VPN with overlapping subnets

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

VPN with overlapping subnets

L3 Networker

We have recently acquired 3 companies and all are using 192.168.1.0/24 as their local subnet.  Now in a perfect world I could just go on-site and and change the addresses, but as well all know it's not and they have critical services running on AS400 systems that need to remain online during the transition.  So here is where NAT comes in.  I need to establish 3 IPSec tunnels and basically say that when traffic is going to 172.16.200.x (for example) go through tunnel.200 and change the IP back to 192.168.1.x.  And...when traffic comes from 192.168.1.x through tunnel.200 change to 172.16.200.x.  I know this can be done (as I have done it on Cisco and SonicWALL), but am just drawing a blank on how to set it up on the PA.  Any thoughts?

6 REPLIES 6

L6 Presenter

L5 Sessionator

Here is an old document, but the concept and the steps still holds good while building VPNs for overlapping subnets.

https://live.paloaltonetworks.com/docs/DOC-1594

You will require Static Bi directional NAT configuration in order to have a seamless flow of traffic for these over lapping subnets, via the VPN

BR,

Karthik

Their device only supports policy based VPNs not route based.  Would I do the same thing?

Hi,

Doesn't matter. Policy or toute based VPN is important for VPN config after that, subnet overlapping will be solved by NAT.

Hope help.

V.

Hi,

I have similar network overlapping problem ( 3 VPN L2L where remote networks are same, 192.168.1.0/24 and the hub network is 172.31.224.0/24 on PA500). But the remote firewalls are not PAN and I have not management on they. To access the central resources, the remote firewalls have to establish L2L tunnel and connect the remote same networks to hub network. How can I solve this problem by only the PAN configuration ?

Thanks.

The same thing would work for you as well; I'm assuming that you can at least give the remote sites directions on how there end needs to look. If not then you are surely out of luck as far as the configuration goes, there is no way to setup a tunnel without configuring the other end 

  • 6039 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!