<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Múltiple Proxy ID PAN - Migration from FG using group address. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/m%C3%BAltiple-proxy-id-pan-migration-from-fg-using-group-address/m-p/376025#M89250</link>
    <description>&lt;P&gt;Hello guys!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm on a manual STS VPN homologation from fortigate, and I have address pools declared in the encryption domains, which translates to too many proxy id's for palo alto, is there any way to configure this without having to generate so many proxy id? I know you can't use groups, but can you do something with variables or any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Wed, 23 Dec 2020 15:37:11 GMT</pubDate>
    <dc:creator>MauricioPerez</dc:creator>
    <dc:date>2020-12-23T15:37:11Z</dc:date>
    <item>
      <title>Múltiple Proxy ID PAN - Migration from FG using group address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/m%C3%BAltiple-proxy-id-pan-migration-from-fg-using-group-address/m-p/376025#M89250</link>
      <description>&lt;P&gt;Hello guys!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm on a manual STS VPN homologation from fortigate, and I have address pools declared in the encryption domains, which translates to too many proxy id's for palo alto, is there any way to configure this without having to generate so many proxy id? I know you can't use groups, but can you do something with variables or any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 15:37:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/m%C3%BAltiple-proxy-id-pan-migration-from-fg-using-group-address/m-p/376025#M89250</guid>
      <dc:creator>MauricioPerez</dc:creator>
      <dc:date>2020-12-23T15:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Múltiple Proxy ID PAN - Migration from FG using group address.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/m%C3%BAltiple-proxy-id-pan-migration-from-fg-using-group-address/m-p/376130#M89264</link>
      <description>&lt;P&gt;is there a way for you to replace the pools with actual subnets?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the Palo Alto firewalls doesn't need Proxy-IDs to function, only if the remote end requires these should they be set up&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;subnets are the more common practice when adding Proxy-IDs (for each unique ID pair, both devices need to create a&amp;nbsp; Security Association, so for a subnet you only need 1 set, but for 1:1 you would need hundreds of SAs the firewalls need to maintain)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2020 11:00:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/m%C3%BAltiple-proxy-id-pan-migration-from-fg-using-group-address/m-p/376130#M89264</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-12-24T11:00:13Z</dc:date>
    </item>
  </channel>
</rss>

