- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-19-2018 11:46 AM
Hello,
Are you referring to IPSec tunnels or Tunnel interfaces?
Just curious.
10-19-2018 02:42 PM
i'm going to go with "no"
When you configure an ipsec tunnel, you define what the connection between a local ike gateway and a remote ike gateway will look like (local and remote gateways are configured in the ike object, the connection between the two is configured in the ipsec object)
It's like the network cable that connects a local ethernet port to a remote ethernet port. if you need to connect to another port, you will need another cable
10-22-2018 05:53 AM
No was the answer I was expecting but the cloud company that we are doing a trial with suggested it but I didn't see how it would be possible
10-23-2018 04:58 AM
Hi,
This is not possible because two different gateways have different proxy IDs which will fail the phase 2 negotiation.
10-24-2018 05:09 AM
@Dali_Chauhan @reaper @OtakarKlier
So are the proxy IDs a requirement i didn't think they were
10-24-2018 09:36 AM
Proxy IDs aren't required for an IPSec tunnel. At least not for a route based tunnel - even if there technically the proxy ID 0.0.0.0/0 on both sides is used (thats what paloalto uses if you do not specify proxy IDs). On a paloalto firewall an IPSec tunnel never is policy based as you have to use the routing table to specify what the firewall sends into the tunnel but the proxy IDs are used to configure tunnels to other VPN gateways that only support policy based tunnels or use policy based tunnels for whatever reason.
10-24-2018 09:37 AM
Hello,
It depends on the other VPN device. If its two PAN's then they are not required, if its a PAN and ASA, yes. PAN's VPN is route based and other manufactures are zone based.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!