- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-18-2022 08:11 AM
Hello Every one
I was trying to build a Site to Site Vpn. I can only select limited interfaces when creating a new Zone. The selection option does not even include the main gateway interface (Ethernet1/10. I have attached a screen shoot of the scenario.
08-18-2022 02:49 PM
Hello @Habte-01
the interfaces you are not able to see in drop down list, are they configured as a Type Layer 3 and are they assigned to Virtual Router?
Kind Regards
Pavel
08-19-2022 12:03 PM
Yes they all are on Vr1 and layer3
08-21-2022 05:17 PM
Thank you for reply @Habte-01
this should be all you need to get an interface available in a zone. An interface can be a member of only one zone. Is the interface you are trying to add already member of existing zone?
Kind Regards
Pavel
08-22-2022 06:41 AM
Thanks Pavel. No it is not.
08-27-2022 05:04 PM
Thank you for reply @Habte-01
I am running out of ideas. Could you please confirm what PAN-OS are you running? I would like to see I can re-produce it by using the same version.
Kind Regards
Pavel
08-29-2022 11:02 AM
Hello Bithead, you might need to create a new interface type "Tunnel" first for the VPN site to site (IPSec ) connection. Then you would want to add it to the desire new or existing zone. I've recently connected 3 sites and I wrote the necessary steps I used to build such connections. I am sharing the steps below, in case is useful:
Steps to create IPSecVPNTunnel:
1. Create the tunnel interface
2. Add the tunnel to a zone.
3. Create the IKE Crypto Profile
4. Create IPSec Crypto Profile
5. Create IKE Gateways
6. Create IPSec Tunnel
7. Create Virtual router static route with the tunnel as the tunnel just created as the interface, define what routes need access.
8. Create the source and destination security policies to define the source and destination and who to allow access.
Kind regards,
Maria.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!