<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Overlapping destination subnets over IPSEC in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/overlapping-destination-subnets-over-ipsec/m-p/375562#M89190</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73217"&gt;@Miroslaw_Iwanowski&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here for IPSEC-A as well as IPSEC-B (post DNAT), the destination is going to be from 10.1.6.x so anyhow it is going to match the static route which will have lowest matric. And in your case, it seems to be IPSEC-A tunnel interface. So in both cases, it will match IPSEC-A tunnel interface and firewall will forward traffic accordingly. Also it seems you have same set of source segment who need access to those resources otherwise PBF would be the option in case you have different source IP addresses accessing same destinations.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Dec 2020 09:08:36 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2020-12-21T09:08:36Z</dc:date>
    <item>
      <title>Overlapping destination subnets over IPSEC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlapping-destination-subnets-over-ipsec/m-p/375403#M89184</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have following scenario. I have a two IPSEC connections to Oracle Cloud. The destination IP range is the same on both networks.&lt;/P&gt;&lt;P&gt;IPSEC A - dest IP range 10.1.6.0/24, security zone Oracle1&lt;/P&gt;&lt;P&gt;IPSEC B -&amp;nbsp;dest IP range 10.1.6.0/24, security zone Oracle 2&lt;/P&gt;&lt;P&gt;LAN - 192.168.0.1/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Static routing:&lt;/P&gt;&lt;P&gt;10.1.6.0/24 to IPSECA&lt;/P&gt;&lt;P&gt;10.1.7.0/24 to IPSECB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created a:&lt;/P&gt;&lt;P&gt;DNAT - from LAN to Oracle2, static DNAT - 10.1.6.0/24&lt;/P&gt;&lt;P&gt;SNAT&amp;nbsp; - from Oracle2 to LAN, static SNAT - 10.1.7.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users will open for example 10.1.7.1 and it should be directed to IPSECB and NAT should change destination address to 10.1.6.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem I am facing is that PA does routing twice pre and post NAT. Post NAT routing directs pocket to IPSECA as the destination address is already NATed to 10.1.6.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to make it working correctly? I cannot do any changes on Oracle side - I only control my PA.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 19:52:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlapping-destination-subnets-over-ipsec/m-p/375403#M89184</guid>
      <dc:creator>Miroslaw_Iwanowski</dc:creator>
      <dc:date>2020-12-20T19:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Overlapping destination subnets over IPSEC</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/overlapping-destination-subnets-over-ipsec/m-p/375562#M89190</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73217"&gt;@Miroslaw_Iwanowski&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here for IPSEC-A as well as IPSEC-B (post DNAT), the destination is going to be from 10.1.6.x so anyhow it is going to match the static route which will have lowest matric. And in your case, it seems to be IPSEC-A tunnel interface. So in both cases, it will match IPSEC-A tunnel interface and firewall will forward traffic accordingly. Also it seems you have same set of source segment who need access to those resources otherwise PBF would be the option in case you have different source IP addresses accessing same destinations.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 09:08:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/overlapping-destination-subnets-over-ipsec/m-p/375562#M89190</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-12-21T09:08:36Z</dc:date>
    </item>
  </channel>
</rss>

