Palo Alto VPN Configuration | Site to Site VPN Configuration in Palo Alto Firewall

Поділитися
Вставка
  • Опубліковано 31 січ 2025

КОМЕНТАРІ • 18

  • @prashanthballa7296
    @prashanthballa7296 2 місяці тому

    Best video for VPN site to site configuration.

  • @devakeenandantiwari8801
    @devakeenandantiwari8801 11 місяців тому

    Good explanation thanks sir...

  • @amanpathania
    @amanpathania 10 місяців тому

    Good session however, I have an input or query - while configuring the static routes: (explained during 16:00-19:00 min timestamp) you ended up configuring it for a VPC IP.
    My question is: In real time, you would never know the VPC IP address on the other side. you should have configured it on the public facing IP and then created a route to the target VPC.
    Please let me know your thoughts on this.

    • @freshdeveloper
      @freshdeveloper  10 місяців тому

      If you are talking about Static route for tunnel, i.e. not just VPC IP of a machine, but its whole subnet of other side.
      So all the traffic towards complete subnet will be forwarded towards tunnel, get encrypted and being delivered on other site.
      I hope i understood your question currently. If not please ask again re-iterating 🙂

  • @dailyadventure0
    @dailyadventure0 4 місяці тому

    Outstanding sir

  • @waseemhasan5372
    @waseemhasan5372 7 місяців тому

    that was so awesome. thanks sir

  • @KentWirianata-yp5dv
    @KentWirianata-yp5dv 7 місяців тому

    Hello i'm new in here,
    7:08 what if there's a router between the palo? what's the peer IP?
    also what config is needed in router beside setting ip and routing so that he vpn site to site work?

    • @freshdeveloper
      @freshdeveloper  7 місяців тому

      In that case peer IP could not be of same network.
      But ultimate purpose will be same, Peer IP should be reachable and make sure routes in place at the intermediate routers

  • @Littlegujju-avengers
    @Littlegujju-avengers Рік тому

    What configuration is needed, if the PA firewall sits behind the router(NAT)? NAT -T enable in palo alto. Is there any changes required in Cisco router 7200. Pls. suggest

    • @freshdeveloper
      @freshdeveloper  Рік тому

      If NAT is happening in between VPN path, you may have to enable port 4500 as well.
      By default UDP port 500 is used for IKE, but in case of NAT-T in between it uses 4500

  • @vijayamadhavi6788
    @vijayamadhavi6788 11 місяців тому

    Hi sir.. can you explain modes,ike,IPsec parameters, give more trouble shooting commands and packet capture it will help

  • @shwetankmishra6870
    @shwetankmishra6870 3 місяці тому

    HiSir,
    we didnt configured anything here for return traffic?