{"id":327,"date":"2022-05-17T21:56:19","date_gmt":"2022-05-18T01:56:19","guid":{"rendered":"https:\/\/opentextbc.ca\/paloalto\/chapter\/s2s-vpn-palo-alto-on-prem-azure\/"},"modified":"2023-11-28T19:06:00","modified_gmt":"2023-11-29T00:06:00","slug":"s2s-vpn-palo-alto-on-prem-azure","status":"publish","type":"chapter","link":"https:\/\/opentextbc.ca\/paloalto\/chapter\/s2s-vpn-palo-alto-on-prem-azure\/","title":{"raw":"4.3 Site-to-Site VPN between Palo Alto on Premise and Palo Alto in the Azure","rendered":"4.3 Site-to-Site VPN between Palo Alto on Premise and Palo Alto in the Azure"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n \t<li>Configure a Virtual Network in Microsoft Azure<\/li>\n \t<li>Set up and configure the Azure VPN Gateway for IPsec VPN<\/li>\n \t<li>Implement Network Security Groups (NSGs) in Azure for traffic control<\/li>\n \t<li>Monitor and troubleshoot IPsec VPN connections on Palo Alto<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox shaded\"><strong>Scenario<\/strong>: In this lab, we will create a site-to-site VPN from Palo Alto on-premise to Palo Alto in the Azure. Knowing the configuration of section 4.2 is necessary for this lab. I have created management and ethernet1\/1 as a DHCP, so they will receive an IP address from Cloud.<\/div>\n\n[caption id=\"attachment_302\" align=\"aligncenter\" width=\"1510\"]<img class=\"wp-image-302 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2022\/05\/2.png\" alt=\"Main scenario - Site to Site VPN between Palo Alto on-prem and Palo Alto in the Azure\" width=\"1510\" height=\"538\"> Figure 4.68: Main scenario[\/caption]\n<h2 style=\"page-break-before: always;\">On-Premise Palo Alto Configuration<\/h2>\n<table style=\"border-collapse: collapse; width: 100%; height: 82px;\" border=\"0\">\n<tbody>\n<tr style=\"height: 18px;\">\n<th style=\"width: 25%; height: 18px;\" scope=\"col\">Devices<\/th>\n<th style=\"width: 25%; height: 18px;\" scope=\"col\">Interface<\/th>\n<th style=\"width: 25%; height: 18px;\" scope=\"col\">IP address<\/th>\n<\/tr>\n<tr style=\"height: 18px;\">\n<th style=\"width: 25%; height: 46px;\" rowspan=\"3\" scope=\"rowgroup\">Palo Alto<\/th>\n<td style=\"width: 25%; height: 18px;\">Management<\/td>\n<td style=\"width: 25%; height: 18px;\">DHCP Client<\/td>\n<\/tr>\n<tr style=\"height: 10px;\">\n<td style=\"width: 25%; height: 10px;\">Ethernet 1\/1<\/td>\n<td style=\"width: 25%; height: 10px;\">DHCP Client<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"width: 25%; height: 18px;\">Ethernet 1\/2<\/td>\n<td style=\"width: 25%; height: 18px;\">192.168.10.1\/24<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<th style=\"width: 25%; height: 18px;\" scope=\"row\">WebTerm<\/th>\n<td style=\"width: 25%; height: 18px;\">Eth0<\/td>\n<td style=\"width: 25%; height: 18px;\">192.168.10.2\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ol>\n \t<li>Configure the interfaces of the firewall. Set Ethernet1\/1 as a Untrust Zone and Ethernet1\/2 as a Trust Zone.\n\n[caption id=\"attachment_303\" align=\"aligncenter\" width=\"1447\"]<img class=\"wp-image-303 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00056.png\" alt=\"Firewall Interfaces\" width=\"1447\" height=\"227\"> Figure 4.69: Firewall Interfaces[\/caption]<\/li>\n \t<li>Create a <strong>tunnel.1<\/strong> and set the tunnel as Untrust zone.\n\n[caption id=\"attachment_304\" align=\"aligncenter\" width=\"1190\"]<img class=\"wp-image-304 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00057.png\" alt=\" Create a tunnel\" width=\"1190\" height=\"209\"> Figure 4.70: Create a tunnel[\/caption]<\/li>\n \t<li style=\"page-break-before: always;\">Create two static routes, one pointing to 142.232.197.254 (on-Prem Default Gateway) and the other one sending the traffic of Azure through the tunnel.\n\n[caption id=\"attachment_306\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-305\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00058.png\" alt=\"Create a static route to default gateway\" width=\"500\" height=\"456\"> Figure 4.71: Create a static route to default gateway[\/caption]\n\n[caption id=\"attachment_306\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-306\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00059.png\" alt=\"Create a static route to Azure\" width=\"500\" height=\"436\"> Figure 4.72: Create a static route to Azure[\/caption]<\/li>\n \t<li style=\"page-break-before: always;\">For setting up, site-to-site VPN we will use default IKE Crypto, IPsec Crypto profiles and we will only set IKE Gateway and IPsec Tunnel as following figures. You have to configure local and peer identification.\n\n[caption id=\"attachment_308\" align=\"aligncenter\" width=\"450\"]<img class=\"wp-image-307\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00067.png\" alt=\"Create an IKE Gateway\" width=\"450\" height=\"365\"> Figure 4.73: Create an IKE Gateway[\/caption]\n\n[caption id=\"attachment_308\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-308\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00061.png\" alt=\"Create an IPsec Tunnel\" width=\"500\" height=\"216\"> Figure 4.74: Create an IPsec Tunnel[\/caption]<\/li>\n \t<li style=\"page-break-before: always;\">Finally, create two security policies, one from Trust to Untrust zone and the other from Untrust to Trust zone.