<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253699#M72024</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It has emerged me a doubt. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I configure tunnel monitoring, in the part of: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;MONITOR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Profile: Failover_VPN_Tunnel &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Adress: 192.168.2.4 &amp;lt;--- This address should be the same as that configured in the tunnel interface? Network -&amp;gt; Intereface - Tunnel? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2019 12:57:38 GMT</pubDate>
    <dc:creator>SebastianRM</dc:creator>
    <dc:date>2019-03-14T12:57:38Z</dc:date>
    <item>
      <title>Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253039#M71899</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have a question about the configuration of the ipsec tunnel, in the article when the tunnel interface is created &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Optional) If you want to assign an IPv4 address to the tunnel interface, select the IPv4 tab, and Add the IP address and network mask, for example 10.31.32.1/32." &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That "Optional" address, what should it be? from my network, anyone? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I also wanted to consult once the monitor profile was created to know if the tunnel is UP or DOWN, when I select "failover". How should the PBF rule be with another ISP? I am looking for the tunnel to be UP in case the principal no longer responds and performs failover. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could someone explain to me?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:44:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253039#M71899</guid>
      <dc:creator>SebastianRM</dc:creator>
      <dc:date>2019-03-10T13:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253109#M71917</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The tunnel interface could be anything. I use rfc1918 addresses that are carved into /30's so each side of the tunnel gets one. Then I have a static route (for monitoring only) to the other sides IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The monitor sends pings to the IP specified to verify if it is up or down. Check out this article about dual ISP's and PBF failover.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/policy/policy-based-forwarding/use-case-pbf-for-outbound-access-with-dual-isps.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/policy/policy-based-forwarding/use-case-pbf-for-outbound-access-with-dual-isps.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:50:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253109#M71917</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-11T15:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253598#M71997</link>
      <description>&lt;P&gt;Hello Otakar.Klier&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your response, I would appreciate it if you could help me with the following, since I have not been able to advance&lt;/P&gt;&lt;P&gt;When I created the PBF and I had a main and a backup tunnel, in "Source" did I have to choose the "Trust" zone (LAN) or the "VPN" zone that was created for the tunnels?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In "Static Routes" I defined as follows&lt;/P&gt;&lt;P&gt;VR_RED_1&lt;/P&gt;&lt;P&gt;Destination: 192.168.2.0 (The other end network)&lt;BR /&gt;Interface: tunnel.1&lt;BR /&gt;Next Hop (Here I have not placed anything, should I put the IP default gateway for the output of ISP1?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VR_RED_1_Backup&lt;BR /&gt;Destination: 192.168.2.0 (The other end network)&lt;BR /&gt;Tunnel interface&lt;BR /&gt;Next Hop (Here I have not placed anything, should I put the IP default gateway for the ISP2 output?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configuring IPSec Tunnel&lt;/P&gt;&lt;P&gt;VPN_Tunnel_1&lt;BR /&gt;Tunnel Interface: tunnel.1&lt;BR /&gt;Address Type: IPv4&lt;BR /&gt;Type: Auto Key&lt;BR /&gt;IKE Gateway: VPN_Tunnel_1_IKE&lt;BR /&gt;IPSec Crypto: Default&lt;BR /&gt;Tunnel Monitor&lt;BR /&gt;- Destination IP: 192.168.2.4 (any host IP in the other network, this is correct or what should I put?)&lt;BR /&gt;Profile: Failover_VPN_Tunnel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN_Tunnel_1_Backup&lt;BR /&gt;Tunnel Interface: tunnel.2&lt;BR /&gt;Address Type: IPv4&lt;BR /&gt;Type: Auto Key&lt;BR /&gt;IKE Gateway: VPN_Tunnel_1_IKE_Backup&lt;BR /&gt;IPSec Crypto: Default&lt;BR /&gt;Tunnel Monitor&lt;BR /&gt;- Destination IP: 192.168.2.4 (any host IP in the other network, this is correct or what should I put?)&lt;BR /&gt;Profile: Failover_VPN_Tunnel&lt;/P&gt;&lt;P&gt;This may be the part that causes me the most trouble.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel interface configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel.1&lt;BR /&gt;IP Address: (I have not placed any address, in the IKE_Gateway I refer to the interface and address of each Peer)&lt;BR /&gt;Virtual Router: Default (It is necessary to place the previously configured? VR_RED_1)&lt;BR /&gt;Security Zone: VPN_Zone&lt;/P&gt;&lt;P&gt;Tunnel.2&lt;BR /&gt;IP Address: (I have not placed any address, in the IKE_Gateway I refer to the interface and address of each Peer)&lt;BR /&gt;Virtual Router: Default (It is necessary to place the previously configured? VR_RED_1_Backup)&lt;BR /&gt;Security Zone: VPN_Zone&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKE_Gateway configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN_Tunnel_1_IKE&lt;BR /&gt;Version: IKEv1&lt;BR /&gt;Address Type: IPv4&lt;BR /&gt;Interface: Eth1 / 1&lt;BR /&gt;Local IP: (Local ISP)&lt;BR /&gt;Peer Address: (Peer ISP)&lt;BR /&gt;Pre-Shared Key: (key ****)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN_Tunnel_1_IKE_Backup&lt;BR /&gt;Version: IKEv1&lt;BR /&gt;Address Type: IPv4&lt;BR /&gt;Interface: Eth1 / 2&lt;BR /&gt;Local IP: (Local ISP Backup)&lt;BR /&gt;Peer Address: (Peer ISP Backup)&lt;BR /&gt;Pre-Shared Key: (key ****)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PBF Config:&lt;BR /&gt;Source Trust / LAN (is this correct?)&lt;BR /&gt;Destination: 192.168.2.0/24 (Destination network)&lt;BR /&gt;[] Negate selected&lt;BR /&gt;Forwarding:&lt;BR /&gt;Action: Forward&lt;BR /&gt;Egress Interface: Tunnel.2&lt;BR /&gt;[ ] Monitor&lt;BR /&gt;Profile: Failover_VPN_Tunnel&lt;BR /&gt;IP Address: 192.168.2.4 (any IP from a host at the other end)&lt;BR /&gt;[] Disable this rule if nexthop / monitor ip is unreachable - Selected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for everything and I apologize for the length of the message, it is that I am having problems to make this configuration and it has cost me something to understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 13:18:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253598#M71997</guid>
