When to Use Proxy IDs in Palo Alto IPSec VPNs

1. Understanding Proxy IDs

In Palo Alto Networks firewalls, a Proxy ID defines the local and remote subnets that are allowed to communicate over an IPSec VPN tunnel. They are crucial during the IKE Phase 2 negotiation to establish Security Associations (SAs) for specific traffic flows.

2. Scenarios Requiring Proxy IDs

3. When Proxy IDs Are Not Required

4. Configuring Proxy IDs

To configure Proxy IDs on a Palo Alto firewall:

  1. Navigate to Network > IPSec Tunnels and select the desired tunnel.
  2. Click on the Proxy IDs tab.
  3. Click Add and enter:
    • Name: A unique identifier for the Proxy ID.
    • Local: The local subnet (e.g., 192.168.1.0/24).
    • Remote: The remote subnet (e.g., 10.0.0.0/24).
    • Protocol: Specify if needed; otherwise, leave as any .
  4. Click OK to save the configuration.

Ensure that the Proxy IDs match exactly on both VPN peers to establish a successful tunnel.

5. Considerations

6. Additional Resources