Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A network architect is designing a new branch office deployment that requires a secure, encrypted tunnel back to the corporate headquarters. Both sites use Palo Alto Networks firewalls. The branch office has a dynamic public IP address. Which type of site-to-site VPN configuration is best suited for this scenario?
- APolicy-based VPN
- BRoute-based VPN with static VTI
- CRoute-based VPN with a dynamic peer
- DSSL VPN
Show answer & explanationAnswer & explanation
Correct answer: C. Route-based VPN with a dynamic peer
When one side of a site-to-site VPN has a dynamic public IP address, a route-based VPN configured with a dynamic peer (using a dynamic DNS hostname or a pre-shared key with 'any' peer ID) is the most appropriate solution. This allows the VPN tunnel to re-establish even if the branch office's public IP changes.
Why the other options are wrong
- A. Policy-based VPNs are older and less flexible, and typically require static IPs for both endpoints.
- B. A static VTI (Virtual Tunnel Interface) requires both endpoints to have static IP addresses.
- D. SSL VPN is primarily for remote access (client-to-site) and not typically used for site-to-site tunnels between firewalls.
Dynamic Peer VPN
A dynamic peer VPN configuration allows one or both VPN endpoints to have a dynamic public IP address, typically using a FQDN or a 'any' peer ID for identification.
- Essential for branch offices with dynamic IPs.
- Often uses a Dynamic DNS service to update the FQDN.
- Requires specific IKE Gateway configuration for dynamic peers.
Memory trick: VPNs Connect Sites: Route for Dynamic, Policy for Static.