\n\n[caption id=\"attachment_309\" align=\"aligncenter\" width=\"1420\"]<img class=\"wp-image-309 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062.png\" alt=\"Create two security policies\" width=\"1420\" height=\"196\"> Figure 4.75: Create two security policies[\/caption]<\/li>\n<\/ol>\n<h2>Azure Configuration<\/h2>\n<ol>\n \t<li>Create a Palo Alto firewall in Azure and configure the interfaces. You need to do all steps in section 4.1 and assign public IP address to Ethernet 1 (Untrust Zone).<\/li>\n \t<li>Create a route in Azure pointing to Trust interface.\n\n[caption id=\"attachment_316\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-310\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00084.png\" alt=\"Step1- create a route table\" width=\"500\" height=\"263\"> Figure 4.76: Create a route table[\/caption]\n\n[caption id=\"attachment_316\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-311\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00085.png\" alt=\"Step2- create a route table\" width=\"500\" height=\"406\"> Figure 4.77: Create a route table[\/caption]\n\n[caption id=\"attachment_316\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-312\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00086.png\" alt=\" Step3- create a route table(verify and create)\" width=\"500\" height=\"422\"> Figure 4.78: Create a route table (verify and create)[\/caption]\n\n[caption id=\"attachment_316\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-313\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00087.png\" alt=\"Step4 - Add a Route\" width=\"500\" height=\"227\"> Figure 4.79: Add a Route[\/caption]\n\n[caption id=\"attachment_316\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-314\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00088.png\" alt=\"Step5 - Add a default route pointing to 10.0.2.4(Trust Interface)\" width=\"500\" height=\"428\"> Figure 4.80: Add a default route pointing to 10.0.2.4 (Trust Interface)[\/caption]\n\n[caption id=\"attachment_316\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-315\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089.png\" alt=\"Step 6 - Associate Trust route to Trust Subnet\" width=\"500\" height=\"125\"> Figure 4.81: Associate Trust route to Trust Subnet[\/caption]\n\n[caption id=\"attachment_316\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-316\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00090.png\" alt=\"Step 7 - Associate fwVNET to Trust Subnet\" width=\"500\" height=\"228\"> Figure 4.82: Associate fwVNET to Trust Subnet[\/caption]<\/li>\n \t<li>Set static routes as figures 4.83 and 4.84.\n\n[caption id=\"attachment_318\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-317\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00016-1.png\" alt=\"Static route pointing to default gateway\" width=\"500\" height=\"456\"> Figure 4.83: Static route pointing to default gateway[\/caption]\n\n[caption id=\"attachment_318\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-318\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00017-1.png\" alt=\" Static route pointing to tunnel\" width=\"500\" height=\"434\"> Figure 4.84: Static route pointing to tunnel[\/caption]<\/li>\n \t<li style=\"page-break-before: always;\">For setting up, site-to-site VPN we will use default IKE Crypto, IPsec Crypto profiles and we will only set IKE Gateway and IPsec Tunnel as figures 4.85 and 4.86.\n\n[caption id=\"attachment_320\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-319\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00064.png\" alt=\"Create an IKE Gateway\" width=\"500\" height=\"410\"> Figure 4.85: Create an IKE Gateway[\/caption]\n\n[caption id=\"attachment_320\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-320\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00066.png\" alt=\" Create an IPsec Tunnel\" width=\"500\" height=\"218\"> Figure 4.86: Create an IPsec Tunnel[\/caption]<\/li>\n \t<li style=\"page-break-before: always;\">Finally, create two security policies, one from Trust to Untrust zone and the other from Untrust to Trust zone.\n\n[caption id=\"attachment_321\" align=\"aligncenter\" width=\"800\"]<img class=\"wp-image-321\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1.png\" alt=\"Create two security policies\" width=\"800\" height=\"110\"> Figure 4.87: Create two security policies[\/caption]<\/li>\n \t<li>Add windows or Linux VM to Trust Subnet. This VM is for testing ping from Azure side to on-prem. We will not create a public IP address for the VM.\n\n[caption id=\"attachment_323\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-322\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00082.png\" alt=\"Create a VM\" width=\"500\" height=\"388\"> Figure 4.88: Create a VM[\/caption]\n\n[caption id=\"attachment_323\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-323\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00083.png\" alt=\" Assign Trust subnet with no public IP\" width=\"500\" height=\"363\"> Figure 4.89: Assign Trust subnet with no public IP[\/caption]<\/li>\n \t<li style=\"page-break-before: always;\">Now, you should be able to ping and your tunnel should be green.