Limitations for creating number of child sa for site to site vpn

Showing results for 
Search instead for 
Did you mean: 

Limitations for creating number of child sa for site to site vpn

L1 Bithead


Here I am trying to create a site to site vpn in Paloalto firewall, now in local network I have 8 individual /32 ips and for remote 10 individual /32 ips. This is for policy based vpn. Now if I add proxy ids for local and remote ips. I am getting around 80 proxy ids. Requirement is to only use ips not subnets. Now few connections are not working though it is allowed and phase 2 is up. I want to confirm if there is any limitations in creating total numbers of proxy ids and if it creates any impact in performance of the firewall?


Cyber Elite
Cyber Elite

proxy id's are essentially individual vpn tunnels, so you're setting up 80 vpn tunnels

what kind of platform are you stting this up on? 

Tom Piens

We are creating a single site to site vpn between PA-220 and FTD firewall and within that multiple /32 ips needs to communicate


See if the IP's can fit into a subnet. Also you can just create one proxy id, all the ip's/subnets and then use policies to limit the traffic.


Just some thoughts.


Correct, but as @reaper mentioned in his previous comment any time you add a proxy id you are essentially adding another tunnel. So as far as your firewall is concerned it's going to create what amounts to 80 tunnels to support all of the Proxy IDs you are trying to configure. 

I just found my answer in the PaloAlto PSNSE Study guide, under Topic Tunnel interface. " Tunnel interface can have a maximum of 250 proxy IDs. Each proxy ID counts toward the IPsec VPN tunnel capacity of the firewall, and the tunnel capacity varies by the firewall model. "

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!