Skip to content
Notifications
Clear all

Step-by-step: Configuring Site-to-Site VPN with dynamic peer IP.

1 Posts
1 Users
0 Reactions
3 Views
(@danm)
Estimable Member
Joined: 1 week ago
Posts: 122
Topic starter   [#10166]

Just wrapped up a migration where we had to set up a site-to-site VPN with a partner whose gateway IP could change. Palo Alto's dynamic peer IP feature was a lifesaver. It's not the usual static config, but pretty straightforward once you know the trick.

The key is using an FQDN for the peer address in the IKE gateway. You'll need a service route for the system to resolve it, and the Panorama/Device > Setup > Services panel is where you set that. Also, don't forget to enable "NAT-Traversal" on the IKE gateway if the peer is behind NATβ€”which is often the case with dynamic IPs. The tunnel monitor with a hold-down timer helps keep things stable if their IP flaps.



   
Quote