{"id":131,"date":"2022-04-25T07:33:20","date_gmt":"2022-04-25T11:33:20","guid":{"rendered":"https:\/\/pressbooks.bccampus.ca\/paloalto\/?post_type=chapter&#038;p=131"},"modified":"2026-02-18T16:08:22","modified_gmt":"2026-02-18T21:08:22","slug":"site-to-site-vpn","status":"publish","type":"chapter","link":"https:\/\/pressbooks.bccampus.ca\/paloalto\/chapter\/site-to-site-vpn\/","title":{"raw":"3.3 Site-to-Site VPN","rendered":"3.3 Site-to-Site VPN"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\r\n<p class=\"textbox__title\">Learning Objectives<\/p>\r\n\r\n<\/header>\r\n<div class=\"textbox__content\">\r\n<ul>\r\n \t<li>Configure site-to-site VPN<\/li>\r\n \t<li>Configure static routing<\/li>\r\n<\/ul>\r\n<\/div>\r\n<\/div>\r\n<div class=\"textbox\">\r\n\r\n<strong>Prerequisites<\/strong>:\r\n<ul>\r\n \t<li>Create Zones on both firewalls<\/li>\r\n \t<li>Create a tunnel interface on both firewalls<\/li>\r\n \t<li>Create a policy to allow VPN to Inside on both firewalls<\/li>\r\n \t<li>Create a policy to allow Inside to VPN on both firewalls<\/li>\r\n \t<li>Interface configuration<\/li>\r\n \t<li>Knowledge of previous labs<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div class=\"textbox shaded\">\r\n\r\n<strong>Scenario<\/strong>: This one is a bit tricky since you will be managing both devices. A site-to-site VPN is what your company would set up if you had offices in other locations without being directly connected to each other. But in this lab, we'll just take it easy and assume that they have a direct connection to each other. So, we are going to configure site-to-site VPN between two Palo Alto firewalls. Then, you should be able to ping from client-1 to client-2.\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_307\" align=\"aligncenter\" width=\"600\"]<img class=\"wp-image-307\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-05-17-image.png\" alt=\"Main scenario\" width=\"600\" height=\"305\" \/> Figure 3.54: Main scenario[\/caption]\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 118px\" border=\"0\"><caption>Table 3.8: Addressing Table<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Device<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Configuration<\/th>\r\n<\/tr>\r\n<tr style=\"height: 47px\">\r\n<td style=\"width: 50%;height: 47px\">Site-1<\/td>\r\n<td style=\"width: 50%;height: 47px\">management: 192.168.0.1\/24\r\nEthernet1\/1: 10.0.0.1\/24\r\nEthernet1\/2: 1.1.1.1\/24<\/td>\r\n<\/tr>\r\n<tr style=\"height: 11px\">\r\n<td style=\"width: 50%;height: 11px\">Site-2<\/td>\r\n<td style=\"width: 50%;height: 11px\">management: 192.168.0.2\/24\r\nEthernet1\/1: 172.16.10.1\/24\r\nEthernet1\/2: 1.1.1.2\/24<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Site1-Client<\/td>\r\n<td style=\"width: 50%;height: 15px\">eth0: 10.0.0.2\/24 GW: 10.0.0.1<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Site2-Client<\/td>\r\n<td style=\"width: 50%;height: 15px\">eth0: 172.16.10.2\/24 GW: 172.16.10.1<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Management1<\/td>\r\n<td style=\"width: 50%;height: 15px\">eth0: 192.168.0.3\/24<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 3.9: Zone Configuration for Site1<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Zone<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Interface<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Inside<\/td>\r\n<td style=\"width: 50%\">Ethernet1\/1<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">VPN<\/td>\r\n<td style=\"width: 50%\">Ethernet1\/2, tunnel.1<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 45px\" border=\"0\"><caption>Table 3.10: Zone Configuration for Site2<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Zone<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Interface<\/th>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Inside<\/td>\r\n<td style=\"width: 50%;height: 15px\">Ethernet1\/1<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">VPN<\/td>\r\n<td style=\"width: 50%;height: 15px\">Ethernet1\/2, tunnel.1<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<h2>Create an IKE Gateway<\/h2>\r\nUnder <strong>Network &gt; Network Profiles &gt; IKE Gateways<\/strong>, click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_447\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-447 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S1.jpg\" alt=\"Add an IKE Gateways\" width=\"1026\" height=\"830\" \/> Figure 3.55: Add an IKE Gateway[\/caption]\r\n\r\nOn the Site1 firewall, configure these settings:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 105px\" border=\"0\"><caption>Table 3.11: Site1 IKE Gateway Configuration<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameter<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Interface<\/td>\r\n<td style=\"width: 50%;height: 15px\">Ethernet1\/2<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Local IP Address<\/td>\r\n<td style=\"width: 50%;height: 15px\">1.1.1.1\/24<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Peer IP Address Type<\/td>\r\n<td style=\"width: 50%;height: 15px\">IP<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Peer Address<\/td>\r\n<td style=\"width: 50%;height: 15px\">1.1.1.2<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Pre-shared Key<\/td>\r\n<td style=\"width: 50%;height: 15px\"><em>Password Here<\/em><\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Confirm Pre-shared key<\/td>\r\n<td style=\"width: 50%;height: 15px\"><em>Confirm Password Here<\/em><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_448\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-448 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S2.jpg\" alt=\"Site1 Firewall- IKE Gateway Configuration\" width=\"1026\" height=\"830\" \/> Figure 3.56: Site1 Firewall: IKE Gateway Configuration[\/caption]\r\n\r\nThen press <strong>OK<\/strong>.