<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limitations for creating number of child sa for site to site vpn in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/333036#M84147</link>
    <description>&lt;P&gt;We are creating a single site to site vpn between PA-220 and FTD firewall and within that multiple /32 ips needs to communicate&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2020 18:49:33 GMT</pubDate>
    <dc:creator>veerrohitparihar2</dc:creator>
    <dc:date>2020-06-11T18:49:33Z</dc:date>
    <item>
      <title>Limitations for creating number of child sa for site to site vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/332912#M84132</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Here I am trying to create a site to site vpn in Paloalto firewall, now in local network I have 8 individual /32 ips and for remote 10 individual /32 ips. This is for policy based vpn. Now if I add proxy ids for local and remote ips. I am getting around 80 proxy ids. Requirement is to only use ips not subnets. Now few connections are not working though it is allowed and phase 2 is up. I want to confirm if there is any limitations in creating total numbers of proxy ids and if it creates any impact in performance of the firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 08:24:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/332912#M84132</guid>
      <dc:creator>veerrohitparihar2</dc:creator>
      <dc:date>2020-06-11T08:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations for creating number of child sa for site to site vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/332943#M84139</link>
      <description>&lt;P&gt;proxy id's are essentially individual vpn tunnels, so you're setting up 80 vpn tunnels&lt;/P&gt;&lt;P&gt;what kind of platform are you stting this up on?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 13:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/332943#M84139</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-06-11T13:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations for creating number of child sa for site to site vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/333036#M84147</link>
      <description>&lt;P&gt;We are creating a single site to site vpn between PA-220 and FTD firewall and within that multiple /32 ips needs to communicate&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 18:49:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/333036#M84147</guid>
      <dc:creator>veerrohitparihar2</dc:creator>
      <dc:date>2020-06-11T18:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations for creating number of child sa for site to site vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/333551#M84226</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;See if the IP's can fit into a subnet. Also you can just create one proxy id, all the ip's/subnets and then use policies to limit the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some thoughts.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 21:56:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/333551#M84226</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-06-15T21:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations for creating number of child sa for site to site vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/333569#M84227</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145438"&gt;@veerrohitparihar2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Correct, but as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;mentioned in his previous comment any time you add a proxy id you are essentially adding another tunnel. So as far as your firewall is concerned&amp;nbsp;&lt;EM&gt;it's&amp;nbsp;&lt;/EM&gt;going to create what amounts to 80 tunnels to support all of the Proxy IDs you are trying to configure.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 02:46:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/333569#M84227</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-06-16T02:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations for creating number of child sa for site to site vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/334422#M84367</link>
      <description>&lt;P&gt;I just found my answer in the PaloAlto PSNSE Study guide, under Topic Tunnel interface. " Tunnel interface can have a maximum of 250 proxy IDs. Each proxy ID counts toward the IPsec VPN tunnel capacity of the firewall, and the tunnel capacity varies by the firewall model. "&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jun 2020 06:06:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitations-for-creating-number-of-child-sa-for-site-to-site-vpn/m-p/334422#M84367</guid>
      <dc:creator>veerrohitparihar2</dc:creator>
      <dc:date>2020-06-20T06:06:10Z</dc:date>
    </item>
  </channel>
</rss>

