<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New site to site VPN creation with same proxy IDs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-site-to-site-vpn-creation-with-same-proxy-ids/m-p/213240#M62058</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a HQ PAN connecting to a remote ASA and IPSec is up with static routes and proxy IDs. Have installed and configured a new PAN parallel to remote ASA which is going to be replacing it&lt;/P&gt;&lt;P&gt;Question is, can i have a new VPN configured in HQ to new remote PAN, where the proxy IDs will be same as the operational one? The remote IP for PAN is different from ASA. Also static route needs to be there for smooth migration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 04 May 2018 19:33:09 GMT</pubDate>
    <dc:creator>mhamid</dc:creator>
    <dc:date>2018-05-04T19:33:09Z</dc:date>
    <item>
      <title>New site to site VPN creation with same proxy IDs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-site-to-site-vpn-creation-with-same-proxy-ids/m-p/213240#M62058</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a HQ PAN connecting to a remote ASA and IPSec is up with static routes and proxy IDs. Have installed and configured a new PAN parallel to remote ASA which is going to be replacing it&lt;/P&gt;&lt;P&gt;Question is, can i have a new VPN configured in HQ to new remote PAN, where the proxy IDs will be same as the operational one? The remote IP for PAN is different from ASA. Also static route needs to be there for smooth migration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 19:33:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-site-to-site-vpn-creation-with-same-proxy-ids/m-p/213240#M62058</guid>
      <dc:creator>mhamid</dc:creator>
      <dc:date>2018-05-04T19:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: New site to site VPN creation with same proxy IDs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-site-to-site-vpn-creation-with-same-proxy-ids/m-p/213246#M62059</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The PAN's are route based VPN so you can bring up the tunnel without any proxy-id's and then when you are ready to migrate to the remote PAN, just change the routes to go down that tunnel instead. One thing I did when working with remote PAN's is allow the external interface be a management interface but only from my data center IP's. That way if something happened with the tunnel, I could still access the remote PAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 19:40:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-site-to-site-vpn-creation-with-same-proxy-ids/m-p/213246#M62059</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-05-04T19:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: New site to site VPN creation with same proxy IDs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-site-to-site-vpn-creation-with-same-proxy-ids/m-p/213253#M62060</link>
      <description>&lt;P&gt;Thanks for the reply&lt;/P&gt;&lt;P&gt;i think i understand it now after your explanation and discussion at below link&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Proxy-ID-for-VPNs-Between-Palo-Alto-Networks-and-Firewalls-with/ta-p/54859" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Proxy-ID-for-VPNs-Between-Palo-Alto-Networks-and-Firewalls-with/ta-p/54859&lt;/A&gt;&lt;/P&gt;&lt;P&gt;PAN to PAN VPN doesnt need proxy ID, and traffic will only pass through VPN when i route to it...&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 21:33:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-site-to-site-vpn-creation-with-same-proxy-ids/m-p/213253#M62060</guid>
      <dc:creator>mhamid</dc:creator>
      <dc:date>2018-05-04T21:33:26Z</dc:date>
    </item>
  </channel>
</rss>