      <dc:creator>SebastianRM</dc:creator>
      <dc:date>2019-03-13T13:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253654#M72014</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I will do my best to answer. From what I have gathered you have a remote site and two ISP's at each site or only 2 isp's at the main site and one at the remote site?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When using PBF, these are used prior to anything in the virtual router. So if you have 2&amp;nbsp; ways to get somewhere, the primary path would be your PBF with the 'Disable' option and the backup route will be the static (if you point it at a tunnel, you dont need a next hop). You should not have static for both as this will not work correctly. Also not sure if its a typo, but you have the same IP for both tunnel interfaces, they should be different?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 21:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253654#M72014</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-13T21:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253696#M72022</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Otakar.Klier&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your support!. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So in the PFB rule should I put the primary tunnel to execute this rule?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It would be ... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SOURCE: LAN &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;DESTINATION / APP / SERV. 192.168.2.0/24/any/any &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;FORWARDING&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Action: Forward &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Egress: tunnel.1 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Next Hop: - &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;MONITOR &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Profile: Failover_VPN_Tunnel &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Adress: 192.168.2.4 (any IP from a host at the other end) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[] Disable this rule if nexthop / monitor ip is unreachable - Selected &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would this always leave the main tunnel? In case it fails, how would it reach the other? In the state of the tunnel, in the main the interface is shown in red, but it is connected at least on the east side and working correctly, what could it be? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have 2 ISPs on both sites. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The IP addresses to configure the IKE Gateway are different from each one. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In the rule NAT_VPN_1 I placed Section "Translated Packet"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Eth1 / 1 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP: (ISP1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In the rule NAT_VPN_1_Backup I placed Section "Translated Packet"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Eth1 / 2 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP: (ISP2) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Again thank you very much !! &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 12:31:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253696#M72022</guid>
      <dc:creator>SebastianRM</dc:creator>
      <dc:date>2019-03-14T12:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253699#M72024</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It has emerged me a doubt. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I configure tunnel monitoring, in the part of: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;MONITOR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Profile: Failover_VPN_Tunnel &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Adress: 192.168.2.4 &amp;lt;--- This address should be the same as that configured in the tunnel interface? Network -&amp;gt; Intereface - Tunnel? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 12:57:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253699#M72024</guid>
      <dc:creator>SebastianRM</dc:creator>
      <dc:date>2019-03-14T12:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253708#M72027</link>
      <description>&lt;P&gt;Add tunnel interfaces to same subnet.&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;Site 1 - 192.168.2.1/30&lt;/P&gt;&lt;P&gt;Site 2&amp;nbsp;- 192.168.2.2/30&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 13:10:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253708#M72027</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-03-14T13:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253751#M72047</link>
      <description>&lt;P&gt;Hi Raido&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then, when I trying to monitoring tunnel that "IP Adress" should be the same of the tunnel?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;MONITOR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Profile: Failover_VPN_Tunnel&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Adress: 192.168.2.1/30 &amp;lt;-&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 17:16:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253751#M72047</guid>
      <dc:creator>SebastianRM</dc:creator>
      <dc:date>2019-03-14T17:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253817#M72060</link>
      <description>&lt;P&gt;Correct, the monitor IP will the the IP that the PAN will ping on the other side of the tunnel to verify that it is up.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 21:09:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253817#M72060</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-14T21:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253850#M72066</link>
      <description>&lt;P&gt;Hi Otakar&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So can it be any IP on the other side of the tunnel or should it be the IP that is assigned to the tunnel interface on the other side?.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 02:01:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253850#M72066</guid>
      <dc:creator>SebastianRM</dc:creator>
      <dc:date>2019-03-15T02:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253853#M72067</link>