\r\n\r\nOn the Site2 firewall, configure these settings:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 105px\" border=\"0\"><caption>Table 3.12: Site2 IKE Gateway Configuration<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameters<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Interface<\/td>\r\n<td style=\"width: 50%;height: 15px\">Ethernet1\/2<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Local IP Address<\/td>\r\n<td style=\"width: 50%;height: 15px\">1.1.1.2\/24<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Peer IP Address Type<\/td>\r\n<td style=\"width: 50%;height: 15px\">IP<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Peer Address<\/td>\r\n<td style=\"width: 50%;height: 15px\">1.1.1.1<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Pre-shared Key<\/td>\r\n<td style=\"width: 50%;height: 15px\"><em>Same Password as before here<\/em><\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Confirm Pre-shared key<\/td>\r\n<td style=\"width: 50%;height: 15px\"><em>Confirm same password as before here<\/em><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_449\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-449 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S3.jpg\" alt=\"Site2 Firewall- IKE Gateway Configuration\" width=\"1026\" height=\"830\" \/> Figure 3.57: Site2 Firewall: IKE Gateway Configuration[\/caption]\r\n\r\nThen press <strong>OK<\/strong>.\r\n<h2>Create an IPsec Tunnel<\/h2>\r\nUnder <strong>Network &gt; IPsec Tunnel<\/strong>, click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_450\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-450 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S4.jpg\" alt=\"Site1 Firewall- Add an IPSEC Tunnels\" width=\"1026\" height=\"830\" \/> Figure 3.58: Site1 Firewall: Add an IPsec Tunnel[\/caption]\r\n\r\nOn both firewalls, configure these settings:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 3.13: IPsec Tunnel Configuration<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Parameters<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Value<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Tunnel Interface<\/td>\r\n<td style=\"width: 50%\">tunnel.1<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">IKE Gateway<\/td>\r\n<td style=\"width: 50%\"><em>The one you created on the respective firewall<\/em><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_451\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-451 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S5.jpg\" alt=\"Site1 and Site 2 Firewall- IPSEC Tunnel Configuration\" width=\"1026\" height=\"830\" \/> Figure 3.59: Site1 and Site2 Firewall: IPsec Tunnel Configuration[\/caption]\r\n<h2>Create Static Routes<\/h2>\r\nUnder <strong>Network &gt; Virtual Routers<\/strong>, click default.\r\n\r\n[caption id=\"attachment_452\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-452 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S6.jpg\" alt=\"Virtual Routers Configuration\" width=\"1026\" height=\"830\" \/> Figure 3.60: Virtual Routers Configuration[\/caption]\r\n\r\nUnder the static routes tab, click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_453\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-453 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S7.jpg\" alt=\"Add a Static Route in the Site1\" width=\"1026\" height=\"830\" \/> Figure 3.61: Add a Static Route in the Site1[\/caption]\r\n\r\nOn the Site1 firewall, configure these settings:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 3.14: Site1 Static Route Configuration<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Parameters<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Value<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Destination<\/td>\r\n<td style=\"width: 50%\">172.16.10.0\/24<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Interface<\/td>\r\n<td style=\"width: 50%\">tunnel.1<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Next Hop<\/td>\r\n<td style=\"width: 50%\">None<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_454\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-454 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S8.jpg\" alt=\"Static Route Configuration in the Site 1\" width=\"1026\" height=\"830\" \/> Figure 3.62: Static Route Configuration in the Site1[\/caption]\r\n\r\nOn the Site2 firewall, configure these settings:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\" border=\"0\"><caption>Table 3.15: Site2 Static Route Configuration<\/caption>\r\n<tbody>\r\n<tr>\r\n<th style=\"width: 50%\" scope=\"col\">Parameters<\/th>\r\n<th style=\"width: 50%\" scope=\"col\">Value<\/th>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Destination<\/td>\r\n<td style=\"width: 50%\">10.0.0.0\/24<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Interface<\/td>\r\n<td style=\"width: 50%\">tunnel.1<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 50%\">Next Hop<\/td>\r\n<td style=\"width: 50%\">None<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_316\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-316 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-52-22-image.png\" alt=\"Static Route Configuration in the Site 2\" width=\"1026\" height=\"830\" \/> Figure 3.63: Static Route Configuration in the Site 2[\/caption]\r\n\r\nThen press <strong>OK<\/strong>.\r\n<h2>Test the Site-to-Site<\/h2>\r\nOn any client device, try and ping the other client on the other site.