How to configure a basic S2S VPN in Palo Alto
Here's a quick how to for setting up a very simple S2S IPSEC VPN on a Palo Alto.
- Create a tunnel interface
- Here you will also create the security zone that will be used
- Create the IKE Gateway and specify your tunnel’s security zone
- Include the Peer address and your outside interface
- Create your IKE crypto policy
- Create your IPSEC crypto policy
- Create a new IPSEC Tunnel using the IKE/IPSEC Crypto policies you made.
- Also create under this any Proxy IDs you may require to conform with a Cisco IPSEC VPN. They're very similar to policies that you might create on a netscreen.
- Create 2 new policies for the inbound and outbound traffic via the S2S VPN.
- These are typically the local and remote destination networks. You need to put them in twice for inbound and outbound permissions.
- Add the tunnel interface to the default virtual router and add the static routes to your remote network via your tunnel interface.
Enjoy! Let me know if there are any question.
- David Pagán
Click to Visit Finance Services
ReplyDelete