<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic two Internetconnection IpSec build in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/two-internetconnection-ipsec-build/m-p/260125#M73722</link>
    <description>&lt;P&gt;Hello, I have two PAs and want to build IPSec tunnels between them. one PA A has a static IP. The other PA B has two internet connections. One with a static IP and one with a dynamic IP. Now I want to build two tunnels from device B to the A side. my two internet interfaces eth 1/4 has the IP 192.189.5.4 and the router behind it has the IP 192.168.5.1. What should my routing look like? Both interfaces are in the same default VR. There I have a route 0.0.0.0/0 on interface eth 1/1 where my main internet connection is. My other side where the tunnel should terminate is the 1.1.1.1 IP.&lt;BR /&gt;Don't really know right now.When my tunnel from eth 1/4 now start, it will go to the untrust zone of eth 1/1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where can I find helpful information?&lt;/P&gt;</description>
    <pubDate>Tue, 07 May 2019 15:08:14 GMT</pubDate>
    <dc:creator>clonesheep</dc:creator>
    <dc:date>2019-05-07T15:08:14Z</dc:date>
    <item>
      <title>two Internetconnection IpSec build</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-internetconnection-ipsec-build/m-p/260125#M73722</link>
      <description>&lt;P&gt;Hello, I have two PAs and want to build IPSec tunnels between them. one PA A has a static IP. The other PA B has two internet connections. One with a static IP and one with a dynamic IP. Now I want to build two tunnels from device B to the A side. my two internet interfaces eth 1/4 has the IP 192.189.5.4 and the router behind it has the IP 192.168.5.1. What should my routing look like? Both interfaces are in the same default VR. There I have a route 0.0.0.0/0 on interface eth 1/1 where my main internet connection is. My other side where the tunnel should terminate is the 1.1.1.1 IP.&lt;BR /&gt;Don't really know right now.When my tunnel from eth 1/4 now start, it will go to the untrust zone of eth 1/1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where can I find helpful information?&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 15:08:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-internetconnection-ipsec-build/m-p/260125#M73722</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2019-05-07T15:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: two Internetconnection IpSec build</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-internetconnection-ipsec-build/m-p/260140#M73727</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;As for the VPN, here is the article you would want to read:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIGCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIGCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for routing, you have several choices:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OSPF with one VPN path having a higher cost of say 10000&lt;/P&gt;&lt;P&gt;Static with route monitoring, .e.g the route will be removed if the far end IP is not reached&lt;/P&gt;&lt;P&gt;Policy based forwarding with monitoring, e.g. the PBF rule will not take affect is the far end IP is not reached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way I have done it in the past is assign IP to the Tunnel interfaces, like /30's and then make the far side /32 routing using static routing. So if the tunnel is down the IP is never reachable since its static routing and the other protocols are of lower value.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this makes sense. Let me know if you would like clarification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 18:42:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-internetconnection-ipsec-build/m-p/260140#M73727</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-07T18:42:41Z</dc:date>
    </item>
  </channel>
</rss>