      <description>&lt;P&gt;It can be any IP.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 03:35:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253853#M72067</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-03-15T03:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253939#M72101</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;While it can be any IP. I always recommend you use one that is as close to the VPN endpoint as possible. So yes I would recommend the Tunnel IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;reason:&lt;/P&gt;&lt;P&gt;Lets say I have the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;switchA --PANA--VPN--PANB--switchB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use switchB's IP for the PANA monitoring, if that switch goes down/reboots the tunnel will fail over.&lt;/P&gt;&lt;P&gt;If I use PANB's IP for PANA monitoring, it will only fail over if the IP of PANB is not reachable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my thoughts.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 14:37:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253939#M72101</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-15T14:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253969#M72108</link>
      <description>&lt;P&gt;Hi Raido and Otakar&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your assistance, it is really useful&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Tunnel 1 and Tunnel 2 (Backup). Both phases are OK, green, but in the main interface "Tunnel 1" the status appears in red.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read this article:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTeCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTeCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Phase 1 - OK&lt;BR /&gt;Phase 2 - OK&lt;BR /&gt;Status = Red&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"RED indicates that the tunnel interface is down because the tunnel monitor is enabled and the remote tunnel monitoring IP address is unreachable."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I disabled the PBF policy and Tunnel 2, but traffic continues to come out of tunnel 2, I can not understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would they know what it could be?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 18:31:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253969#M72108</guid>
      <dc:creator>SebastianRM</dc:creator>
      <dc:date>2019-03-15T18:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253973#M72109</link>
      <description>&lt;P&gt;Here comes my doubt too&lt;/P&gt;&lt;P&gt;Network - IPSec Tunnels&lt;/P&gt;&lt;P&gt;IpsecTunnel.PNG&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IpsecTunnel.PNG" style="width: 763px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19093i66DA11E8C2D28E99/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="IpsecTunnel.PNG" alt="IpsecTunnel.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here I put the profile and the IP address is that of a host that is 24 hours UP on the other side.&lt;/P&gt;&lt;P&gt;In the PBF&lt;/P&gt;&lt;P&gt;Policies - PBF&lt;/P&gt;&lt;P&gt;PBF.PNG&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBF.PNG" style="width: 668px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19094iCC975A64DCA54F0A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PBF.PNG" alt="PBF.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here it is necessary to place&lt;/P&gt;&lt;P&gt;&amp;nbsp;the IP address again if I choose the profile?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In "Destination" within the PBF should I enter the network address? or the address of the Gateway?&lt;/P&gt;&lt;P&gt;Example:&lt;BR /&gt;Network: 192.168.2.0/24&lt;BR /&gt;Gateway: 192.168.2.1/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PBFDest.PNG" style="width: 669px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19095i0E4036C0634740DC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PBFDest.PNG" alt="PBFDest.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not understand well the operation of "Negate"&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 18:54:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253973#M72109</guid>
      <dc:creator>SebastianRM</dc:creator>
      <dc:date>2019-03-15T18:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253975#M72111</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Negate just means 'Not Equal To' so lets say you want everything to route except a specific /24 you would enter that /24 network and select negate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The monitor is just a ping so it can be anything. The PBF is a route so it needs to be the IP of the next hop router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the interface is Red, then its down and something is not happy, i.e. needs to be investigated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 19:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/253975#M72111</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-15T19:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/254256#M72167</link>
      <description>&lt;P&gt;Hi Otakar,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks you so much for your assistance&lt;/P&gt;&lt;P&gt;Really it help me&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;its necessary the "negate" or if I don't check this happens something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the PBF, then I'll put the IP of the next router there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 18:28:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/254256#M72167</guid>
      <dc:creator>SebastianRM</dc:creator>
      <dc:date>2019-03-19T18:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/254442#M72215</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So the Negate translates to "not equal to'. Let ssay you have 192.168.0.0/16 on your internal network. Now lets say you want all traffic 'except' a certain subnet(s). This is where you would use negate so that the rule is 'cleaner'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;i dont want the policy to apply to the following subnets: 192.168.199.0/24 and 192.168.66.0/25.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you were to apply a 'Permit' policy you would have to list out all the subnets except those you dont want. So instead you use the Negate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 457px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19162iB4A7538AEFA5B321/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What this does is allows all subnets 'Except' the ones listed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 20:43:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-tunnel/m-p/254442#M72215</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-20T20:43:38Z</dc:date>
    </item>
  </channel>
</rss>

