Limit Hub and Spoke PA 460

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Limit Hub and Spoke PA 460

L0 Member

We have done the creation of a tunnel (VPN) as hub and spoke, currently we will connect 203 devices to this tunnel, we have been researching but we have not found information on how many peers this tunnel can support with this hub and spoke configuration? Does anyone know the limit of devices that can be linked to the same tunnel?

 

If there is documentation on this information, could you please share it?

4 REPLIES 4

L2 Linker

Hello @Cristian_Soler ,

 

According to the product specification, a PA-460 can have maximum of 2800 IPSec Site-to-Site VPN peers.

 

AlinScarlat_0-1694057797986.png

 

Please find more information on this link by searching for your product.

 

I hope this helps.

Don't forget to Like if you find this post helpful

Thanks for the answer

We only want to have one (1) VPN on this PA-460, we don't want to configure site to site, but site to many sites.
In theory if my PA-460 is my HUB and the other devices(Forti, Cisco, etc) are the spoke for a total of 203.
Could I say that with a single tunnel (Ipsec) configured on my PA 460 I can support up to 2800 spoke at the same time through that single tunnel we will have

L2 Linker

Hello @Cristian_Soler ,

 

In theory, even if you have a single tunnel interface in a hub-and-spoke topology, you would have multiple ISAKMP and IPSec sessions, one for each spoke (like Cisco has with DMVPN and other VPN technologies). As far as I know, a tunnel interface can have up to 250 proxy IDs.

 

The information presented above is the platform limit presented by Palo Alto regarding IPSec VPNs.

 

I hope this helps.

Don't forget to Like if you find this post helpful

Cyber Elite
Cyber Elite

@Cristian_Soler,

Keep in mind that you'll hit your proxy-id limit for a single tunnel well before you'd hit your max IKE limit. Seeing as you already have 203 peers I'd be cautious on what your actual proxy-id requirements will be at present, and what they'll be going forward if you intend to see any growth. 

  • 1720 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!