Dynamic VPN

cancel
Showing results for 
Search instead for 
Did you mean: 

Dynamic VPN

Not applicable

Dear PaloAlto Support,

Does Palo Alto support this VPN feature such as  Dynamic VPN or Easy VPN?

Customer will use  Cisco Router at their branches. They want to connect VPN from all  branches to their HQ. All branches will have dynamic IP and HQ will have static  IP.

Thanks,

3 REPLIES 3

L5 Sessionator

Hi Ovan,

PAN devices don't support Cisco's proprietary Dynamic Multipoint VPN or Easy VPN.  You can configure the PAN to create tunnels with third party security devices, however.   Connections between the central site and multiple remote sites would require VPN tunnels for each central-remote site pair and configuration of appropriate policies, DH parameters and encryption algorithms.

Not applicable

Thank nrice,

But If I want to test Dynamic VPN with 2 PaloAlto appliance, can I?

I have 2 line Internet:

    +Line 1:

-IP Public: 123.21.40.167 (dynamic IP)

-Modem's IP: 172.16.1.254/24

-PaloAlto1 Layer 3:  Zone-Internet: 172.16.1.120/24

                            Zone-LAN: 192.168.5.0/24

-Modem NAT port 1723 to IP 172.16.1.120

     +Line 2: 222.253.113.230 (static IP)

-Modem's IP: 192.168.81.254/24

-PaloAlto2 Layer 3:  Zone-Internet:  192.168.81.98/24

                            Zone-LAN:  192.168.2.0/24

-Modem NAT port 1723 to IP 192.168.81.98

Both 2 PaloAlto, I configured IKE Gateway to point direct 2 IP public (still not use Dynamic option) but when I SSH to PaloAlto, and type 'show vpn flow' the state is init (not inactive) (please refer the attached file: Snapshot VPN-SSH.jpg).

I want to test Dynamic VPN, but I want to ensure that IPSec VPN running well first.

I uploaded some snapshots and the configuration file, please refer the attached files and help to solve this problem.

Many thanks,

Ovan

Skype: ovan_pham

L5 Sessionator

Ovan,

Please contact Support so that they can assist you with your configuration.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!