\n\n[caption id=\"attachment_326\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-324\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00091.png\" alt=\"ping from WebTerm to Azure\" width=\"500\" height=\"296\"> Figure 4.90: Ping from WebTerm to Azure[\/caption]\n\n[caption id=\"attachment_326\" align=\"aligncenter\" width=\"500\"]<img class=\"wp-image-325\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00092.png\" alt=\"Ping from Azure to WebTerm\" width=\"500\" height=\"352\"> Figure 4.91: Ping from Azure to WebTerm[\/caption]\n\n[caption id=\"attachment_326\" align=\"aligncenter\" width=\"1073\"]<img class=\"wp-image-326 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00025.png\" alt=\"Tunnel Status\" width=\"1073\" height=\"104\"> Figure 4.92: Tunnel Status[\/caption]<\/li>\n<\/ol>","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Configure a Virtual Network in Microsoft Azure<\/li>\n<li>Set up and configure the Azure VPN Gateway for IPsec VPN<\/li>\n<li>Implement Network Security Groups (NSGs) in Azure for traffic control<\/li>\n<li>Monitor and troubleshoot IPsec VPN connections on Palo Alto<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox shaded\"><strong>Scenario<\/strong>: In this lab, we will create a site-to-site VPN from Palo Alto on-premise to Palo Alto in the Azure. Knowing the configuration of section 4.2 is necessary for this lab. I have created management and ethernet1\/1 as a DHCP, so they will receive an IP address from Cloud.<\/div>\n<figure id=\"attachment_302\" aria-describedby=\"caption-attachment-302\" style=\"width: 1510px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-302 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2022\/05\/2.png\" alt=\"Main scenario - Site to Site VPN between Palo Alto on-prem and Palo Alto in the Azure\" width=\"1510\" height=\"538\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/05\/2.png 1510w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/05\/2-300x107.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/05\/2-1024x365.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/05\/2-768x274.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/05\/2-65x23.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/05\/2-225x80.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/05\/2-350x125.png 350w\" sizes=\"auto, (max-width: 1510px) 100vw, 1510px\" \/><figcaption id=\"caption-attachment-302\" class=\"wp-caption-text\">Figure 4.68: Main scenario<\/figcaption><\/figure>\n<h2 style=\"page-break-before: always;\">On-Premise Palo Alto Configuration<\/h2>\n<table style=\"border-collapse: collapse; width: 100%; height: 82px;\">\n<tbody>\n<tr style=\"height: 18px;\">\n<th style=\"width: 25%; height: 18px;\" scope=\"col\">Devices<\/th>\n<th style=\"width: 25%; height: 18px;\" scope=\"col\">Interface<\/th>\n<th style=\"width: 25%; height: 18px;\" scope=\"col\">IP address<\/th>\n<\/tr>\n<tr style=\"height: 18px;\">\n<th style=\"width: 25%; height: 46px;\" rowspan=\"3\" scope=\"rowgroup\">Palo Alto<\/th>\n<td style=\"width: 25%; height: 18px;\">Management<\/td>\n<td style=\"width: 25%; height: 18px;\">DHCP Client<\/td>\n<\/tr>\n<tr style=\"height: 10px;\">\n<td style=\"width: 25%; height: 10px;\">Ethernet 1\/1<\/td>\n<td style=\"width: 25%; height: 10px;\">DHCP Client<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"width: 25%; height: 18px;\">Ethernet 1\/2<\/td>\n<td style=\"width: 25%; height: 18px;\">192.168.10.1\/24<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<th style=\"width: 25%; height: 18px;\" scope=\"row\">WebTerm<\/th>\n<td style=\"width: 25%; height: 18px;\">Eth0<\/td>\n<td style=\"width: 25%; height: 18px;\">192.168.10.2\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ol>\n<li>Configure the interfaces of the firewall. Set Ethernet1\/1 as a Untrust Zone and Ethernet1\/2 as a Trust Zone.<br \/>\n<figure id=\"attachment_303\" aria-describedby=\"caption-attachment-303\" style=\"width: 1447px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-303 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00056.png\" alt=\"Firewall Interfaces\" width=\"1447\" height=\"227\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00056.png 1447w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00056-300x47.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00056-1024x161.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00056-768x120.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00056-65x10.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00056-225x35.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00056-350x55.png 350w\" sizes=\"auto, (max-width: 1447px) 100vw, 1447px\" \/><figcaption id=\"caption-attachment-303\" class=\"wp-caption-text\">Figure 4.69: Firewall Interfaces<\/figcaption><\/figure>\n<\/li>\n<li>Create a <strong>tunnel.1<\/strong> and set the tunnel as Untrust zone.<br \/>\n<figure id=\"attachment_304\" aria-describedby=\"caption-attachment-304\" style=\"width: 1190px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-304 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00057.png\" alt=\"Create a tunnel\" width=\"1190\" height=\"209\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00057.png 1190w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00057-300x53.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00057-1024x180.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00057-768x135.