PA support point to multipoint IPSEC VPN?

Reply
L4 Transporter

PA support point to multipoint IPSEC VPN?

Hello

 

Does PA support point to multipoint IPSEC in hub and spoke VPN envorirnmet? Means Only one tunnel interface we create on hub and through NHTB protocol, nexthop is bind to SA.

 

Regards,

 

GR

L4 Transporter

Re: PA support point to multipoint IPSEC VPN?

L4 Transporter

Re: PA support point to multipoint IPSEC VPN?

Hello

 

Thanks for the reply. I will go through this. It seems like getvpn of cisco or group vpn of juniper srx. I just want to know that for traditional hub and spoke VPN, hub has to confiugre one tunnel interface per spoke. Is there way we can confiugre only one tunnel interface making it point to multipoint like in Juniper and Cisco DMVPN

L7 Applicator

Re: PA support point to multipoint IPSEC VPN?

No, Large scale VPN is NOT point to multi-point tunnels.  Rather this is a method to use SSL VPN in order to semi-automate with minimal config getting VPN setup from remote sites to the hub.

 

Currently I can find no additions to the PA VPN instructions for point to multi point tunnels.  The hub and spoke documentation lists using separate tunnels for each site as routed links

 

https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Configuring-Hub-and-Spoke-Route-based-VPN/ta...

 

You should contact your sales engineer to discuss future feature release plans as PA won't discuss these in public forums.  You should also confirm that point to multi point tunnel interfaces are already in the "Feature Request" database and add your company vote for the feature.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
Highlighted
L4 Transporter

Re: PA support point to multipoint IPSEC VPN?

thank you

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!