Múltiple Proxy ID PAN - Migration from FG using group address.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Múltiple Proxy ID PAN - Migration from FG using group address.

L1 Bithead

Hello guys!

 

I'm on a manual STS VPN homologation from fortigate, and I have address pools declared in the encryption domains, which translates to too many proxy id's for palo alto, is there any way to configure this without having to generate so many proxy id? I know you can't use groups, but can you do something with variables or any ideas?

 

Thank you!

1 REPLY 1

Cyber Elite
Cyber Elite

is there a way for you to replace the pools with actual subnets?

 

the Palo Alto firewalls doesn't need Proxy-IDs to function, only if the remote end requires these should they be set up

 

subnets are the more common practice when adding Proxy-IDs (for each unique ID pair, both devices need to create a  Security Association, so for a subnet you only need 1 set, but for 1:1 you would need hundreds of SAs the firewalls need to maintain)

 

 

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1625 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!