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00057-65x11.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00057-225x40.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00057-350x61.png 350w\" sizes=\"auto, (max-width: 1190px) 100vw, 1190px\" \/><figcaption id=\"caption-attachment-304\" class=\"wp-caption-text\">Figure 4.70: Create a tunnel<\/figcaption><\/figure>\n<\/li>\n<li style=\"page-break-before: always;\">Create two static routes, one pointing to 142.232.197.254 (on-Prem Default Gateway) and the other one sending the traffic of Azure through the tunnel.<br \/>\n<figure id=\"attachment_306\" aria-describedby=\"caption-attachment-306\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-305\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00058.png\" alt=\"Create a static route to default gateway\" width=\"500\" height=\"456\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00058.png 745w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00058-300x273.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00058-65x59.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00058-225x205.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00058-350x319.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-306\" class=\"wp-caption-text\">Figure 4.71: Create a static route to default gateway<\/figcaption><\/figure>\n<figure id=\"attachment_306\" aria-describedby=\"caption-attachment-306\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-306\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00059.png\" alt=\"Create a static route to Azure\" width=\"500\" height=\"436\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00059.png 744w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00059-300x262.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00059-65x57.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00059-225x196.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00059-350x305.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-306\" class=\"wp-caption-text\">Figure 4.72: Create a static route to Azure<\/figcaption><\/figure>\n<\/li>\n<li style=\"page-break-before: always;\">For setting up, site-to-site VPN we will use default IKE Crypto, IPsec Crypto profiles and we will only set IKE Gateway and IPsec Tunnel as following figures. You have to configure local and peer identification.<br \/>\n<figure id=\"attachment_308\" aria-describedby=\"caption-attachment-308\" style=\"width: 450px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-307\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00067.png\" alt=\"Create an IKE Gateway\" width=\"450\" height=\"365\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00067.png 740w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00067-300x243.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00067-65x53.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00067-225x182.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00067-350x284.png 350w\" sizes=\"auto, (max-width: 450px) 100vw, 450px\" \/><figcaption id=\"caption-attachment-308\" class=\"wp-caption-text\">Figure 4.73: Create an IKE Gateway<\/figcaption><\/figure>\n<figure id=\"attachment_308\" aria-describedby=\"caption-attachment-308\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-308\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00061.png\" alt=\"Create an IPsec Tunnel\" width=\"500\" height=\"216\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00061.png 992w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00061-300x130.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00061-768x332.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00061-65x28.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00061-225x97.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00061-350x151.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-308\" class=\"wp-caption-text\">Figure 4.74: Create an IPsec Tunnel<\/figcaption><\/figure>\n<\/li>\n<li style=\"page-break-before: always;\">Finally, create two security policies, one from Trust to Untrust zone and the other from Untrust to Trust zone.<br \/>\n<figure id=\"attachment_309\" aria-describedby=\"caption-attachment-309\" style=\"width: 1420px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-309 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062.png\" alt=\"Create two security policies\" width=\"1420\" height=\"196\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062.png 1420w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-300x41.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1024x141.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-768x106.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-65x9.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-225x31.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-350x48.png 350w\" sizes=\"auto, (max-width: 1420px) 100vw, 1420px\" \/><figcaption id=\"caption-attachment-309\" class=\"wp-caption-text\">Figure 4.75: Create two security policies<\/figcaption><\/figure>\n<\/li>\n<\/ol>\n<h2>Azure Configuration<\/h2>\n<ol>\n<li>Create a Palo Alto firewall in Azure and configure the interfaces. You need to do all steps in section 4.1 and assign public IP address to Ethernet 1 (Untrust Zone).<\/li>\n<li>Create a route in Azure pointing to Trust interface.