PaloAlto LAB ByRiaz Gul
Palo Alto Site to Site
VPN
Cisco IOS Routers
Fortinet FortiGate Sophos NGFW
2.
This LAB demonstratehow to configure Site-
to-Site VPN between Palo Alto Firewalls and
other vendor firewalls, including Fortinet,
Cisco IOS Routers and Sophos NGFW.
PaloAlto LAB
What to do ?
By Riaz Gul
IKE v1 & IKE v2
3.
LAB Environment
PNETLab ver4.2.10
Palo Alto Firewall 11.2.0
SophosXG 20.0.0 Firewall
Fortinet Fortigate OS 7.2
Mikrotik Router OS
PaloAlto LAB By Riaz Gul
Pre-Requisites
PaloAlto LAB
Basic IPConfiguration on Interfaces
Routing, WAN to WAN Reachability
Here we are not showing end to end
configuration for LAB devices. Therefore, you
need to have environment ready for VPN
connectivity. So only showing VPN
configurations.
By Riaz Gul
6.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
This section showing the configuration for
IPSec VPN between Palo Alto Firewall and
Cisco IOS Router
By Riaz Gul
7.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
Palo Alto
IKE Crypto Profile
Define IKE Crypto Profile, usually
called the Phase 1 of IPSec VPN
By Riaz Gul
8.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
Palo Alto
IPSec Crypto Profile
Define IPSec Profile, usually
called the Phase 2 of IPSec VPN
or also called as Transform Set.
By Riaz Gul
9.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
Palo Alto
IKE Gateway General
IKE Gateway defines the
gateway information for local
are remote peer the interface
and identification parameters.
By Riaz Gul
10.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
Palo Alto
IKE Gateway Advance
If there is a NAT device in
between the path enable NAT
transversal option.
By Riaz Gul
11.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
Palo Alto
Tunnel Interface
Since Palo Alto support route-
based VPNs, therefore we need
to have on interface to be
attached to VPN so that we can
configure Policy and route desire
traffic on tunnel.
By Riaz Gul
12.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
Palo Alto
IPSec Tunnel Interface
Now create IPSec Tunnel and
combine the configured crypto
profile and IPSec profile and
define the proxy IDs (Interesting
Traffic)
By Riaz Gul
13.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
Palo Alto
IPSec Tunnel Interface
Proxy IDs
By Riaz Gul
14.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
Palo Alto
Remote Subnet Routing
Since Palo Alto support route-
based VPN, we need to define
the route for other site LAN
subnet towards the tunnel
interfaces which is linked to
IPSec tunnel.
By Riaz Gul
15.
PaloAlto LAB
IPSec PaloAlto & Cisco IOS Router
Palo Alto
Remote Subnet Routing
Since Palo Alto support route-
based VPN, we need to define
the route for other site LAN
subnet towards the tunnel
interfaces which is linked to
IPSec tunnel.
By Riaz Gul
PaloAlto LAB
IPSec PaloAlto & Fortigate
By Riaz Gul
To establish site to site VPN between
Fortigate and Paloalto firewalls, the WAN
reachability must be present.