Multiple Cisco Router IPSec tunnels to single Palo Alto IPSec Tunnel

Announcements
Attention: The LIVEcommunity is experiencing an interruption with videos in some areas. We apologize for any inconvenience this may cause. Thank you for your patience as we work towards a solution to restore videos.
Reply
Highlighted
L3 Networker

Multiple Cisco Router IPSec tunnels to single Palo Alto IPSec Tunnel

Dear peers,

 

I have been fighting an issue for about a month regarding issues running Cisco DMVPN behind a static 1-to-1 NAT address (VeloCloud not a Palo Alto).  I am currently still trying to ascertain if this is an issue with the VeloCloud appliance (I have a ticket open with them) or moving the Cisco DMVPN solution behind a NAT.  


This being said, I was wondering if there is a way to setup a "many-to-one" configuration for VPN in my Palo Alto that would where I could configure my remote Cisco routers (public DHCP or static) to connect to a single tunnel.  I know that I wont get full mesh or nhrp shortcuts, but at this point I am looking to move a few Cisco devices to the Palo Alto to rule out DMVPN itself as being an issue.  Is this possible?  Can  anyone cite a configuration example?


Thanks,


Matt

Highlighted
L7 Applicator

Re: Multiple Cisco Router IPSec tunnels to single Palo Alto IPSec Tunnel

Hello,

Can you clarify what you mean by single tunnel? I just dont want to steer you in a wrong direction. The PAN can have many IPSEC tunnels going to it on the same local IP address from many remote IP's (not sure if this is what you mean).

 

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/vpns/set-up-site-to-site-vpn

 

https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/vpns/site-to-site-vpn-quick-configs

 

Let us know so we can help.

 

Cheers!

Highlighted
L3 Networker

Re: Multiple Cisco Router IPSec tunnels to single Palo Alto IPSec Tunnel

What I'm really looking for is the LSVPN type solution without having to have all Palo Alto endpoints.


Right now I have over 100+ telecommuters terminated on one "tunnel" in my Cisco solution.  While I know I could create individual site-to-site VPN tunnels for each of these routers, I would rather not configure 100+ individual tunnels in the Palo Alto.


I've done site-to-site before.. just never tried to connect multiple endponts to the same VPN tunnel.

Highlighted
L7 Applicator

Re: Multiple Cisco Router IPSec tunnels to single Palo Alto IPSec Tunnel

Hi @mlinsemier

 

This would be something really interessting to try out. In theory it should work with global protect (client or satellite configuration) as this is a standard/RFC compliant IPSec VPN connection. But if this really works in a real situation, I have no idea.

If you try it, please share your results here in the live community.

 

Regards,

Remo

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!