PaloAlto LAB By Riaz Gul
Palo Alto Site to Site
VPN
Cisco IOS Routers
Fortinet FortiGate Sophos NGFW
This LAB demonstrate how to configure Site-
to-Site VPN between Palo Alto Firewalls and
other vendor firewalls, including Fortinet,
Cisco IOS Routers and Sophos NGFW.
PaloAlto LAB
What to do ?
By Riaz Gul
IKE v1 & IKE v2
LAB Environment
PNETLab ver 4.2.10
Palo Alto Firewall 11.2.0
SophosXG 20.0.0 Firewall
Fortinet Fortigate OS 7.2
Mikrotik Router OS
PaloAlto LAB By Riaz Gul
LAB Topology
PaloAlto LAB By Riaz Gul
Pre-Requisites
PaloAlto LAB
Basic IP Configuration on Interfaces
Routing, WAN to WAN Reachability
Here we are not showing end to end
configuration for LAB devices. Therefore, you
need to have environment ready for VPN
connectivity. So only showing VPN
configurations.
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
This section showing the configuration for
IPSec VPN between Palo Alto Firewall and
Cisco IOS Router
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto
IKE Crypto Profile
Define IKE Crypto Profile, usually
called the Phase 1 of IPSec VPN
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto
IPSec Crypto Profile
Define IPSec Profile, usually
called the Phase 2 of IPSec VPN
or also called as Transform Set.
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto
IKE Gateway General
IKE Gateway defines the
gateway information for local
are remote peer the interface
and identification parameters.
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto
IKE Gateway Advance
If there is a NAT device in
between the path enable NAT
transversal option.
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto
Tunnel Interface
Since Palo Alto support route-
based VPNs, therefore we need
to have on interface to be
attached to VPN so that we can
configure Policy and route desire
traffic on tunnel.
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto
IPSec Tunnel Interface
Now create IPSec Tunnel and
combine the configured crypto
profile and IPSec profile and
define the proxy IDs (Interesting
Traffic)
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto
IPSec Tunnel Interface
Proxy IDs
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto
Remote Subnet Routing
Since Palo Alto support route-
based VPN, we need to define
the route for other site LAN
subnet towards the tunnel
interfaces which is linked to
IPSec tunnel.
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto
Remote Subnet Routing
Since Palo Alto support route-
based VPN, we need to define
the route for other site LAN
subnet towards the tunnel
interfaces which is linked to
IPSec tunnel.
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Palo Alto Traffic Access Rules
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Cisco Router
Phase 1 & 2 Parameters
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Define Interesting Traffic
Cisco Router
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Crypto Map on WAN Interface
Cisco Router
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Verification
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Cisco IOS Router
Verification
By Riaz Gul
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
To establish site to site VPN between
Fortigate and Paloalto firewalls, the WAN
reachability must be present.
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Palo Alto
IKE Phase 1
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Palo Alto
IKE Phase 2
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Palo Alto
IKE Gateway
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Palo Alto
IKE Gateway Advance
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Palo Alto
Tunnel Interface
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Palo Alto
IPSec Tunnel
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Palo Alto
Proxy IDs
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Palo Alto
Define Route for Remote
Subnet towards Tunnel
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Fortigate
VPN Tunnel Network Settings
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Fortigate
Authentication Settings
IKE Version
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Fortigate
Phase 1 Parameters
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Fortigate
Phase 2 Parameters &
Interesting Traffic
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Fortigate
Define Route for PA LAN
Subnet
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Fortigate
Security Access Policies to
Allow Traffic on VPN
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Verification
PaloAlto LAB
IPSec Palo Alto & Fortigate
By Riaz Gul
Verification
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Both peers have WAN reachability,
therefore we can configure IPSec VPN
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Palo Alto
IKE Crypto Profile
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Palo Alto
IPSec Profile
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Palo Alto
IKE Gateway
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Palo Alto
IKE Gateway Advance
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Palo Alto
Tunnel Interface
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Palo Alto
IPSec Tunnel
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Palo Alto
Proxy IDs
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Palo Alto
Remote Route
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
IPSec
Profile
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
IPSec VPN General Setting
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
Encryption Authentication
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
Gateway & Interesting Traffic
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
Tunnel Interface
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
Access Rules
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
Routing
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
Verification
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
Verification
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
Verification
PaloAlto LAB
IPSec Palo Alto & SophosXG
By Riaz Gul
Sophos XG
Verification

multi vendor VPN NGF UTM untuk setting vpn