;/P&gt;&lt;P&gt;Source IP: 192.168.100.20 all ports&lt;/P&gt;&lt;P&gt;Destination IP: 10.0.1.85 all ports&lt;/P&gt;&lt;P&gt;Source Translation Static NAT: 10.0.0.20&lt;/P&gt;&lt;P&gt;Bi-Directional NAT - Checked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My firewall policies:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trust to Tunnel Zone:&lt;/P&gt;&lt;P&gt;Allow 192.168.100.20 to reach 10.0.1.85&lt;/P&gt;&lt;P&gt;Allow 10.0.0.20 to reach 10.0.1.85&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel to Trust Zone:&lt;/P&gt;&lt;P&gt;Allow 10.0.1.85 to reach 192.168.100.20&lt;/P&gt;&lt;P&gt;Allow 10.0.1.85 to reach 10.0.0.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Proxy IDs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Allow 10.0.0.20 to 10.0.1.85&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The vendor has said they did the same on their side and the VPN is up but I am only see 1 way communication. I can ping them from my server and the NAT works fine, but they can't reach my server at all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone run into this issue that could point me in the right direction? Any help is greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 21:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-ipsec-vpn-with-overlapping-subnets/m-p/187281#M57012</guid>
      <dc:creator>portugueese</dc:creator>
      <dc:date>2017-11-15T21:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Help with IPSEC VPN with overlapping subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-ipsec-vpn-with-overlapping-subnets/m-p/188683#M57228</link>
      <description>&lt;P&gt;hi mate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there is a link below with a tech doc on this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Configuring-route-based-IPSec-with-overlapping-networks/ta-p/53337" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Configuring-route-based-IPSec-with-overlapping-networks/ta-p/53337&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 00:42:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-ipsec-vpn-with-overlapping-subnets/m-p/188683#M57228</guid>
      <dc:creator>DonohoeRobert</dc:creator>
      <dc:date>2017-11-25T00:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Help with IPSEC VPN with overlapping subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-with-ipsec-vpn-with-overlapping-subnets/m-p/188861#M57256</link>
      <description>&lt;P&gt;Hey Rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I had followed the doc you linked before and it doesn't work. I did get this to work last week by adding a static route to 10.0.0.0 into the tunnel on my side. They also had to add a route for 10.0.1.0 into the tunnel on theirs.&lt;/P&gt;&lt;P&gt;I don't understand why I needed a route added to the tunnel for a local network but it worked and traffic is flowing correctly now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To summarize in case anyone comes across this&amp;nbsp;issue and needs it, see the changes in bold:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo Alto Side:&lt;BR /&gt;&lt;BR /&gt;Source server: 192.168.100.20&lt;BR /&gt;Their Server: 192.168.100.85&lt;BR /&gt;&lt;BR /&gt;My server NAT address: 10.0.0.20&lt;BR /&gt;Their Server NAT address: 10.0.1.85&lt;BR /&gt;&lt;BR /&gt;I've configured a NAT rule that goes from Trust to Tunnel Zone:&lt;BR /&gt;&lt;BR /&gt;Dest Interface: Tunnel.10&lt;BR /&gt;Source IP: 192.168.100.20 all ports&lt;BR /&gt;Destination IP: 10.0.1.85 all ports&lt;BR /&gt;Source Translation Static NAT: 10.0.0.20&lt;BR /&gt;Bi-Directional NAT - Checked&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;My routes:&lt;/P&gt;&lt;P&gt;10.0.1.85/24 routed into Tunnel.10&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;10.0.0.20/24 routed into Tunnel.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Their routes:&lt;/P&gt;&lt;P&gt;10.0.0.20/24 routed into Tunnel.10&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;10.0.1.85/24 routed into Tunnel.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My firewall policies:&lt;BR /&gt;&lt;BR /&gt;Trust to Tunnel Zone:&lt;BR /&gt;Allow 192.168.100.20 to reach 10.0.1.85&lt;BR /&gt;Allow 10.0.0.20 to reach 10.0.1.85&lt;BR /&gt;&lt;BR /&gt;Tunnel to Trust Zone:&lt;BR /&gt;Allow 10.0.1.85 to reach 192.168.100.20&lt;BR /&gt;Allow 10.0.1.85 to reach 10.0.0.20&lt;BR /&gt;&lt;BR /&gt;Proxy IDs:&lt;BR /&gt;&lt;BR /&gt;Allow 10.0.0.20 to 10.0.1.85&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 20:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-with-ipsec-vpn-with-overlapping-subnets/m-p/188861#M57256</guid>
      <dc:creator>portugueese</dc:creator>
      <dc:date>2017-11-27T20:19:31Z</dc:date>
    </item>
  </channel>
</rss>