<br \/>\n<figure id=\"attachment_316\" aria-describedby=\"caption-attachment-316\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-310\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00084.png\" alt=\"Step1- create a route table\" width=\"500\" height=\"263\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00084.png 890w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00084-300x158.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00084-768x405.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00084-65x34.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00084-225x119.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00084-350x184.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-316\" class=\"wp-caption-text\">Figure 4.76: Create a route table<\/figcaption><\/figure>\n<figure id=\"attachment_316\" aria-describedby=\"caption-attachment-316\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-311\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00085.png\" alt=\"Step2- create a route table\" width=\"500\" height=\"406\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00085.png 1012w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00085-300x243.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00085-768x623.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00085-65x53.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00085-225x183.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00085-350x284.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-316\" class=\"wp-caption-text\">Figure 4.77: Create a route table<\/figcaption><\/figure>\n<figure id=\"attachment_316\" aria-describedby=\"caption-attachment-316\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-312\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00086.png\" alt=\"Step3- create a route table(verify and create)\" width=\"500\" height=\"422\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00086.png 982w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00086-300x253.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00086-768x648.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00086-65x55.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00086-225x190.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00086-350x295.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-316\" class=\"wp-caption-text\">Figure 4.78: Create a route table (verify and create)<\/figcaption><\/figure>\n<figure id=\"attachment_316\" aria-describedby=\"caption-attachment-316\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-313\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00087.png\" alt=\"Step4 - Add a Route\" width=\"500\" height=\"227\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00087.png 1224w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00087-300x136.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00087-1024x464.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00087-768x348.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00087-65x29.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00087-225x102.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00087-350x159.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-316\" class=\"wp-caption-text\">Figure 4.79: Add a Route<\/figcaption><\/figure>\n<figure id=\"attachment_316\" aria-describedby=\"caption-attachment-316\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-314\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00088.png\" alt=\"Step5 - Add a default route pointing to 10.0.2.4(Trust Interface)\" width=\"500\" height=\"428\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00088.png 790w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00088-300x257.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00088-768x657.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00088-65x56.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00088-225x193.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00088-350x299.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-316\" class=\"wp-caption-text\">Figure 4.80: Add a default route pointing to 10.0.2.4 (Trust Interface)<\/figcaption><\/figure>\n<figure id=\"attachment_316\" aria-describedby=\"caption-attachment-316\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-315\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089.png\" alt=\"Step 6 - Associate Trust route to Trust Subnet\" width=\"500\" height=\"125\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089.png 1883w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089-300x75.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089-1024x256.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089-768x192.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089-1536x384.png 1536w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089-65x16.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089-225x56.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00089-350x88.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-316\" class=\"wp-caption-text\">Figure 4.81: Associate Trust route to Trust Subnet<\/figcaption><\/figure>\n<figure id=\"attachment_316\" aria-describedby=\"caption-attachment-316\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-316\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00090.png\" alt=\"Step 7 - Associate fwVNET to Trust Subnet\" width=\"500\" height=\"228\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00090.png 788w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00090-300x137.