<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Do I configure proxy-id in ipsec-vpn certainly? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12881#M9442</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is proxy-id in ipsec-vpn configuration??&lt;/P&gt;&lt;P&gt;Why does it need??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will use ipsec-vpn on PA-2020 &amp;amp; PA-500.&lt;/P&gt;&lt;P&gt;Each devices have 15 proxy-id(remote-networks).&lt;/P&gt;&lt;P&gt;I know one tunnel interface has 10 proxy-ids.&lt;/P&gt;&lt;P&gt;So I have tested without proxy-id that traffics are processed routing-table(next-hop tunnel interface) to 15 remote-networks.&lt;/P&gt;&lt;P&gt;It is normal. Do I configure proxy-id in ipsec-vpn certainly??&lt;/P&gt;&lt;P&gt;What problem does it has if I configure ipsec-vpn without proxy-id???&lt;/P&gt;&lt;P&gt;Or please let me know if you know other good way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Apr 2013 08:56:05 GMT</pubDate>
    <dc:creator>KiCheon.Lee</dc:creator>
    <dc:date>2013-04-23T08:56:05Z</dc:date>
    <item>
      <title>Do I configure proxy-id in ipsec-vpn certainly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12881#M9442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is proxy-id in ipsec-vpn configuration??&lt;/P&gt;&lt;P&gt;Why does it need??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will use ipsec-vpn on PA-2020 &amp;amp; PA-500.&lt;/P&gt;&lt;P&gt;Each devices have 15 proxy-id(remote-networks).&lt;/P&gt;&lt;P&gt;I know one tunnel interface has 10 proxy-ids.&lt;/P&gt;&lt;P&gt;So I have tested without proxy-id that traffics are processed routing-table(next-hop tunnel interface) to 15 remote-networks.&lt;/P&gt;&lt;P&gt;It is normal. Do I configure proxy-id in ipsec-vpn certainly??&lt;/P&gt;&lt;P&gt;What problem does it has if I configure ipsec-vpn without proxy-id???&lt;/P&gt;&lt;P&gt;Or please let me know if you know other good way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 08:56:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12881#M9442</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-04-23T08:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Do I configure proxy-id in ipsec-vpn certainly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12882#M9443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000;"&gt;What is proxy-id in ipsec-vpn configuration??&lt;SPAN style="font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Why does it need??&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="color: #000000; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;A proxy-IDs&amp;nbsp; are negotiated during&amp;nbsp; Phase II tunnel establishment and define the Traffic that needs to be Encrypted or the Interested Traffic for an IPSEC tunnel.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="color: #000000; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Policy Based VPN define this using a &lt;SPAN style="font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;combination of SRC IP, DST&amp;nbsp; IP, and SERVICES&amp;nbsp; in a tunnel policy.&lt;/SPAN&gt; (Eg : Security Rules in Juniper for Policy Based VPNs or ACLs in Cisco).&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="color: #000000; font-family: arial, sans-serif; line-height: 1.5em;"&gt;Route Based VPN use a logical L3&amp;nbsp; tunnel interface ,traffic destined for the Tunnel is Encrypted and use 0.0.0.0/0 as Proxy IDs by default.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: arial, sans-serif; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;PA firewalls use Route Based approach hence Proxy-IDs are manually configured&amp;nbsp; On PA firewalls only while connecting with Policy Based VPNs to match the ones configured on the Peer.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline; color: #000000;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="text-decoration: underline; color: #000000;"&gt;&lt;STRONG&gt;Terminology&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000;"&gt;(ACL :: CISCO&amp;nbsp;&amp;nbsp; ||&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PROXY IDs :: Juniper&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ||&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Encryption Domains :: CHKPOINT)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;So the behavior observed is NORMAL and You do not need to configure Proxy IDs for Establishing IPSEC between&amp;nbsp; PA firewalls.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 10:27:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12882#M9443</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-04-23T10:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Do I configure proxy-id in ipsec-vpn certainly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12883#M9444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow, Thanks a million for your detail answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Must not between PA devices be configured proxy-ids?&lt;/P&gt;&lt;P&gt;And must PA device be configured proxy-id when connect policy based vpn such as Cisco , Juniper , CHKPOINT by ipsec-vpn????&lt;/P&gt;&lt;P&gt;Is it right???&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 11:44:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12883#M9444</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-04-23T11:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Do I configure proxy-id in ipsec-vpn certainly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12884#M9445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes thts Right.&lt;/P&gt;&lt;P&gt;No Proxy Ids between 2 PA s&lt;/P&gt;&lt;P&gt;But only for Policy Based VPN using Peer ,in short for Cross Vendor VPNs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 11:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12884#M9445</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-04-23T11:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: Do I configure proxy-id in ipsec-vpn certainly?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12885#M9446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much, Ameya.&lt;/P&gt;&lt;P&gt;I am helpful for you answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 12:02:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-configure-proxy-id-in-ipsec-vpn-certainly/m-p/12885#M9446</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2013-04-23T12:02:48Z</dc:date>
    </item>
  </channel>
</rss>

