<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bind multiple VPNs to a single tunnel interface? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9045#M6610</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alexander,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have three separate sites, you'll need a separate IKE gateway for each. The IKE gateway specifies the local and remote IP addresses that will be the termination points for each tunnel. In your case, you would configure three IKE gateways, and associate unique tunnel to each one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jul 2013 17:48:04 GMT</pubDate>
    <dc:creator>ncampagna</dc:creator>
    <dc:date>2013-07-16T17:48:04Z</dc:date>
    <item>
      <title>Bind multiple VPNs to a single tunnel interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9039#M6604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;greetings all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I come from a ScreenOS background, and in their world, you can terminate multiple route-based VPNs onto a single logical tunnel interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 30-40 remote sites with VPN tunnels back to HQ, which will soon be a new PAN firewall.&amp;nbsp; In our lab I have tried to configure multiple IPSec VPNs terminating onto the same tunnel interface and I get the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tunnel interface tunnel.1 multiple binding with different IKE gateways. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This leads me to believe I will have to create a tunnel interface per each remote site -- is this the case?&amp;nbsp; or is there a configuration setting I am missing that will allow this configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is the case, i'm a little worried about having to run a routing protocol on each and every one of those interfaces (we need to dynamically learn routes from the remote sites in our scenario)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2011 15:48:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9039#M6604</guid>
      <dc:creator>wmclendon</dc:creator>
      <dc:date>2011-02-10T15:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Bind multiple VPNs to a single tunnel interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9040#M6605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you can bind multiple VPNs to an interface.&amp;nbsp; It would be best to have a zone specified to a tunnel interface so to be able to create separate VPN policies.&amp;nbsp; Heres a doc for configuring IPSEC VPN:&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1163"&gt;https://live.paloaltonetworks.com/docs/DOC-1163&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 23:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9040#M6605</guid>
      <dc:creator>odaos</dc:creator>
      <dc:date>2011-02-17T23:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Bind multiple VPNs to a single tunnel interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9041#M6606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Will,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do support adding multiple phase 2's to a single tunnel interface.&amp;nbsp; However your question is specific to phase 1's or IKE gateway configurations.&amp;nbsp; For this you will need an additional tunnel interface for each site to which you want to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Feb 2011 06:35:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9041#M6606</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2011-02-23T06:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Bind multiple VPNs to a single tunnel interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9042#M6607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same issue where I can't bind phase 2 to the same tunnel interface and I got this error message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="1" style="text-indent: 0px; font-family: Tahoma, Arial, Helvetica, sans-serif; background-color: #ebedee;" width="98%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="font-size: 11px; font-family: Tahoma, Arial, Helvetica, sans-serif; text-align: right;" width="70"&gt;&lt;STRONG&gt;Operation&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="padding-left: 5px; font-size: 11px; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;Commit&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="font-size: 11px; font-family: Tahoma, Arial, Helvetica, sans-serif; text-align: right;" width="70"&gt;&lt;STRONG&gt;Result&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD style="padding-left: 5px; font-size: 11px; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;Failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD colspan="2" style="padding-left: 5px; font-size: 11px; font-family: Tahoma, Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;STRONG&gt;Details&lt;/STRONG&gt;:&lt;BR /&gt;&lt;STRONG&gt;·&lt;/STRONG&gt;&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;Tunnel interface tunnel.1 multiple binding with different IKE gateways. IPSec tunnel: johng-fw-01. IKE gateway: johng-fw-01. &lt;P&gt;&lt;STRONG&gt;·&lt;/STRONG&gt;&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;Tunnel interface tunnel.1 multiple binding with different IKE gateways. IPSec tunnel: VPN-Z-Test-PA200. IKE gateway: VPN-Z-Test-PA200.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;·&lt;/STRONG&gt;&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;Configuration is invalid&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please tell me how do you achive that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Johnson&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2012 16:47:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9042#M6607</guid>
      <dc:creator>johng</dc:creator>
      <dc:date>2012-06-20T16:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Bind multiple VPNs to a single tunnel interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9043#M6608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Johnson,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot attach an IPSec tunnel to multiple IKE gateways. You can attach multiple IPSec tunnels to a common IKE gateway. This is commonly done to support &amp;gt;10 proxy IDs on a connection to a single VPN (IKE) peer. Can you please share a bit more information on what you're trying to do? That way we can recommend the correct configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2012 17:13:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9043#M6608</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2012-06-20T17:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Bind multiple VPNs to a single tunnel interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9044#M6609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So for example, I could have 3 remote sites. Say site A, B and C. Then on the firewall I have 1 IKE Gateway configured. Site A, B and C could establish a VPN tunnel via the 1 IKE gateway I've configured on the firewall? In other words, each VPN tunnel configured on the firewall, would have the same IKE gateway set for it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 03:03:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9044#M6609</guid>
      <dc:creator>alexander_conn</dc:creator>
      <dc:date>2013-07-16T03:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Bind multiple VPNs to a single tunnel interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9045#M6610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alexander,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have three separate sites, you'll need a separate IKE gateway for each. The IKE gateway specifies the local and remote IP addresses that will be the termination points for each tunnel. In your case, you would configure three IKE gateways, and associate unique tunnel to each one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jul 2013 17:48:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9045#M6610</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2013-07-16T17:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Bind multiple VPNs to a single tunnel interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9046#M6611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have worked with juniper SRX earlier, In order to configure site to multisite VPN's I use to configure "multipoint" option for the tunnel interface.&lt;/P&gt;&lt;P&gt;What is the additional option to used in PA , in order to configure Site-Multi Site VPN ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 10:49:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9046#M6611</guid>
      <dc:creator>rparamati</dc:creator>
      <dc:date>2013-07-29T10:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Bind multiple VPNs to a single tunnel interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9047#M6612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe that the feature that Juniper ScreenOS/SRX uses to support binding multiple VPNs to single tunnel interface is called next-hop tunnel binding (NHTB). This is not part of the RFC standard for IPsec and should be considered proprietary for Juniper. For the most part this allows to save on the number of tunnel interfaces that would need to be configured and is meant for hub-and-spoke configurations. The configuration though is not that simple in that despite sharing single tunnel interface as you still need to populate the NHTB table with either static NHTB entries or via routing protocol such as OSPF p2mp. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For PAN-OS there are two options to do similar scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. With 5.0 you can deploy large-scale VPN with Global Protect Satellite configuration. This is closest to Juniper NHTB. It is actually similar in that you can use a single tunnel interface and then can either specify routes to advertise to GP gateway or use OSPF to learn routes from all spoke sites. But also can do much more in that the configs on each satellite site is rather easy since you point each satellite site to the GP portal to automatically get all configs about each GP gateway to connect to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Configure separate tunnel interface for each spoke site. There should not be an issue with limit on number of tunnel interfaces that can be configured (actually the limit is higher than the max number if SAs that can be configured). Then you can add each of the interfaces into OSPF p2p to learn each spoke site routes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For reference, here is a good doc on the Large-Scale VPN feature in 5.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-4139"&gt;https://live.paloaltonetworks.com/docs/DOC-4139&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 20:52:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bind-multiple-vpns-to-a-single-tunnel-interface/m-p/9047#M6612</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-29T20:52:13Z</dc:date>
    </item>
  </channel>
</rss>

