<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring s to s VPN between three devices. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11879#M8727</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two clients who have same ip subnets for VPN users ( ex. 192.168.29.0/24). Is it possible to configure PaloAlto to support both VPNs for different source users.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN1:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source- 10.66.249.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination- 192.168.29.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Peer IP-&amp;nbsp; X.X.X.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source- 172.16.1.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination- 192.168.29.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Peer IP- y.y.y.y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we use PBF to achieve this.&lt;/P&gt;&lt;P&gt;Ex. If source is 10.66.249.0/24 and destination is 192.168.29.0/24 then route to tunnel.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If source is 172.16.1.0/24 and destination is 192.168.29.0/24 then route to tunnel.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this works what ip address we needs to assign for each tunnel . Because without ip address to tunnel we can't use PBF.&lt;/P&gt;&lt;P&gt;Correct me if am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly help,.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gururaj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Aug 2013 04:51:26 GMT</pubDate>
    <dc:creator>Gururaj</dc:creator>
    <dc:date>2013-08-08T04:51:26Z</dc:date>
    <item>
      <title>Configuring s to s VPN between three devices.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11879#M8727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two clients who have same ip subnets for VPN users ( ex. 192.168.29.0/24). Is it possible to configure PaloAlto to support both VPNs for different source users.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN1:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source- 10.66.249.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination- 192.168.29.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Peer IP-&amp;nbsp; X.X.X.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source- 172.16.1.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination- 192.168.29.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Peer IP- y.y.y.y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we use PBF to achieve this.&lt;/P&gt;&lt;P&gt;Ex. If source is 10.66.249.0/24 and destination is 192.168.29.0/24 then route to tunnel.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If source is 172.16.1.0/24 and destination is 192.168.29.0/24 then route to tunnel.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this works what ip address we needs to assign for each tunnel . Because without ip address to tunnel we can't use PBF.&lt;/P&gt;&lt;P&gt;Correct me if am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly help,.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gururaj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 04:51:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11879#M8727</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2013-08-08T04:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring s to s VPN between three devices.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11880#M8728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="GingerNoCheckStart"&gt;&lt;/SPAN&gt;Hi Gururaj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i understood correctly, above mentioned subnets are belong to private networks right ( end users)..?. But Site to site VPN will establish between&amp;nbsp; gateway to gateway, (between two public IP address).&lt;/P&gt;&lt;P&gt;So, it will be ok to configure 2 different tunnel and Palo Alto firewall will support the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please&amp;nbsp; configure proxy ID for both tunnel. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Subhankar&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GingerNoCheckEnd"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 05:15:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11880#M8728</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-08-08T05:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring s to s VPN between three devices.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11881#M8729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Subhankar,.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But in Virtual router we need to give static route for private subnets to route through tunnel.Below is the snap for the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/7561_pastedImage_0.png" style="width: 799px; height: 227px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our scenario destination (private network) for both sites is 192.168.29.0/24, How we can define two static routes for same destination?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we use PBF to achieve this.&lt;/P&gt;&lt;P&gt;Ex. If source is 10.66.249.0/24 and destination is 192.168.29.0/24 then route to tunnel.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If source is 172.16.1.0/24 and destination is 192.168.29.0/24 then route to tunnel.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this works what ip address we needs to assign for each tunnel we should use. Because without ip address to tunnel we can't use PBF.&lt;/P&gt;&lt;P&gt;Correct me if am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Gururaj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 05:32:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11881#M8729</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2013-08-08T05:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring s to s VPN between three devices.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11882#M8730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gururaj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12.222222328186035px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Overlapping subnets for host IP's are supported only when they are in a separate virtual router. For example:&lt;/P&gt;&lt;P style="font-size: 12.222222328186035px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12.222222328186035px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Virtual Router1: 192.168.1.1/24&lt;/P&gt;&lt;P style="font-size: 12.222222328186035px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Virtual Router2: 192.168.1.2/24&lt;/P&gt;&lt;P style="font-size: 12.222222328186035px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12.222222328186035px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Hope it will help you.&lt;/P&gt;&lt;P style="font-size: 12.222222328186035px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 05:41:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11882#M8730</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-08-08T05:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring s to s VPN between three devices.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11883#M8731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doc fo you: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1594"&gt;https://live.paloaltonetworks.com/docs/DOC-1594&lt;/A&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Aug 2013 07:51:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-s-to-s-vpn-between-three-devices/m-p/11883#M8731</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-08-08T07:51:12Z</dc:date>
    </item>
  </channel>
</rss>

