I'm on a manual STS VPN homologation from fortigate, and I have address pools declared in the encryption domains, which translates to too many proxy id's for palo alto, is there any way to configure this without having to generate so many proxy id? I know you can't use groups, but can you do something with variables or any ideas?
is there a way for you to replace the pools with actual subnets?
the Palo Alto firewalls doesn't need Proxy-IDs to function, only if the remote end requires these should they be set up
subnets are the more common practice when adding Proxy-IDs (for each unique ID pair, both devices need to create a Security Association, so for a subnet you only need 1 set, but for 1:1 you would need hundreds of SAs the firewalls need to maintain)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!