\r\n\r\n[caption id=\"attachment_317\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-317 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-54-25-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" \/> Figure 3.64: Verify your configuration[\/caption]\r\n\r\nIf you can ping the other client in the other site, everything worke<span style=\"background-color: #ffff00\">d! If you go to <strong>Network &gt; IPSec<\/strong> <strong>Tunnels<\/strong>, the Tunnel status should be green<\/span>.","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Configure site-to-site VPN<\/li>\n<li>Configure static routing<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox\">\n<p><strong>Prerequisites<\/strong>:<\/p>\n<ul>\n<li>Create Zones on both firewalls<\/li>\n<li>Create a tunnel interface on both firewalls<\/li>\n<li>Create a policy to allow VPN to Inside on both firewalls<\/li>\n<li>Create a policy to allow Inside to VPN on both firewalls<\/li>\n<li>Interface configuration<\/li>\n<li>Knowledge of previous labs<\/li>\n<\/ul>\n<\/div>\n<div class=\"textbox shaded\">\n<p><strong>Scenario<\/strong>: This one is a bit tricky since you will be managing both devices. A site-to-site VPN is what your company would set up if you had offices in other locations without being directly connected to each other. But in this lab, we&#8217;ll just take it easy and assume that they have a direct connection to each other. So, we are going to configure site-to-site VPN between two Palo Alto firewalls. Then, you should be able to ping from client-1 to client-2.<\/p>\n<\/div>\n<figure id=\"attachment_307\" aria-describedby=\"caption-attachment-307\" style=\"width: 600px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-307\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-05-17-image.png\" alt=\"Main scenario\" width=\"600\" height=\"305\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-05-17-image.png 980w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-05-17-image-300x152.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-05-17-image-768x390.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-05-17-image-65x33.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-05-17-image-225x114.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-05-17-image-350x178.png 350w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption id=\"caption-attachment-307\" class=\"wp-caption-text\">Figure 3.54: Main scenario<\/figcaption><\/figure>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 118px\">\n<caption>Table 3.8: Addressing Table<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Device<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Configuration<\/th>\n<\/tr>\n<tr style=\"height: 47px\">\n<td style=\"width: 50%;height: 47px\">Site-1<\/td>\n<td style=\"width: 50%;height: 47px\">management: 192.168.0.1\/24<br \/>\nEthernet1\/1: 10.0.0.1\/24<br \/>\nEthernet1\/2: 1.1.1.1\/24<\/td>\n<\/tr>\n<tr style=\"height: 11px\">\n<td style=\"width: 50%;height: 11px\">Site-2<\/td>\n<td style=\"width: 50%;height: 11px\">management: 192.168.0.2\/24<br \/>\nEthernet1\/1: 172.16.10.1\/24<br \/>\nEthernet1\/2: 1.1.1.2\/24<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Site1-Client<\/td>\n<td style=\"width: 50%;height: 15px\">eth0: 10.0.0.2\/24 GW: 10.0.0.1<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Site2-Client<\/td>\n<td style=\"width: 50%;height: 15px\">eth0: 172.16.10.2\/24 GW: 172.16.10.1<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Management1<\/td>\n<td style=\"width: 50%;height: 15px\">eth0: 192.168.0.3\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 3.9: Zone Configuration for Site1<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Zone<\/th>\n<th style=\"width: 50%\" scope=\"col\">Interface<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Inside<\/td>\n<td style=\"width: 50%\">Ethernet1\/1<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">VPN<\/td>\n<td style=\"width: 50%\">Ethernet1\/2, tunnel.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 45px\">\n<caption>Table 3.10: Zone Configuration for Site2<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Zone<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Interface<\/th>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Inside<\/td>\n<td style=\"width: 50%;height: 15px\">Ethernet1\/1<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">VPN<\/td>\n<td style=\"width: 50%;height: 15px\">Ethernet1\/2, tunnel.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Create an IKE Gateway<\/h2>\n<p>Under <strong>Network &gt; Network Profiles &gt; IKE Gateways<\/strong>, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_447\" aria-describedby=\"caption-attachment-447\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-447 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S1.jpg\" alt=\"Add an IKE Gateways\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S1.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S1-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S1-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S1-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S1-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S1-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S1-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-447\" class=\"wp-caption-text\">Figure 3.55: Add an IKE Gateway<\/figcaption><\/figure>\n<p>On the Site1 firewall, configure these settings:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 105px\">\n<caption>Table 3.11: Site1 IKE Gateway Configuration<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameter<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Interface<\/td>\n<td style=\"width: 50%;height: 15px\">Ethernet1\/2<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Local IP Address<\/td>\n<td style=\"width: 50%;height: 15px\">1.1.1.1\/24<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Peer IP Address Type<\/td>\n<td style=\"width: 50%;height: 15px\">IP<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Peer Address<\/td>\n<td style=\"width: 50%;height: 15px\">1.1.1.2<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Pre-shared Key<\/td>\n<td style=\"width: 50%;height: 15px\"><em>Password Here<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Confirm Pre-shared key<\/td>\n<td style=\"width: 50%;height: 15px\"><em>Confirm Password Here<\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_448\" aria-describedby=\"caption-attachment-448\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-448 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S2.jpg\" alt=\"Site1 Firewall- IKE Gateway Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S2.