<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DMVPN router traffic through DMZ to trusted LAN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dmvpn-router-traffic-through-dmz-to-trusted-lan/m-p/231067#M66347</link>
    <description>&lt;P&gt;We are setting up DMVPN routers for on-demand VPNs from our remote sites to HQ.&amp;nbsp; our DMVPN routers have the front end exposed to internet and the back end is on our special DMVPN DMZ.&amp;nbsp; When the VPN is built from the remote site traffic from the site comes into the DMZ and needs to be routed through the PA (5050) to the trusted interface (HQ LAN SEGMENT).&amp;nbsp; &amp;nbsp;The traffic is being blocked by policy and when I tried to put in a policy I get a L3 error. It think its because the traffic from the site is not part of the DMVPN ZONE.&amp;nbsp; &amp;nbsp;The DMVPN zone is 192.55.XXX.XXX but the traffic going through is on the 10.XXX.XXX.XXX network.&amp;nbsp; Since the traffic being passed is not part of the ZONE I think that is causing the L3 error/message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions would be appreciated.&amp;nbsp; (We wanted to use the DMZ approach so the traffic could be controlled, blocked, and scanned as required.)&lt;/P&gt;</description>
    <pubDate>Mon, 17 Sep 2018 13:58:56 GMT</pubDate>
    <dc:creator>tim_cahoon</dc:creator>
    <dc:date>2018-09-17T13:58:56Z</dc:date>
    <item>
      <title>DMVPN router traffic through DMZ to trusted LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmvpn-router-traffic-through-dmz-to-trusted-lan/m-p/231067#M66347</link>
      <description>&lt;P&gt;We are setting up DMVPN routers for on-demand VPNs from our remote sites to HQ.&amp;nbsp; our DMVPN routers have the front end exposed to internet and the back end is on our special DMVPN DMZ.&amp;nbsp; When the VPN is built from the remote site traffic from the site comes into the DMZ and needs to be routed through the PA (5050) to the trusted interface (HQ LAN SEGMENT).&amp;nbsp; &amp;nbsp;The traffic is being blocked by policy and when I tried to put in a policy I get a L3 error. It think its because the traffic from the site is not part of the DMVPN ZONE.&amp;nbsp; &amp;nbsp;The DMVPN zone is 192.55.XXX.XXX but the traffic going through is on the 10.XXX.XXX.XXX network.&amp;nbsp; Since the traffic being passed is not part of the ZONE I think that is causing the L3 error/message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions would be appreciated.&amp;nbsp; (We wanted to use the DMZ approach so the traffic could be controlled, blocked, and scanned as required.)&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 13:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmvpn-router-traffic-through-dmz-to-trusted-lan/m-p/231067#M66347</guid>
      <dc:creator>tim_cahoon</dc:creator>
      <dc:date>2018-09-17T13:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: DMVPN router traffic through DMZ to trusted LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dmvpn-router-traffic-through-dmz-to-trusted-lan/m-p/231143#M66363</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I used to have a similar setup and we changed to just use the PAN's VPN and dynamic routing, OSPF, with costs so the VP would only be chosen if hte primary link went down. However from your description, I would say its possibly a routing issues? The PAN might not know where to rout the 192 network or there is no secondary path to/from the remote office on the PAN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if I didnt understand your question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 20:50:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dmvpn-router-traffic-through-dmz-to-trusted-lan/m-p/231143#M66363</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-17T20:50:46Z</dc:date>
    </item>
  </channel>
</rss>

