Q. When I am configuring IPsec Tunnels and have to identify local and remote ProxyID, what IP network I should add? pre nat or post nat network ? A. If you are going Palo Alto to Palo Alto, ProxyIDs are not required - but, I suspect that is not the case do to the nature of your question, so the answer is post NAT. It will be what the other side expects to see as the source address of the traffic. Q. I have to configure a static rule for vpn traffic. What destination network should be in that way? is it pre nat or post nat network ? if I am adding pre nat network I faced problems that there are other static routes which is used in my local network (because some remote sites subnets are similar like my site subnets). A. Again, this will be the post NAT address. The traffic coming from one side to the other will have a source address of what ever you source NAT it to. NOTE: Make sure that your ProxyIDs match on both sides of the tunnel. If it is a Cisco ASA for example, the crypto map (ACL) will need to match the proxy IDs configured on your Palo Alto - only in reverse (local on your side is remote on the other and vise versa). Hope this helps, -chadd.
... View more