<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up an IPSEC VPN? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12859#M9424</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't defined anything in my security policy, this is just a simple deployment as per the PDFs linked to above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latency, well both units are plugged into the same 100mbps switch for testing, so I'd hope it's not that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Aug 2010 19:49:26 GMT</pubDate>
    <dc:creator>networkadmin</dc:creator>
    <dc:date>2010-08-19T19:49:26Z</dc:date>
    <item>
      <title>Setting up an IPSEC VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12854#M9419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We want to use our PA-500 (3.1.3) at our site to create a tunnel to a remote site which will have a McAfee/Secure Computing Sidewinder.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've never used IPSEC VPN before so I guess I want to be clear on how I do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our PA-500 is setup in a simple L3 deployment, so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ethernet1/1 is "trust" private IP of 10.6.1.1/16&lt;/P&gt;&lt;P&gt;ethernet1/2 is "untrust" public IP of 193.35.x.x/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and a single virtual router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The remote sites LAN IP range will be 10.7.x.x/16 and for their public IP for testing will also be 193.35.x.x/24 as I'll be connecting the Sidewinder to the same switch/subnet as the PA-500's ethernet1/2 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So at our main site everyone's default gateway is our main router, which routes 0.0.0.0 to 10.6.1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we want is for all traffic in the remote site to be tunnelled back here, and to go out through out PA-500 so their traffic is subject to the same policies as ours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate the Sidewinder is outside the scope here so I'll have to work that out, but with regards to the PA-500 any pointers on a quick and simple config to achieve what I want?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 19:44:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12854#M9419</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-08-12T19:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up an IPSEC VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12855#M9420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please call into support to set up a trouble shooting session to go over basic vpn configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 18:04:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12855#M9420</guid>
      <dc:creator>jnguyen</dc:creator>
      <dc:date>2010-08-13T18:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up an IPSEC VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12856#M9421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is good document that provide step by step instructions on setting up IPSec VPN&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://live.paloaltonetworks.com/docs/DOC-1163"&gt;https://live.paloaltonetworks.com/docs/DOC-1163&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 18:38:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12856#M9421</guid>
      <dc:creator>jpa</dc:creator>
      <dc:date>2010-08-13T18:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up an IPSEC VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12857#M9422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK I got this working, all by the book apart from having to manually specify local/remote proxy addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured a tunnel and it works, however I've noticed that if I run iperf I get a higher throughput from a client behind the Sidewinder pushing to a server behind the Palo Alto, and a lower throughput with the server behind the Sidewinder and the client behind the Palo Alto.&lt;BR /&gt;&lt;BR /&gt;I'm assuming this isn't normal and VPN throughput should be symmetrical given that for testing both firewalls external interfaces are connected to the same switch?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Aug 2010 13:16:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12857#M9422</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-08-16T13:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up an IPSEC VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12858#M9423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would begin by checking the policy and inspection order within the security policy on the PAN.&amp;nbsp; Can you provide a latency number in both directions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Aug 2010 02:40:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12858#M9423</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-08-19T02:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up an IPSEC VPN?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12859#M9424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't defined anything in my security policy, this is just a simple deployment as per the PDFs linked to above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latency, well both units are plugged into the same 100mbps switch for testing, so I'd hope it's not that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Aug 2010 19:49:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-up-an-ipsec-vpn/m-p/12859#M9424</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2010-08-19T19:49:26Z</dc:date>
    </item>
  </channel>
</rss>

