Site to Site VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Site to Site VPN

L1 Bithead

Quick question on setting a site to site vpn, using tunnel mode. If I have a site "A" peer going and connecting with a site "B" peer for a VPN, can both sites have the same IP address subnet, or will that conflict? 

 

Scenario:

  Site A: 192.168.20.5/24 (Local LAN)

  Site B: 192.168.20.88/24 (Local LAN)

 

Would a NAT be required within the Palo Alto Firewall if I did not change one of sites subnets?

1 accepted solution

Accepted Solutions

Community Team Member

Hi @ITSMC24 ,

 

No prob! As far as adding additional remote sites in the future, I would recommend to ensure CIDRs are free to use and not overlapping. This way you don't have to rely on setting up NAT and you can perform full routing. I would definitely reserve some space within your network for remote sites. 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

5 REPLIES 5

Community Team Member

Hi @ITSMC24 ,

 

Yes, you will need to create a unique subnet that doesn't overlap with any of your managed subnets, make sure you point routing to those new subnets via the tunnel, and create the appropriate NAT policies. 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Cyber Elite
Cyber Elite

@ITSMC24,

To expand on what @JayGolf mentioned; you can either set this up as is and utilize NAT to get around the conflicting subnets, or you take the easier route and change one side. It's easiest in a lot of environments to just forgo the overlapping subnets if possible so you don't have to worry about setting specific DNS entries or the like up to direct traffic from one network to the next.

 

If you need to deal with the overlapping subnets, and it looks like you just need access to a single node, that would be done via NAT to remove the conflict. There used to be a good KB about this that appears to have been removed, but THIS describes the process perfectly fine with a quick search. That should help get you in the right direction.

L1 Bithead

All,

  @JayGolf and @BPry Thank you for the insight on this subject matter. For the one side NAT, if I choose to add more remote sites in the future then would I have to create a one-site NAT to each of the remote tunnels? 

 

Thanks again, this was very helpful. 

Community Team Member

Hi @ITSMC24 ,

 

No prob! As far as adding additional remote sites in the future, I would recommend to ensure CIDRs are free to use and not overlapping. This way you don't have to rely on setting up NAT and you can perform full routing. I would definitely reserve some space within your network for remote sites. 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L1 Bithead

Sounds good, thanks JayGolf. 

  • 1 accepted solution
  • 688 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!