Can not change

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Can not change

L1 Bithead

Hello Every one 

 

I was trying to build a Site to Site Vpn. I can only select limited interfaces when creating a new Zone. The selection option does not even include the main gateway interface (Ethernet1/10. I have attached a screen shoot of the scenario.

 

Habte01_0-1660835482512.png

 

6 REPLIES 6

Cyber Elite
Cyber Elite

Hello @Habte-01

 

the interfaces you are not able to see in drop down list, are they configured as a Type Layer 3 and are they assigned to Virtual Router?

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Yes they all are  on Vr1 and layer3

Cyber Elite
Cyber Elite

Thank you for reply @Habte-01

 

this should be all you need to get an interface available in a zone. An interface can be a member of only one zone. Is the interface you are trying to add already member of existing zone?

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Thanks Pavel. No it is not. 

Cyber Elite
Cyber Elite

Thank you for reply @Habte-01

 

I am running out of ideas. Could you please confirm what PAN-OS are you running? I would like to see I can re-produce it by using the same version.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

L0 Member

Hello Bithead, you might need to create a new interface type "Tunnel"  first for the VPN site to site (IPSec ) connection. Then you would want to add it to the desire new or existing zone. I've recently connected 3 sites and I wrote the necessary steps I used to build such connections. I am sharing the steps below, in case is useful:

Steps to create IPSecVPNTunnel:
1. Create the tunnel interface

2. Add the tunnel to a zone.
3. Create the IKE Crypto Profile
4. Create IPSec Crypto Profile
5. Create IKE Gateways
6. Create IPSec Tunnel
7. Create Virtual router static route with the tunnel as the tunnel just created as the interface, define what routes need access.
8. Create the source and destination security policies to define the source and destination and who to allow access.

 

Kind regards,

Maria.

MR
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!