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00090-768x351.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00090-65x30.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00090-225x103.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00090-350x160.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-316\" class=\"wp-caption-text\">Figure 4.82: Associate fwVNET to Trust Subnet<\/figcaption><\/figure>\n<\/li>\n<li>Set static routes as figures 4.83 and 4.84.<br \/>\n<figure id=\"attachment_318\" aria-describedby=\"caption-attachment-318\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-317\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00016-1.png\" alt=\"Static route pointing to default gateway\" width=\"500\" height=\"456\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00016-1.png 597w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00016-1-300x274.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00016-1-65x59.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00016-1-225x205.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00016-1-350x320.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-318\" class=\"wp-caption-text\">Figure 4.83: Static route pointing to default gateway<\/figcaption><\/figure>\n<figure id=\"attachment_318\" aria-describedby=\"caption-attachment-318\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-318\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00017-1.png\" alt=\"Static route pointing to tunnel\" width=\"500\" height=\"434\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00017-1.png 595w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00017-1-300x261.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00017-1-65x56.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00017-1-225x196.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00017-1-350x304.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-318\" class=\"wp-caption-text\">Figure 4.84: Static route pointing to tunnel<\/figcaption><\/figure>\n<\/li>\n<li style=\"page-break-before: always;\">For setting up, site-to-site VPN we will use default IKE Crypto, IPsec Crypto profiles and we will only set IKE Gateway and IPsec Tunnel as figures 4.85 and 4.86.<br \/>\n<figure id=\"attachment_320\" aria-describedby=\"caption-attachment-320\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-319\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00064.png\" alt=\"Create an IKE Gateway\" width=\"500\" height=\"410\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00064.png 742w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00064-300x246.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00064-65x53.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00064-225x184.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00064-350x287.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-320\" class=\"wp-caption-text\">Figure 4.85: Create an IKE Gateway<\/figcaption><\/figure>\n<figure id=\"attachment_320\" aria-describedby=\"caption-attachment-320\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-320\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00066.png\" alt=\"Create an IPsec Tunnel\" width=\"500\" height=\"218\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00066.png 993w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00066-300x131.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00066-768x335.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00066-65x28.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00066-225x98.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00066-350x153.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-320\" class=\"wp-caption-text\">Figure 4.86: Create an IPsec Tunnel<\/figcaption><\/figure>\n<\/li>\n<li style=\"page-break-before: always;\">Finally, create two security policies, one from Trust to Untrust zone and the other from Untrust to Trust zone.<br \/>\n<figure id=\"attachment_321\" aria-describedby=\"caption-attachment-321\" style=\"width: 800px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-321\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1.png\" alt=\"Create two security policies\" width=\"800\" height=\"110\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1.png 1420w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1-300x41.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1-1024x141.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1-768x106.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1-65x9.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1-225x31.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00062-1-350x48.png 350w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><figcaption id=\"caption-attachment-321\" class=\"wp-caption-text\">Figure 4.87: Create two security policies<\/figcaption><\/figure>\n<\/li>\n<li>Add windows or Linux VM to Trust Subnet. This VM is for testing ping from Azure side to on-prem. We will not create a public IP address for the VM.