<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Site-to-Site Private IP and Public IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/424547#M94265</link>
    <description>&lt;P&gt;VPN Site-to-Site Private IP and Public IP&lt;/P&gt;&lt;P&gt;Good afternoon everyone, is it possible to set up a Site-to-Site VPN between a site with a Palo Alto Private IP and a Palo Alto Public IP.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Site Privado: PaloAlto---IpWan-192.168.1.254---Router/Modem--------Internet-------Site Publico:IPWan:190.100.100.200&lt;/P&gt;&lt;P&gt;Thank you very much for your help and support, I remain attentive.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
    <pubDate>Wed, 04 Aug 2021 18:37:03 GMT</pubDate>
    <dc:creator>Metgatz</dc:creator>
    <dc:date>2021-08-04T18:37:03Z</dc:date>
    <item>
      <title>VPN Site-to-Site Private IP and Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/424547#M94265</link>
      <description>&lt;P&gt;VPN Site-to-Site Private IP and Public IP&lt;/P&gt;&lt;P&gt;Good afternoon everyone, is it possible to set up a Site-to-Site VPN between a site with a Palo Alto Private IP and a Palo Alto Public IP.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Site Privado: PaloAlto---IpWan-192.168.1.254---Router/Modem--------Internet-------Site Publico:IPWan:190.100.100.200&lt;/P&gt;&lt;P&gt;Thank you very much for your help and support, I remain attentive.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 18:37:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/424547#M94265</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2021-08-04T18:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site-to-Site Private IP and Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/424562#M94266</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes it is! On the PAN with the private IP address make sure to give it a Local IP Address in the IKE Gateway setting.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1628107014575.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35455i70D1862A200431F6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1628107014575.png" alt="OtakarKlier_0-1628107014575.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then on the other PAN point the IKE gateway at the public IP address however in the Ike Gateway, put in the Peer Address:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_1-1628107087842.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35456iC9D8E368E92031DD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_1-1628107087842.png" alt="OtakarKlier_1-1628107087842.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 19:58:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/424562#M94266</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-08-04T19:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site-to-Site Private IP and Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/424565#M94268</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good afternoon, thank you for your reply.&lt;/P&gt;&lt;P&gt;On the private IP side, I don't need to do any NAT or Port-Forwarding ?&lt;BR /&gt;That configuration would be enough ?&lt;/P&gt;&lt;P&gt;I remain attentive, thank you very much&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 21:16:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/424565#M94268</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2021-08-04T21:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site-to-Site Private IP and Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/564509#M114227</link>
      <description>&lt;P&gt;Hi, any details setting for the ike gateway for both site?&lt;/P&gt;
&lt;P&gt;I need create port forward at the site using internal ip as wan ip (udp500,udp4500) on my ISP router?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 13:40:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/564509#M114227</guid>
      <dc:creator>zlling</dc:creator>
      <dc:date>2023-11-06T13:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site-to-Site Private IP and Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/564643#M114248</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;For your ISP router, dont have it filter anything. Leave it wide open and let the Palo Alto handle the traffic.&lt;/P&gt;
&lt;P&gt;Just my thoughts.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 16:48:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/564643#M114248</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-11-07T16:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site-to-Site Private IP and Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/564644#M114249</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179185"&gt;@Metgatz&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Apologies for the late response. For the VPN tunnel, no. If the traffic is going out the internet, then internal to external traffic will need attention.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 16:49:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/564644#M114249</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-11-07T16:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site-to-Site Private IP and Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/564701#M114252</link>
      <description>&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;thank you for your reply and collaboration.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-txoke809" class="-Zro6 -ZADH IjV6v _57WYp"&gt;&lt;SPAN class="d0767"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;I understand that it is feasible, I have not had to do it, but I understand that it is possible to do the following.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;Scenario:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;-Palo Alto Firewall Static Public IP directly connected to PA Interface.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;-Firewall fortigate behind traditional Modem/Route/OTN almost domiciliary with Dynamica public IP but with private IP in &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;its WAN interface of the fortigate.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-as0gv817" class="-Zro6 -ZADH IjV6v _57WYp"&gt;&lt;SPAN class="d0767"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;I.e.:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;PaloAlto-Untrust-Interface-Static dedicated Public IP=======Internet=====VPN-Site-to-Site=============Dynamic-IP-traditional-Internet-Modem-ISP=====NAT===Private WAN IP Fortigate.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-r054h821" class="-Zro6 -ZADH IjV6v _57WYp"&gt;&lt;SPAN class="d0767"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;I can set up a Site to Site VPN tunnel between a Palo Alto FW with dedicated static public IP coming directly to the AP against a Fortigate firewall behind a traditional ISP modem/router/nat.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-f8znk823" class="-Zro6 -ZADH IjV6v _57WYp"&gt;&lt;SPAN class="d0767"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;Is it feasible to realize this IPSEC tunnel, that is stable, operates correctly ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-dc4l4825" class="-Zro6 -ZADH IjV6v _57WYp"&gt;&lt;SPAN class="d0767"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;What aspects, configurations, settings, etc. should I consider when making this configuration?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-lnass827" class="-Zro6 -ZADH IjV6v _57WYp"&gt;&lt;SPAN class="d0767"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;Thanks as always for the collaboration, good vibes and for all the advice and your time in answering.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="viewer-fnau9829" class="-Zro6 -ZADH IjV6v _57WYp"&gt;&lt;SPAN class="d0767"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P class="-Zro6 -ZADH IjV6v AnCKd _57WYp"&gt;&lt;SPAN class="d0767"&gt;&lt;SPAN&gt;Greetings and very attentive to your comments.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 01:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/564701#M114252</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2023-11-08T01:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site-to-Site Private IP and Public IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/565379#M114340</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I not know the Fortigate devices well but on the Palo Alto you will setup the following:&lt;/P&gt;
&lt;P&gt;Network &amp;gt; Network Profiles &amp;gt; IKE Gateways &amp;gt; General&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Peer IP Address = the public IP address on the other side (Fortigate side of hte ISP moden doing the NAT)&lt;/LI&gt;
&lt;LI&gt;Peer Identification = the Private NAT'ed IP of the Fortigate device.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 15:22:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-private-ip-and-public-ip/m-p/565379#M114340</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-11-13T15:22:59Z</dc:date>
    </item>
  </channel>
</rss>

