Palo Alto S2S VPN using Loopback interface


PA-4 using loopback interface for S2S VPN:

loopback interface has a public IP from same subnet of E1/1 interface.
loopback interface is in same Untrust zone as E1/1.

1. Create lookback interface

2. Create Tunnel interface 

3. Create IKE Gateway for remote PA-1, with local loopback interface

4. Create IPSec Tunnel 

5. Add Security Policies