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S2-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S2-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S2-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S2-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S2-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S2-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-448\" class=\"wp-caption-text\">Figure 3.56: Site1 Firewall: IKE Gateway Configuration<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<p>On the Site2 firewall, configure these settings:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 105px\">\n<caption>Table 3.12: Site2 IKE Gateway Configuration<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameters<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Interface<\/td>\n<td style=\"width: 50%;height: 15px\">Ethernet1\/2<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Local IP Address<\/td>\n<td style=\"width: 50%;height: 15px\">1.1.1.2\/24<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Peer IP Address Type<\/td>\n<td style=\"width: 50%;height: 15px\">IP<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Peer Address<\/td>\n<td style=\"width: 50%;height: 15px\">1.1.1.1<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Pre-shared Key<\/td>\n<td style=\"width: 50%;height: 15px\"><em>Same Password as before here<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Confirm Pre-shared key<\/td>\n<td style=\"width: 50%;height: 15px\"><em>Confirm same password as before here<\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_449\" aria-describedby=\"caption-attachment-449\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-449 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S3.jpg\" alt=\"Site2 Firewall- IKE Gateway Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S3.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S3-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S3-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S3-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S3-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S3-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S3-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-449\" class=\"wp-caption-text\">Figure 3.57: Site2 Firewall: IKE Gateway Configuration<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<h2>Create an IPsec Tunnel<\/h2>\n<p>Under <strong>Network &gt; IPsec Tunnel<\/strong>, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_450\" aria-describedby=\"caption-attachment-450\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-450 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S4.jpg\" alt=\"Site1 Firewall- Add an IPSEC Tunnels\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S4.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S4-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S4-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S4-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S4-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S4-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S4-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-450\" class=\"wp-caption-text\">Figure 3.58: Site1 Firewall: Add an IPsec Tunnel<\/figcaption><\/figure>\n<p>On both firewalls, configure these settings:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 3.13: IPsec Tunnel Configuration<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Parameters<\/th>\n<th style=\"width: 50%\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Tunnel Interface<\/td>\n<td style=\"width: 50%\">tunnel.1<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">IKE Gateway<\/td>\n<td style=\"width: 50%\"><em>The one you created on the respective firewall<\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_451\" aria-describedby=\"caption-attachment-451\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-451 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S5.jpg\" alt=\"Site1 and Site 2 Firewall- IPSEC Tunnel Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S5.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S5-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S5-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S5-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S5-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S5-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S5-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-451\" class=\"wp-caption-text\">Figure 3.59: Site1 and Site2 Firewall: IPsec Tunnel Configuration<\/figcaption><\/figure>\n<h2>Create Static Routes<\/h2>\n<p>Under <strong>Network &gt; Virtual Routers<\/strong>, click default.<\/p>\n<figure id=\"attachment_452\" aria-describedby=\"caption-attachment-452\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-452 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S6.jpg\" alt=\"Virtual Routers Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S6.