- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-14-2021 11:38 AM
Site-to-Site VPN with PPPoE
Good afternoon, please help me to confirm if the following scenarios are compatible or not.
- Palo Alto with Interface in DHCP mode ( with private IP - Typical example ADLS modem delivering a Private IP ) establish a site-2-site vpn tunnel with another Palo Alto with Public IP.
-Palo Alto with interface in PPPoE mode (with Public IP) establish a Site-2-Site VPN tunnel with another Palo Alto with Public IP.
Thank you very much, best regards
07-15-2021 05:46 AM
1. yes, you do need to enable NAT-T, then set the local-ID on the dynamic peer, and add the same ID as 'remote ID' on the static peer. the static peer also needs to be set as 'passive' so it doesn't try to connect to the dynamic peer
2. yes, simply use the local-ID on the dynamic peer and remote-ID on the static peer
the id can be any FQDN or email address (doesn't need to be real or resolve to anything, it just needs to match on both peers)
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!