Here I am trying to create a site to site vpn in Paloalto firewall, now in local network I have 8 individual /32 ips and for remote 10 individual /32 ips. This is for policy based vpn. Now if I add proxy ids for local and remote ips. I am getting around 80 proxy ids. Requirement is to only use ips not subnets. Now few connections are not working though it is allowed and phase 2 is up. I want to confirm if there is any limitations in creating total numbers of proxy ids and if it creates any impact in performance of the firewall?
proxy id's are essentially individual vpn tunnels, so you're setting up 80 vpn tunnels
what kind of platform are you stting this up on?
We are creating a single site to site vpn between PA-220 and FTD firewall and within that multiple /32 ips needs to communicate
See if the IP's can fit into a subnet. Also you can just create one proxy id, all the ip's/subnets and then use policies to limit the traffic.
Just some thoughts.
I just found my answer in the PaloAlto PSNSE Study guide, under Topic Tunnel interface. " Tunnel interface can have a maximum of 250 proxy IDs. Each proxy ID counts toward the IPsec VPN tunnel capacity of the firewall, and the tunnel capacity varies by the firewall model. "
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!