<br \/>\n<figure id=\"attachment_323\" aria-describedby=\"caption-attachment-323\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-322\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00082.png\" alt=\"Create a VM\" width=\"500\" height=\"388\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00082.png 1060w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00082-300x233.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00082-1024x794.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00082-768x596.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00082-65x50.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00082-225x174.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00082-350x271.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-323\" class=\"wp-caption-text\">Figure 4.88: Create a VM<\/figcaption><\/figure>\n<figure id=\"attachment_323\" aria-describedby=\"caption-attachment-323\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-323\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00083.png\" alt=\"Assign Trust subnet with no public IP\" width=\"500\" height=\"363\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00083.png 1131w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00083-300x218.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00083-1024x742.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00083-768x557.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00083-65x47.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00083-225x163.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00083-350x254.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-323\" class=\"wp-caption-text\">Figure 4.89: Assign Trust subnet with no public IP<\/figcaption><\/figure>\n<\/li>\n<li style=\"page-break-before: always;\">Now, you should be able to ping and your tunnel should be green.<br \/>\n<figure id=\"attachment_326\" aria-describedby=\"caption-attachment-326\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-324\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00091.png\" alt=\"ping from WebTerm to Azure\" width=\"500\" height=\"296\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00091.png 810w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00091-300x178.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00091-768x455.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00091-65x39.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00091-225x133.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00091-350x207.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-326\" class=\"wp-caption-text\">Figure 4.90: Ping from WebTerm to Azure<\/figcaption><\/figure>\n<figure id=\"attachment_326\" aria-describedby=\"caption-attachment-326\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-325\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00092.png\" alt=\"Ping from Azure to WebTerm\" width=\"500\" height=\"352\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00092.png 786w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00092-300x211.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00092-768x540.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00092-65x46.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00092-225x158.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00092-350x246.png 350w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-326\" class=\"wp-caption-text\">Figure 4.91: Ping from Azure to WebTerm<\/figcaption><\/figure>\n<figure id=\"attachment_326\" aria-describedby=\"caption-attachment-326\" style=\"width: 1073px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-326 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00025.png\" alt=\"Tunnel Status\" width=\"1073\" height=\"104\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00025.png 1073w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00025-300x29.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00025-1024x99.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00025-768x74.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00025-65x6.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00025-225x22.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/ScreenShot00025-350x34.png 350w\" sizes=\"auto, (max-width: 1073px) 100vw, 1073px\" \/><figcaption id=\"caption-attachment-326\" class=\"wp-caption-text\">Figure 4.92: Tunnel Status<\/figcaption><\/figure>\n<\/li>\n<\/ol>\n","protected":false},"author":124,"menu_order":6,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-327","chapter","type-chapter","status-publish","hentry"],"part":230,"_links":{"self":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/users\/124"}],"version-history":[{"count":1,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/327\/revisions"}],"predecessor-version":[{"id":328,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/327\/revisions\/328"}],"part":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/parts\/230"}],"metadata":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/327\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/media?parent=327"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapter-type?post=327"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/contributor?post=327"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/license?post=327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}