- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-10-2010 11:41 PM
Dear PaloAlto Support,
Does Palo Alto support this VPN feature such as Dynamic VPN or Easy VPN?
Customer will use Cisco Router at their branches. They want to connect VPN from all branches to their HQ. All branches will have dynamic IP and HQ will have static IP.
Thanks,
01-11-2010 10:10 AM
Hi Ovan,
PAN devices don't support Cisco's proprietary Dynamic Multipoint VPN or Easy VPN. You can configure the PAN to create tunnels with third party security devices, however. Connections between the central site and multiple remote sites would require VPN tunnels for each central-remote site pair and configuration of appropriate policies, DH parameters and encryption algorithms.
01-14-2010 08:29 PM
Thank nrice,
But If I want to test Dynamic VPN with 2 PaloAlto appliance, can I?
I have 2 line Internet:
+Line 1:
-IP Public: 123.21.40.167 (dynamic IP)
-Modem's IP: 172.16.1.254/24
-PaloAlto1 Layer 3: Zone-Internet: 172.16.1.120/24
Zone-LAN: 192.168.5.0/24
-Modem NAT port 1723 to IP 172.16.1.120
+Line 2: 222.253.113.230 (static IP)
-Modem's IP: 192.168.81.254/24
-PaloAlto2 Layer 3: Zone-Internet: 192.168.81.98/24
Zone-LAN: 192.168.2.0/24
-Modem NAT port 1723 to IP 192.168.81.98
Both 2 PaloAlto, I configured IKE Gateway to point direct 2 IP public (still not use Dynamic option) but when I SSH to PaloAlto, and type 'show vpn flow' the state is init (not inactive) (please refer the attached file: Snapshot VPN-SSH.jpg).
I want to test Dynamic VPN, but I want to ensure that IPSec VPN running well first.
I uploaded some snapshots and the configuration file, please refer the attached files and help to solve this problem.
Many thanks,
Ovan
Skype: ovan_pham
01-15-2010 02:51 PM
Ovan,
Please contact Support so that they can assist you with your configuration.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!