- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-06-2023 05:46 AM
I want build IPsec connection bwtween HQ and Branch Office.
HQ using Public IP with fixed.
Branch Office using Internal IP with fixed. (have one ISP router above firewall)
May know the details setting?
and i need create port forward udp500,4500 on my ISP router?
11-06-2023 07:18 AM
Does Branch Site have static IP?
Do you have capability to configure port forwarding on ISP router?
11-06-2023 04:44 PM
Does Branch Site have static IP?
-Yes, branch office have static IP but with internal IP.
Do you have capability to configure port forwarding on ISP router?
-I have done configure port forward in my ISP router. (udp500,4500,4510,4511)
I'm new to PaloAlto, so I not sure the details setting in PaloAlto. I had see some discussion about the setting needed in IPsec when one of the site using an internal IP as wan IP. After trying the step mentioned, but failed. So may share to me the detail setting at both site? we need enable NAT-Traversal at both site? we need usingaggresive mode at both site? what need to configure in local & peer identification at both site?
Thank you.
11-06-2023 05:46 PM - edited 11-06-2023 05:48 PM
You need to NAT only udp/500 and udp/4500.
On "Advanced Options" tab check "Enable NAT Traversal" checkbox and you are done.
You do not need aggressive mode.
11-06-2023 07:13 PM
Hi,
I had try this way. IPsec connection still failed to build.
Does IPsec function need license?
Thank you.
11-06-2023 07:23 PM
No license needed.
How do you identify that tunnel fails to build?
Do you see anything in system log?
If you enter command below and check System logs on other side what do you see?
test vpn ipsec-sa tunnel name-of-the-ipsec-tunnel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!