<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to site VPN terminating in DMZ possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10195#M7482</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my current situation i don't have PI and BGP. But it is something customer is looking into for the near future so any input on this would be welcome too.&lt;/P&gt;&lt;P&gt;I just wanted to terminate VPN in public DMZ but failed to get any actual traffic through VPN despite VPN going up without any problems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Oct 2012 06:30:55 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2012-10-16T06:30:55Z</dc:date>
    <item>
      <title>Site to site VPN terminating in DMZ possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10192#M7479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to setup a site to site VPN and have it terminate on the DMZ interface rather than the WAN interface? We have numerous remote locations that are running small sonicwall firewalls and connecting back to our corporate site. They currently terminate on a Sonicwall, but we are migrating over to a Palo Alto unit. The reason for terminating in the DMZ is that we'd like to be able to use redundant WAN connections with BGP routing. This way if one of the ISPs goes down, the VPN will still be accessible through the other ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any docs on how to do this? I couldn't locate any.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2012 18:49:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10192#M7479</guid>
      <dc:creator>ajezierski</dc:creator>
      <dc:date>2012-06-19T18:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN terminating in DMZ possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10193#M7480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like some info on this issue as well. I've tried terminating VPN on the DMZ interface with public IP address and it didn't work. VPN tunnel was established quickly and without any problems. But I couldn't get any traffic through it. What was even more confusing I couldn't find any log entries about encrypted traffic at all! I have a default drop rule in the end which logs everything, yet I still didn't get any log entries. I used the packet capturing feature and I could see packets logged in received stage, but not at firewall or transmitted stage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I gave up debugging the mentioned situation I've terminated VPN tunnel on WAN interface (with same settings) and everything worked imeediatelly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any official info about this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2012 13:26:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10193#M7480</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2012-10-15T13:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN terminating in DMZ possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10194#M7481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shouldnt it work if you setup a loopback interface out of your PI range (or whatever you use for BGP announcement) and configure your VPN to use this loopback interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 03:01:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10194#M7481</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-16T03:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN terminating in DMZ possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10195#M7482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my current situation i don't have PI and BGP. But it is something customer is looking into for the near future so any input on this would be welcome too.&lt;/P&gt;&lt;P&gt;I just wanted to terminate VPN in public DMZ but failed to get any actual traffic through VPN despite VPN going up without any problems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 06:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10195#M7482</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2012-10-16T06:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN terminating in DMZ possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10196#M7483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should work before you get BGP aswell, just use an ip out of your public range as loopback.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then when you configure the tunnel you set it to zone DMZ - this way you wont need any security rules for traffic going to the DMZ servers (because the tunnel and the server will be on the same zone).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 07:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-terminating-in-dmz-possible/m-p/10196#M7483</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-16T07:37:18Z</dc:date>
    </item>
  </channel>
</rss>

