- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-11-2020 01:24 AM
Hi,
Here I am trying to create a site to site vpn in Paloalto firewall, now in local network I have 8 individual /32 ips and for remote 10 individual /32 ips. This is for policy based vpn. Now if I add proxy ids for local and remote ips. I am getting around 80 proxy ids. Requirement is to only use ips not subnets. Now few connections are not working though it is allowed and phase 2 is up. I want to confirm if there is any limitations in creating total numbers of proxy ids and if it creates any impact in performance of the firewall?
06-11-2020 06:28 AM
proxy id's are essentially individual vpn tunnels, so you're setting up 80 vpn tunnels
what kind of platform are you stting this up on?
06-11-2020 11:49 AM
We are creating a single site to site vpn between PA-220 and FTD firewall and within that multiple /32 ips needs to communicate
06-15-2020 02:56 PM
Hello,
See if the IP's can fit into a subnet. Also you can just create one proxy id, all the ip's/subnets and then use policies to limit the traffic.
Just some thoughts.
06-15-2020 07:46 PM
Correct, but as @reaper mentioned in his previous comment any time you add a proxy id you are essentially adding another tunnel. So as far as your firewall is concerned it's going to create what amounts to 80 tunnels to support all of the Proxy IDs you are trying to configure.
06-19-2020 11:06 PM
I just found my answer in the PaloAlto PSNSE Study guide, under Topic Tunnel interface. " Tunnel interface can have a maximum of 250 proxy IDs. Each proxy ID counts toward the IPsec VPN tunnel capacity of the firewall, and the tunnel capacity varies by the firewall model. "
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!