VPN Site-to-Site configuration with Palo Alto
Prerequisites
Ensure the following conditions are met before starting:
- The VPN Site-to-Site service is set up on FPT Cloud Portal.
- A Palo Alto firewall is installed and enabled on the customer side.
- The Palo Alto firewall has three IP addresses configured: Management (Public IP), WAN (Public IP), and LAN.
Step 1: Configure VPN Site-to-Site on FPT Cloud Portal
Create a Customer Gateway and a VPN Connection for the Palo Alto device on the FPT Cloud Portal. For detailed steps, see Create VPN connection.
Step 2: Configure IPsec on Palo Alto
- Log in to Palo Alto via the Management IP.
- Click Add and activate the Palo Alto Zone.
- Create a Virtual Router and click OK.
- Create WAN and LAN interfaces (for example, ethernet1/1 and ethernet1/2).
- Create an IKE Crypto profile.
- Create an IPSec Crypto profile.
-
Go to IPsec Tunnels:
- In the General tab, enter the Peer Address as the FPT Cloud IP from Step 1 (e.g.,
103.176.147.48). - In the Authentication section, enter the Pre-shared key value from the VPN Connection created in Step 1.
- In the General tab, enter the Peer Address as the FPT Cloud IP from Step 1 (e.g.,
- In the Advanced Options tab, fill in the required details.
- Create a GlobalProtect IPSec entry.
- Create the IPSec Tunnels.
Step 3: Configure firewall and routing on Palo Alto
- Open a firewall policy.
Configure the source and destination according to your environment rules.
- Configure routing between the two subnets (e.g.,
30.30.30.0/24and80.80.80.0/24). Adjust to match your actual source and destination networks.
You can now open a terminal to test network connectivity using ping.


















