Professional Documents
Culture Documents
Design Consideration
The scenario is tested using PAN OS 3.1.3. PAN OS does not support the use of a single tunnel
interface to route traffic to multiple VPN end points. The hub site requires a separate tunnel
interface to connect to each one of the spoke site. Each of the tunnel interfaces is configured as
point-to-point interface. As far as OSPF is concerned adjacencies are always formed over a point-
to-point interface. With point-to-point interfaces each one of segment will belong to a different
subnet.
Topology
In this example, the site B is dynamic end point. Two tunnel interfaces are configured on the HUB
to connect to the spoke sites. Each one of the tunnel interfaces pairs must be in its own subnet.
The table below summarizes the interface and OSPF configuration on each one of the sites
Site A
Site B
VPN configuration
Configuration for site-A
IKE gateway configuration
Network>IPSec tunnels
OSPF configuration
The tunnel interfaces are assigned to the backbone area 0.0.0.0 with link type of point-to-point.
OSPF adjacencies are always formed on p2p interfaces. The ethernet interface connecting to the
local network is the area 0.0.0.141. figure below shows the snap shot of OSPF configuration for the
area 0.0.0.0
IKE gateway
IPSec VPN
IKE configuration
IPSec configuration
OSPF configuration
The tunnel interfaces are assigned to the backbone area 0.0.0.0 with link type of point-to-point.
OSPF adjacencies are always formed on p2p interfaces. The ethernet interface connecting to the
local network is the area 0.0.0.122. figure below shows the snap shot of OSPF configuration for the
area 0.0.0.0
HUB site
On the Hub site you will see two active tunnels- one for each spoke
-------------------------------------------------------------------------------
total tunnels configured: 2
filter - type IPSec, state any
The routes to LAN behind the spoke, 192.168.1.0/24 and 192.168.2.0/24 will be learned via OSPF
with the corresponding tunnel interface as the next hop.
-------------------------------------------------------------------------------
total tunnels configured: 1
filter - type IPSec, state any
Additional references
How to Configure and Troubleshoot IPSec VPNs
https://live.paloaltonetworks.com/docs/DOC-1163