<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN over MetroE in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212741#M61993</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;. I also have L2 connections and that is how i do it. Just give each interface the WAN link connect to a RFC 1918 /30 and do the same on the other side with the corresponding /30 address. I also add static routes for the /30's in each direction along with the associated Polcies to secure the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Wed, 02 May 2018 18:24:06 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-05-02T18:24:06Z</dc:date>
    <item>
      <title>VPN over MetroE</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212644#M61989</link>
      <description>&lt;P&gt;I've been given an L2 handoff from Comcast from our data center to our co-location. I can move switched traffic over the link between the Palos at both sites with no issues. My problem comes when I try to add L3 and a a tunnel to the link. I've set up many site-to-site vpns before, but this is&amp;nbsp; my first time trying to add it to an L2 interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My first attempt I told the Palo the the L2 interface was an L3, and applied my normal configurations for setting up the tunnel. It does attempt to negotiate, but times out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My second attempt I used an older KB by Palo from around 2010 where it used a VLAN interface. However, the guide was setting it up to work from a single Palo versus between two separate. I can't even see them attempt to negotiate in the logs, so fairly sure I totally messed that configuration up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does any one have any advice, or can point me to a more solid resource for setting this up?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 15:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212644#M61989</guid>
      <dc:creator>Paul_Lupini</dc:creator>
      <dc:date>2018-05-02T15:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN over MetroE</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212683#M61991</link>
      <description>&lt;P&gt;Let's take this one step at a time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You say you can move switched traffic over the link.&amp;nbsp; What happens if you add IP addresses to the interfaces connected to comcast (configure them as L3) and add a ping management profile during troubleshooting - can you ping across teh link (you should be able to)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now configure your IPSEC tunnel using those IP addresses as the targets for the tunnel - does the tunnel come up?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you able to&amp;nbsp;share any configuration details?&amp;nbsp; We may need more detail to determine exactly what you have configured and make better recommendations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If they deliver you a "Layer 2" tunnel, it just means they don't have a gateway you need to reach out to, layer 3 and above are up to you.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 16:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212683#M61991</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-05-02T16:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN over MetroE</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212685#M61992</link>
      <description>&lt;P&gt;Thanks for the advice. I'll give that a go after lunch and report back.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 16:39:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212685#M61992</guid>
      <dc:creator>Paul_Lupini</dc:creator>
      <dc:date>2018-05-02T16:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN over MetroE</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212741#M61993</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83021"&gt;@JoeAndreini&lt;/a&gt;. I also have L2 connections and that is how i do it. Just give each interface the WAN link connect to a RFC 1918 /30 and do the same on the other side with the corresponding /30 address. I also add static routes for the /30's in each direction along with the associated Polcies to secure the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 18:24:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212741#M61993</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-02T18:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN over MetroE</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212742#M61994</link>
      <description>&lt;P&gt;At that point you can configure your IPSEC tunnel as if it was over any other network.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 18:33:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-over-metroe/m-p/212742#M61994</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-05-02T18:33:33Z</dc:date>
    </item>
  </channel>
</rss>

