- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-06-2023 06:22 PM - edited 09-06-2023 06:24 PM
We have done the creation of a tunnel (VPN) as hub and spoke, currently we will connect 203 devices to this tunnel, we have been researching but we have not found information on how many peers this tunnel can support with this hub and spoke configuration? Does anyone know the limit of devices that can be linked to the same tunnel?
If there is documentation on this information, could you please share it?
09-06-2023 08:38 PM - edited 09-06-2023 08:39 PM
Hello @Cristian_Soler ,
According to the product specification, a PA-460 can have maximum of 2800 IPSec Site-to-Site VPN peers.
Please find more information on this link by searching for your product.
I hope this helps.
09-06-2023 09:07 PM - edited 09-06-2023 09:08 PM
Thanks for the answer
We only want to have one (1) VPN on this PA-460, we don't want to configure site to site, but site to many sites.
In theory if my PA-460 is my HUB and the other devices(Forti, Cisco, etc) are the spoke for a total of 203.
Could I say that with a single tunnel (Ipsec) configured on my PA 460 I can support up to 2800 spoke at the same time through that single tunnel we will have
09-08-2023 10:44 AM
Hello @Cristian_Soler ,
In theory, even if you have a single tunnel interface in a hub-and-spoke topology, you would have multiple ISAKMP and IPSec sessions, one for each spoke (like Cisco has with DMVPN and other VPN technologies). As far as I know, a tunnel interface can have up to 250 proxy IDs.
The information presented above is the platform limit presented by Palo Alto regarding IPSec VPNs.
I hope this helps.
09-11-2023 08:18 PM
Keep in mind that you'll hit your proxy-id limit for a single tunnel well before you'd hit your max IKE limit. Seeing as you already have 203 peers I'd be cautious on what your actual proxy-id requirements will be at present, and what they'll be going forward if you intend to see any growth.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!