PA support point to multipoint IPSEC VPN?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PA support point to multipoint IPSEC VPN?

L4 Transporter

Hello

 

Does PA support point to multipoint IPSEC in hub and spoke VPN envorirnmet? Means Only one tunnel interface we create on hub and through NHTB protocol, nexthop is bind to SA.

 

Regards,

 

GR

1 accepted solution

Accepted Solutions

No, Large scale VPN is NOT point to multi-point tunnels.  Rather this is a method to use SSL VPN in order to semi-automate with minimal config getting VPN setup from remote sites to the hub.

 

Currently I can find no additions to the PA VPN instructions for point to multi point tunnels.  The hub and spoke documentation lists using separate tunnels for each site as routed links

 

https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Configuring-Hub-and-Spoke-Route-based-VPN/ta...

 

You should contact your sales engineer to discuss future feature release plans as PA won't discuss these in public forums.  You should also confirm that point to multi point tunnel interfaces are already in the "Feature Request" database and add your company vote for the feature.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

View solution in original post

4 REPLIES 4

L4 Transporter

Hello

 

Thanks for the reply. I will go through this. It seems like getvpn of cisco or group vpn of juniper srx. I just want to know that for traditional hub and spoke VPN, hub has to confiugre one tunnel interface per spoke. Is there way we can confiugre only one tunnel interface making it point to multipoint like in Juniper and Cisco DMVPN

No, Large scale VPN is NOT point to multi-point tunnels.  Rather this is a method to use SSL VPN in order to semi-automate with minimal config getting VPN setup from remote sites to the hub.

 

Currently I can find no additions to the PA VPN instructions for point to multi point tunnels.  The hub and spoke documentation lists using separate tunnels for each site as routed links

 

https://live.paloaltonetworks.com/t5/Tech-Note-Articles/Configuring-Hub-and-Spoke-Route-based-VPN/ta...

 

You should contact your sales engineer to discuss future feature release plans as PA won't discuss these in public forums.  You should also confirm that point to multi point tunnel interfaces are already in the "Feature Request" database and add your company vote for the feature.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

thank you

  • 1 accepted solution
  • 6357 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!