Palo Alto S2S VPN using Loopback interface

 


PA-4 using loopback interface for S2S VPN:

loopback interface has a public IP from same subnet of E1/1 interface.
loopback interface is in same Untrust zone as E1/1.


1. Create lookback interface


2. Create Tunnel interface 

3. Create IKE Gateway for remote PA-1, with local loopback interface


4. Create IPSec Tunnel 


5. Add Security Policies









Comments