Auto-VPN Configuration with Branch Behind
NAT | (PAN-OS 10.0.3 and later PAN-OS 10.0
releases, and SD-WAN Plugin 2.0.1 and later 2.0 releases) If
you place your SD-WAN branch firewall behind a device performing
NAT, you need a way to specify the IP address of the public-facing
interface on that upstream device, which Auto VPN Configuration
uses as the tunnel endpoint for the branch. When you add an SD-WAN
branch to Panorama, you can now specify the IP address or FQDN of
the upstream device performing NAT for the branch, or you can specify
DDNS, which indicates that the IP address for the interface on the
NAT device is obtained from the Palo Alto Networks DDNS service.
Auto VPN uses the public IP address as the tunnel endpoint for the
branch. |