<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing traffic from branch through HQ to vendor in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/routing-traffic-from-branch-through-hq-to-vendor/m-p/234147#M67128</link>
    <description>&lt;P&gt;So found I the problem, or "more of a design issue".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The dynamic vpn setup on my branch side, is the issue to the vendor. I relized that when settting up a direct connection from branch to vendor. The vendor does not support Nat-T!!!! Doh!!!! Which is why I would see the out bound encaps but no decaps back on the HQ side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Back to the drawing board... Hopefully this stops someone form spinning their wheels&lt;/P&gt;</description>
    <pubDate>Fri, 05 Oct 2018 17:09:43 GMT</pubDate>
    <dc:creator>k.truex</dc:creator>
    <dc:date>2018-10-05T17:09:43Z</dc:date>
    <item>
      <title>Routing traffic from branch through HQ to vendor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-traffic-from-branch-through-hq-to-vendor/m-p/232745#M66770</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example.jpg" style="width: 530px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16823i7CA9A91D26241E32/image-dimensions/530x324/is-moderation-mode/true?v=v2" width="530" height="324" role="button" title="example.jpg" alt="example.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently Im labing a situtation where I'll need to have branch users route to a vendor through HQ via IPsec tunnels. Users at my banch access can acesss Web/HQ services though the HQ firewall, but when accessing the vendor. Logs show from HQ the attempts to the vendor from the branch office. But nothing but incompletes/aged-out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From HQ, I do see active connections for&amp;nbsp; phaseII for the branch/vendor connection but of course no encap/decaps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I&amp;nbsp;do have redistrabution profiles for Branch and Vendor connections on the HQ firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 16:37:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-traffic-from-branch-through-hq-to-vendor/m-p/232745#M66770</guid>
      <dc:creator>k.truex</dc:creator>
      <dc:date>2018-09-27T16:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Routing traffic from branch through HQ to vendor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-traffic-from-branch-through-hq-to-vendor/m-p/232754#M66772</link>
      <description>&lt;P&gt;Just found this, which Im spot on. I do worry that my vendor side might be incorrect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-To-Connect-2-Branch-Locations-to-Connect-through-HQ-Site/ta-p/62643&amp;nbsp;" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-To-Connect-2-Branch-Locations-to-Connect-through-HQ-Site/ta-p/62643&amp;nbsp;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 16:50:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-traffic-from-branch-through-hq-to-vendor/m-p/232754#M66772</guid>
      <dc:creator>k.truex</dc:creator>
      <dc:date>2018-09-27T16:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Routing traffic from branch through HQ to vendor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/routing-traffic-from-branch-through-hq-to-vendor/m-p/234147#M67128</link>
      <description>&lt;P&gt;So found I the problem, or "more of a design issue".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The dynamic vpn setup on my branch side, is the issue to the vendor. I relized that when settting up a direct connection from branch to vendor. The vendor does not support Nat-T!!!! Doh!!!! Which is why I would see the out bound encaps but no decaps back on the HQ side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Back to the drawing board... Hopefully this stops someone form spinning their wheels&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 17:09:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/routing-traffic-from-branch-through-hq-to-vendor/m-p/234147#M67128</guid>
      <dc:creator>k.truex</dc:creator>
      <dc:date>2018-10-05T17:09:43Z</dc:date>
    </item>
  </channel>
</rss>

