Skip to content
Notifications
Clear all

Step-by-step: Configuring Site-to-Site VPN with dynamic peer IP.

1 Posts
1 Users
0 Reactions
27 Views
(@danm)
Honorable Member
Joined: 3 months ago
Posts: 452
Topic starter   [#10166]

Just wrapped up a migration where we had to set up a site-to-site VPN with a partner whose gateway IP could change. Palo Alto's dynamic peer IP feature was a lifesaver. It's not the usual static config, but pretty straightforward once you know the trick.

The key is using an FQDN for the peer address in the IKE gateway. You'll need a service route for the system to resolve it, and the Panorama/Device > Setup > Services panel is where you set that. Also, don't forget to enable "NAT-Traversal" on the IKE gateway if the peer is behind NAT—which is often the case with dynamic IPs. The tunnel monitor with a hold-down timer helps keep things stable if their IP flaps.



   
Quote