I have a HQ PAN connecting to a remote ASA and IPSec is up with static routes and proxy IDs. Have installed and configured a new PAN parallel to remote ASA which is going to be replacing it
Question is, can i have a new VPN configured in HQ to new remote PAN, where the proxy IDs will be same as the operational one? The remote IP for PAN is different from ASA. Also static route needs to be there for smooth migration
Solved! Go to Solution.
The PAN's are route based VPN so you can bring up the tunnel without any proxy-id's and then when you are ready to migrate to the remote PAN, just change the routes to go down that tunnel instead. One thing I did when working with remote PAN's is allow the external interface be a management interface but only from my data center IP's. That way if something happened with the tunnel, I could still access the remote PAN.
Hope that helps.
Thanks for the reply
i think i understand it now after your explanation and discussion at below link
PAN to PAN VPN doesnt need proxy ID, and traffic will only pass through VPN when i route to it...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!