- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-08-2011 07:54 AM
Hi ,
You can use the Easy VPN setup in Cisco ASA to create a site to site VPN from a remote site that does not have a static IP address associated with it. Is it possible to do the same when the Main Office device is a Palo Alto firewall ?
The remote office device will be a Cisco ASA configured to initiate a IPSEC connection to the corporate Palo Alto device. But I need Palo to be configured to accept the IPSEC connection irrespective of the source IP from which the ASA initiates the connection. Is this possible ?
If so , could you briefly describe how it is done ?
Regards,
Sunil
09-10-2011 10:37 AM
Yes this is possible. On PA side you would need to be able to identify the peer by means other than IP. That usually means FQDN. So Cisco should send local ID as FQDN (i.e. vpn.domain.com). PA side should have same for peer ID. You will also need to have both sides in aggressive mode as well (default is main mode). Otherwise other parameters such as P1 and P2 proposals, preshared keys, proxy-ids, etc. are pretty much same.
Note that in this case the Cisco must always be initiator of the VPN.
-Richard
09-10-2011 10:37 AM
Yes this is possible. On PA side you would need to be able to identify the peer by means other than IP. That usually means FQDN. So Cisco should send local ID as FQDN (i.e. vpn.domain.com). PA side should have same for peer ID. You will also need to have both sides in aggressive mode as well (default is main mode). Otherwise other parameters such as P1 and P2 proposals, preshared keys, proxy-ids, etc. are pretty much same.
Note that in this case the Cisco must always be initiator of the VPN.
-Richard
09-12-2011 12:46 PM
Thanks Richard,
I will try it and confirm if it works.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!