- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-28-2016 01:38 PM
Hello
Does PA support point to multipoint IPSEC in hub and spoke VPN envorirnmet? Means Only one tunnel interface we create on hub and through NHTB protocol, nexthop is bind to SA.
Regards,
GR
10-30-2016 05:25 AM
No, Large scale VPN is NOT point to multi-point tunnels. Rather this is a method to use SSL VPN in order to semi-automate with minimal config getting VPN setup from remote sites to the hub.
Currently I can find no additions to the PA VPN instructions for point to multi point tunnels. The hub and spoke documentation lists using separate tunnels for each site as routed links
You should contact your sales engineer to discuss future feature release plans as PA won't discuss these in public forums. You should also confirm that point to multi point tunnel interfaces are already in the "Feature Request" database and add your company vote for the feature.
10-28-2016 05:55 PM
The feature is called Large Scale VPN (LSVPN)
https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/large-scale-vpn-lsvpn
10-29-2016 07:39 AM
Hello
Thanks for the reply. I will go through this. It seems like getvpn of cisco or group vpn of juniper srx. I just want to know that for traditional hub and spoke VPN, hub has to confiugre one tunnel interface per spoke. Is there way we can confiugre only one tunnel interface making it point to multipoint like in Juniper and Cisco DMVPN
10-30-2016 05:25 AM
No, Large scale VPN is NOT point to multi-point tunnels. Rather this is a method to use SSL VPN in order to semi-automate with minimal config getting VPN setup from remote sites to the hub.
Currently I can find no additions to the PA VPN instructions for point to multi point tunnels. The hub and spoke documentation lists using separate tunnels for each site as routed links
You should contact your sales engineer to discuss future feature release plans as PA won't discuss these in public forums. You should also confirm that point to multi point tunnel interfaces are already in the "Feature Request" database and add your company vote for the feature.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!