IPsec Tunnel with Loopback and NAT

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

IPsec Tunnel with Loopback and NAT

L0 Member

Hi

 

I have 2 questions.

1. I want to create an IPSec tunnel, using a loopback interface.

This removes a dependency on the main interface ip. ie if the loopback ip is :3.4.5.2, and the main internet ip is changed from 3.4.5.1 to 3.4.5.30, this then doesn't impact the IPSec tunnel.

 

After the IPSec tunnel is online.

2. I want to NAT the communication from different ip's across several internal subnets to a specific 10.x.x.x/24 subnet as the new "source". This subnet is then used to communicate to Site B's internal subnets. This masks Site A internal subnets and removes additional configuration requirements from Site B, when additional Site A subnets are enabled.

CherieWatts_3-1662410895804.png

Can anyone direct me to the pertinent doco to look up how to do my NAT, ie question 2?

 

Doesn't anyone see any major issues with this design?

Thanks for any feedback

 

 

 

 

 

 

1 accepted solution

Accepted Solutions

L0 Member

Hi OtakarKlier,

I implemented the site-to-site vpn yesterday and its all working correctly.

I am really happy.

Thanks

Cherie

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

So since the traffic is sourced from site A and you are putting the NAT into site A's firewall. You can use a Source NAT, if you are putting the NAT rules in firewall B, then use a Destination NAT.

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/source-nat-and-destination...

Hope this helps.

L0 Member

Hi OtakarKlier,

I implemented the site-to-site vpn yesterday and its all working correctly.

I am really happy.

Thanks

Cherie

Cyber Elite
Cyber Elite

Nice work!

  • 1 accepted solution
  • 2866 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!