Forgive the newbie question, but I've been searching the documentation and I don't see where I can configure the Paloalto FW for vpn passthrough, specifically ESP (Protocol 50) and even ICMP. I have some routers that I need to provide NAT for their external address, but I also want to limit the services available on the Internet to just PING reply, ESP, IKE and NAT-T. I've added UDP service definitions for IKE and NAT-T, but I don't see anything for the others. Can someone point me in the right direction?
... View more