How to Build IPsec connection without using Public IP at Branch Site

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How to Build IPsec connection without using Public IP at Branch Site

L1 Bithead

I want build IPsec connection bwtween HQ and Branch Office.

 

HQ using Public IP with fixed.

Branch Office using Internal IP with fixed. (have one ISP router above firewall)

 

May know the details setting?

 

and i need create port forward udp500,4500 on my ISP router?

 

5 REPLIES 5

Cyber Elite
Cyber Elite

Does Branch Site have static IP?

Do you have capability to configure port forwarding on ISP router?

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Does Branch Site have static IP?

-Yes, branch office have static IP but with internal IP.

 

Do you have capability to configure port forwarding on ISP router?

-I have done configure port forward in my ISP router. (udp500,4500,4510,4511)

 

I'm new to PaloAlto, so I not sure the details setting in PaloAlto. I had see some discussion about the setting needed in IPsec when one of the site using an internal IP as wan IP. After trying the step mentioned, but failed. So may share to me the detail setting at both site? we need enable NAT-Traversal at both site? we need usingaggresive mode at both site? what need to configure in local & peer identification at both site?

 

Thank you.

Cyber Elite
Cyber Elite

You need to NAT only udp/500 and udp/4500.

 

On "Advanced Options" tab check "Enable NAT Traversal" checkbox and you are done.

You do not need aggressive mode.

 

Raido_Rattameister_0-1699321537581.png

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi,

 

I had try this way. IPsec connection still failed to build. 

Does IPsec function need license?

 

Thank you.

 

Cyber Elite
Cyber Elite

No license needed.

How do you identify that tunnel fails to build?

Do you see anything in system log?

 

If you enter command below and check System logs on other side what do you see?

test vpn ipsec-sa tunnel name-of-the-ipsec-tunnel

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 1729 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!