<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How many IPSEC VPN peers can PA-5220 handle ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206556#M60609</link>
    <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;, for your prompt reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per your clarification then, when my batch of 3000 IKE peers have transitioned into phase-2(ipsec) , then I can have 3000 more(and different) IKE peers ?&lt;/P&gt;&lt;P&gt;Can I deploy 3xPA-3020 in cluster, I think they support max 2 units. Correct me if I am wrong !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Again for your valuable inputs !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bhushit Dave&lt;/P&gt;</description>
    <pubDate>Tue, 20 Mar 2018 13:38:05 GMT</pubDate>
    <dc:creator>bhushitda</dc:creator>
    <dc:date>2018-03-20T13:38:05Z</dc:date>
    <item>
      <title>How many IPSEC VPN peers can PA-5220 handle ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206514#M60597</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having a scenario where we are supporting various vendors through IPSEC VPN and we were using Cisco ASA 5585-X for that.&lt;/P&gt;&lt;P&gt;The problem is we are nearing the 4000 total active tunnels now and ASA is facing some issues handling that much tunnels, so we are thinking to migrate these tunnels to PA-5220.&lt;/P&gt;&lt;P&gt;Now when I reffered to the data sheet of PA-5220, it shows the following :&lt;/P&gt;&lt;P&gt;IPSec VPN:&lt;/P&gt;&lt;P&gt;Site to site&amp;nbsp; -- 10,000&lt;/P&gt;&lt;P&gt;Max IKE Peers -- 3000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that mean it can&amp;nbsp; olny support 3000 IKE peers ?&lt;/P&gt;&lt;P&gt;Also, please let me know which model can support around 5000 simultaneous IPSEC site-to-site tunnels.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 08:08:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206514#M60597</guid>
      <dc:creator>bhushitda</dc:creator>
      <dc:date>2018-03-20T08:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: How many IPSEC VPN peers can PA-5220 handle ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206522#M60599</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85238"&gt;@bhushitda&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least this means that PaloAlto officially supports "only" 3000 ike peers. You can have a lot more IPSec phase 2 tunnels, this is what the number at "site to site vpn tunnels" mean.&lt;/P&gt;&lt;P&gt;The PA-5260 supports 5000 ike peers. Or you could go with 3xPA-3020 (probably less expensive than a PA-5260). The PA-3020 supports up to 2000 ike peers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 08:33:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206522#M60599</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-20T08:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: How many IPSEC VPN peers can PA-5220 handle ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206556#M60609</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;, for your prompt reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per your clarification then, when my batch of 3000 IKE peers have transitioned into phase-2(ipsec) , then I can have 3000 more(and different) IKE peers ?&lt;/P&gt;&lt;P&gt;Can I deploy 3xPA-3020 in cluster, I think they support max 2 units. Correct me if I am wrong !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Again for your valuable inputs !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bhushit Dave&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 13:38:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206556#M60609</guid>
      <dc:creator>bhushitda</dc:creator>
      <dc:date>2018-03-20T13:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: How many IPSEC VPN peers can PA-5220 handle ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206563#M60612</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85238"&gt;@bhushitda&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With route based vpn (phase 2 between 0.0.0.0/0 and 0.0.0.0/0) you have one "site to site vpn tunnel" per ike gateway.&lt;/P&gt;&lt;P&gt;If route based isn't possible and a peer requires policy based then you need to configure proxy IDs in the ipsec tunnel configuration. These IPsec configurarions are bound to an ike gateway but per ipsec tunnel configuration you can have up to 30 proxy IDs (not absolutely sure about that). So this way you could have 30 "site to site vpn tunnels" with only one ike gateway/peer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;About the 3020s: no you cannot have a 3 node cluster. I was mentionning this because of the costs. If you want a HA setup you need 6xPA-3020, which means three independent clusters (active active I would NOT recommend here because if you have 2000 one one node and 2000 on the second node you will have issues with 2000 tunnels when there is a problem with one node or in case of updates).&lt;/P&gt;&lt;P&gt;But this solution allows you to grow over time --&amp;gt; simply buy a new cluster&amp;nbsp;when you need it instead of a 5260 cluster right now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to have ALL connections on one firewall (cluster) then the PA-5260 is your only option. The PA-7080 "only" supports up to 8000 ike peers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 14:33:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206563#M60612</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-20T14:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: How many IPSEC VPN peers can PA-5220 handle ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206667#M60639</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since all my tunnels are policy-based, I must have 5000 IKE peers able to negotiate and connect with the device.&lt;/P&gt;&lt;P&gt;So my only option ssems to be PA-5260, as you also suggested.&lt;/P&gt;&lt;P&gt;Managing 3 different HA pairs will not be a good idea so will not be going the PA-3020 way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thankyou very much,&lt;/P&gt;&lt;P&gt;Bhushit&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 11:15:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-many-ipsec-vpn-peers-can-pa-5220-handle/m-p/206667#M60639</guid>
      <dc:creator>bhushitda</dc:creator>
      <dc:date>2018-03-21T11:15:58Z</dc:date>
    </item>
  </channel>
</rss>

