Hello forum members, I have been testing the VPN site-2-site configurations on my Palo Alto VM lab, prior to deploying on our production environment. I have successfully set up a VPN connection where both firewalls use static routing. Trouble I'm having now is setting up the VPN connection where the 3rd party site uses static routing and my corp LAN uses OSPF. I can't get the tunnel up between the two sites. I followed the Site-2-Site VPN with Static and Dynamic Routing example in the PAN-OS Admin guide, but some of the steps seem vague (vague to me any way). My R1 router has formed an OSPF neighbour relation ship with the Palo Alto VM-PA-01 fine and the PC host 172.19.9.10 can ping the E1/2 interface (10.216.7.1) of the Palo Alto fine. The following is my lab topology and screen shots of the configs. VM-PA-01 config. *** I also tried this IKE Gateway config with the FQDNs, as in the PAN-OS guide *** VM-PA-02 config. *** I also tried this IKE Gateway config with the FQDNs, as in the PAN-OS guide *** Any suggestions and advice will be much appreciated.
... View more