New site to site VPN creation with same proxy IDs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

New site to site VPN creation with same proxy IDs

L1 Bithead

Hi

I have a HQ PAN connecting to a remote ASA and IPSec is up with static routes and proxy IDs. Have installed and configured a new PAN parallel to remote ASA which is going to be replacing it

Question is, can i have a new VPN configured in HQ to new remote PAN, where the proxy IDs will be same as the operational one? The remote IP for PAN is different from ASA. Also static route needs to be there for smooth migration

 

Thanks

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hello,

The PAN's are route based VPN so you can bring up the tunnel without any proxy-id's and then when you are ready to migrate to the remote PAN, just change the routes to go down that tunnel instead. One thing I did when working with remote PAN's is allow the external interface be a management interface but only from my data center IP's. That way if something happened with the tunnel, I could still access the remote PAN.

 

Hope that helps.

 

Regards,

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello,

The PAN's are route based VPN so you can bring up the tunnel without any proxy-id's and then when you are ready to migrate to the remote PAN, just change the routes to go down that tunnel instead. One thing I did when working with remote PAN's is allow the external interface be a management interface but only from my data center IP's. That way if something happened with the tunnel, I could still access the remote PAN.

 

Hope that helps.

 

Regards,

Thanks for the reply

i think i understand it now after your explanation and discussion at below link

https://live.paloaltonetworks.com/t5/Learning-Articles/Proxy-ID-for-VPNs-Between-Palo-Alto-Networks-...

PAN to PAN VPN doesnt need proxy ID, and traffic will only pass through VPN when i route to it...

  • 1 accepted solution
  • 2605 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!