<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ipsec question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-question/m-p/336587#M84788</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In IPSEC if you need to reach &amp;nbsp;remote network on other side say 192.168.10.0/24 then you need to put Static route saying&lt;/P&gt;
&lt;P&gt;to reach remote network 192.168.10.0/24 interface is tunnel .50&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no need to apply the IP 192.168.10.0/24 to any PA &amp;nbsp;interface as any traffic for 192.168.10.0/24 will have tunnel interface as outgoing interface and tunnel interface is virtual and it knows it has to pass the traffic to interface with public IP address which in your&lt;/P&gt;
&lt;P&gt;case is ae1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA public IP ---------------ipsec tunnel --------------------------------------------Remote Device Public IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Sat, 04 Jul 2020 04:32:33 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2020-07-04T04:32:33Z</dc:date>
    <item>
      <title>ipsec question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-question/m-p/336586#M84787</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i have my public interface ae1.10&lt;/P&gt;&lt;P&gt;I attached a ikev2 interface to that and attach it to tunnel.50&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no the other side of the ipsec tunnel are providing 192.168.10.0/24 and I am providing 192.168.250.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do I have to place a static route in the v_router saying 192.168.10.0/24 via tunnel.50&lt;/P&gt;&lt;P&gt;how do i do that if I haven't applied a ip address to the tunnel interface, do I have to&amp;nbsp;&lt;/P&gt;&lt;P&gt;do I have to add the static route ?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 02:17:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-question/m-p/336586#M84787</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-07-04T02:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: ipsec question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-question/m-p/336587#M84788</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In IPSEC if you need to reach &amp;nbsp;remote network on other side say 192.168.10.0/24 then you need to put Static route saying&lt;/P&gt;
&lt;P&gt;to reach remote network 192.168.10.0/24 interface is tunnel .50&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is no need to apply the IP 192.168.10.0/24 to any PA &amp;nbsp;interface as any traffic for 192.168.10.0/24 will have tunnel interface as outgoing interface and tunnel interface is virtual and it knows it has to pass the traffic to interface with public IP address which in your&lt;/P&gt;
&lt;P&gt;case is ae1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA public IP ---------------ipsec tunnel --------------------------------------------Remote Device Public IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 04:32:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-question/m-p/336587#M84788</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-04T04:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: ipsec question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-question/m-p/336592#M84793</link>
      <description>&lt;P&gt;So because the destination address is part of the proxy, it will route it via the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thought that might be the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;edit&lt;/P&gt;&lt;P&gt;did a quick check remove the static routes and tested the FIB for that destination it wasn't going via the tunnel !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did a quick test the packets are not going out the tunnel - they are going out the public ae.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so my ae.7 is my internet and I have a few ip's on here. one of them is my end of the ipsec ike&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 08:05:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-question/m-p/336592#M84793</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-07-04T08:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: ipsec question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-question/m-p/336654#M84829</link>
      <description>&lt;P&gt;This covers it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGkCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGkCAK&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 09:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-question/m-p/336654#M84829</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-07-06T09:46:43Z</dc:date>
    </item>
  </channel>
</rss>