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S6-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S6-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S6-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S6-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S6-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S6-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-452\" class=\"wp-caption-text\">Figure 3.60: Virtual Routers Configuration<\/figcaption><\/figure>\n<p>Under the static routes tab, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_453\" aria-describedby=\"caption-attachment-453\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-453 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S7.jpg\" alt=\"Add a Static Route in the Site1\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S7.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S7-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S7-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S7-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S7-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S7-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S7-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-453\" class=\"wp-caption-text\">Figure 3.61: Add a Static Route in the Site1<\/figcaption><\/figure>\n<p>On the Site1 firewall, configure these settings:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 3.14: Site1 Static Route Configuration<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Parameters<\/th>\n<th style=\"width: 50%\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Destination<\/td>\n<td style=\"width: 50%\">172.16.10.0\/24<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Interface<\/td>\n<td style=\"width: 50%\">tunnel.1<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Next Hop<\/td>\n<td style=\"width: 50%\">None<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_454\" aria-describedby=\"caption-attachment-454\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-454 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S8.jpg\" alt=\"Static Route Configuration in the Site 1\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S8.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S8-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S8-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S8-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S8-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S8-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/S8-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-454\" class=\"wp-caption-text\">Figure 3.62: Static Route Configuration in the Site1<\/figcaption><\/figure>\n<p>On the Site2 firewall, configure these settings:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%\">\n<caption>Table 3.15: Site2 Static Route Configuration<\/caption>\n<tbody>\n<tr>\n<th style=\"width: 50%\" scope=\"col\">Parameters<\/th>\n<th style=\"width: 50%\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Destination<\/td>\n<td style=\"width: 50%\">10.0.0.0\/24<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Interface<\/td>\n<td style=\"width: 50%\">tunnel.1<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">Next Hop<\/td>\n<td style=\"width: 50%\">None<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_316\" aria-describedby=\"caption-attachment-316\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-316 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-52-22-image.png\" alt=\"Static Route Configuration in the Site 2\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-52-22-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-52-22-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-52-22-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-52-22-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-52-22-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-52-22-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-52-22-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-316\" class=\"wp-caption-text\">Figure 3.63: Static Route Configuration in the Site 2<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<h2>Test the Site-to-Site<\/h2>\n<p>On any client device, try and ping the other client on the other site.<\/p>\n<figure id=\"attachment_317\" aria-describedby=\"caption-attachment-317\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-317 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-54-25-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-54-25-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-54-25-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-54-25-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-54-25-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-54-25-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-54-25-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-02-54-25-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-317\" class=\"wp-caption-text\">Figure 3.64: Verify your configuration<\/figcaption><\/figure>\n<p>If you can ping the other client in the other site, everything worke<span style=\"background-color: #ffff00\">d! If you go to <strong>Network &gt; IPSec<\/strong> <strong>Tunnels<\/strong>, the Tunnel status should be green<\/span>.<\/p>\n","protected":false},"author":1572,"menu_order":3,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-131","chapter","type-chapter","status-publish","hentry"],"part":123,"_links":{"self":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/users\/1572"}],"version-history":[{"count":25,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/131\/revisions"}],"predecessor-version":[{"id":1334,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/131\/revisions\/1334"}],"part":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/parts\/123"}],"metadata":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/131\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/media?parent=131"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapter-type?post=131"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/contributor?post=131"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/license?post=131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}