Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Deploying LSVPN ( Large Scale VPN) with NAT !!!

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Deploying LSVPN ( Large Scale VPN) with NAT !!!

L0 Member

I'm newcomer with Palo Alto. I have project to deploy PA using LSVPN . But there is a problem because The Internet Link from ISP & MPLS must Via Router Cisco.

But I wonder , when using Router at Border , that means you must NAT Public IP to Private IP of PA.

So when deploy LSVPN, Traffic is encryped , that mean Router cann't NAT . So how to solve that problem.

I cann't deploy VPN with IPSEC VPN site-to-site because we have many Connection , many HUB & Spoke.

Please help me with answer.

Thanks alot.

1 accepted solution

Accepted Solutions

A drawing of what you're trying to accomplish might help us understand

But I think from what I've read, a static NAT from a public IP on your router to an inside IP on your PA device should solve the problem of having the PA "behind" the router, right?

Encrypted traffic can be NAT'd... why do you think that encrypted traffic from the PA can't be NAT'd by your edge router?

View solution in original post

5 REPLIES 5

L0 Member

SO, i wait for longtime. No one has deployed LSVPN yet ? I have confused what kind of LSVPN Deployment , just like SSL VPN or IPSec VPN,  and however, if i use with Router, so what Port i need to Allow for LS VPN.

thank so much .

A drawing of what you're trying to accomplish might help us understand

But I think from what I've read, a static NAT from a public IP on your router to an inside IP on your PA device should solve the problem of having the PA "behind" the router, right?

Encrypted traffic can be NAT'd... why do you think that encrypted traffic from the PA can't be NAT'd by your edge router?

Yeah, i have uploaded my Topology .

GSO-Overral-V6.png

We have 3 site. 1 is HQ, 2 Branch.

Every Bratnch have two Connection to HQ via MPLS & Internet.

Now we want to Make VPN to secure Connection . We using LSVPN .But we still have Router infront of PaloAlto

PaloAlto have function like VPN Gateway.

I have some questions:

1 . If we config Static NAT 1-to-1 on Router , is this true ?

2.  Actually, i don't know what kind of LSVPN , SSL or IPSec, because  IF that is IPSec , we will NAT in Router with Port 500 &4500 , IF SSL VPN, how ?

3.  When configuring GlobalProtect ,  IP when we configure GlobalPortal & GlobalGateway  is using Private IP of Palo Alto or using Public IP which provided by ISP.

I have test that LAB. I have answer for my question .

In router , we make Static NAT 1-to-1

When configure GlobalProtect in HUB. , some infomations are very important.

1. When generating Certificate from CA , you must using Common Name is Public IP of HUB . In this scenaro is 222.0.0.1

2. When configure Global Portal from HUB,  in Satellite Configuration --- Gateway is : Private IP of Hub . In this scenaro is 192.168.1.2

When configure in Spoke ... make IPSec tunnel., IP of Portal is : Public IP of HUB  . In this scenaro is 222.0.0.1

Nice! Thanks for sharing your final solution. I haven't done anything with LSVPN yet, but it's in the back of my mind if/when we start deploying remote PA firewalls to some of our remote offices.

  • 1 accepted solution
  • 4563 Views
  • 5 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!