{"id":734,"date":"2026-08-26T08:02:49","date_gmt":"2026-08-26T02:32:49","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/palo-alto-site-to-site-ipsec-vpn\/"},"modified":"2026-09-30T14:55:17","modified_gmt":"2026-09-30T09:25:17","slug":"palo-alto-site-to-site-ipsec-vpn","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/","title":{"rendered":"Palo Alto Site-to-Site IPsec VPN Configuration with a Branch Office Example"},"content":{"rendered":"<p>Connecting geographically separated office locations securely across the public internet is a core requirement for enterprise networks. Setting up a <strong>Palo Alto site to site IPsec VPN<\/strong> allows organizations to build encrypted, route-based tunnels between Next-Generation Firewalls (NGFW). Route-based VPNs decouple the network topology from the encryption mechanism, simplifying routing policies and security rule management.<\/p>\n<p>This technical guide demonstrates how to configure, verify, and troubleshoot a route-based IPsec VPN connecting a Head Office firewall to a remote Branch Office firewall. The example uses explicit lab IP addressing and step-by-step instructions to ensure a production-ready deployment.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>A growing financial services firm needs to connect its Head Office network to a newly opened Branch Office. Remote users and local servers at both sites require secure, bi-directional communication across the untrusted public internet.<\/p>\n<p>Key operational requirements include:<\/p>\n<ul>\n<li>Encrypted connectivity between the HQ internal subnet (<code>10.10.10.0\/24<\/code>) and the Branch internal subnet (<code>10.20.20.0\/24<\/code>).<\/li>\n<li>Route-based IPsec architecture using dedicated tunnel interfaces to support future dynamic routing policies.<\/li>\n<li>Strong cryptographic standards compliant with current security benchmarks (AES-256-GCM, SHA-256, Diffie-Hellman Group 19).<\/li>\n<li>Isolating VPN traffic into a dedicated logical security zone for fine-grained access control.<\/li>\n<\/ul>\n<h2>Lab Topology<\/h2>\n<p>The network topology consists of two Palo Alto Networks firewalls connected via public IP addresses over an internet gateway path. Dedicated virtual tunnel interfaces handles the IPsec encapsulations.<\/p>\n<pre>\n[ Head Office LAN ]                                                      [ Branch Office LAN ]\n  10.10.10.0\/24                                                            10.20.20.0\/24\n       |                                                                        |\n (eth1\/2 - Trust Zone)                                                    (eth1\/2 - Trust Zone)\n[ PA-HQ-FW ]                                                             [ PA-BO-FW ]\n (eth1\/1 - Untrust Zone: 198.51.100.1)                                   (eth1\/1 - Untrust Zone: 203.0.113.1)\n  [ tunnel.1 - VPN Zone: 10.255.255.1\/30 ]                                 [ tunnel.1 - VPN Zone: 10.255.255.2\/30 ]\n       |                                                                        |\n       +====================== IPsec Tunnel (Internet) =========================+\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The table below outlines the network addresses, zones, and parameters used throughout this configuration. Example public IP addresses use official documentation ranges reserved by RFC 5737 (<code>198.51.100.0\/24<\/code> and <code>203.0.113.0\/24<\/code>). Adapt these values to match your WAN allocation.<\/p>\n<table>\n<thead>\n<tr>\n<th>Parameter \/ Object<\/th>\n<th>Head Office (PA-HQ-FW)<\/th>\n<th>Branch Office (PA-BO-FW)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Untrust Interface<\/strong><\/td>\n<td>ethernet1\/1 (198.51.100.1\/24)<\/td>\n<td>ethernet1\/1 (203.0.113.1\/24)<\/td>\n<\/tr>\n<tr>\n<td><strong>Trust Interface<\/strong><\/td>\n<td>ethernet1\/2 (10.10.10.1\/24)<\/td>\n<td>ethernet1\/2 (10.20.20.1\/24)<\/td>\n<\/tr>\n<tr>\n<td><strong>Tunnel Interface<\/strong><\/td>\n<td>tunnel.1 (10.255.255.1\/30)<\/td>\n<td>tunnel.1 (10.255.255.2\/30)<\/td>\n<\/tr>\n<tr>\n<td><strong>Internal Subnet<\/strong><\/td>\n<td>10.10.10.0\/24<\/td>\n<td>10.20.20.0\/24<\/td>\n<\/tr>\n<tr>\n<td><strong>VPN Zone Name<\/strong><\/td>\n<td>VPN-Zone<\/td>\n<td>VPN-Zone<\/td>\n<\/tr>\n<tr>\n<td><strong>IKE Profile \/ Version<\/strong><\/td>\n<td>IKEv2 \/ AES-256-GCM \/ DH Group 19<\/td>\n<td>IKEv2 \/ AES-256-GCM \/ DH Group 19<\/td>\n<\/tr>\n<tr>\n<td><strong>IPsec Profile<\/strong><\/td>\n<td>ESP \/ AES-256-GCM \/ DH Group 19<\/td>\n<td>ESP \/ AES-256-GCM \/ DH Group 19<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Before initiating the VPN configuration, verify that the following environment criteria are met:<\/p>\n<ul>\n<li>Static public IPv4 addresses assigned to the external interface of each firewall.<\/li>\n<li>Upstream ISPs allow UDP port 500 (IKE), UDP port 4500 (IKE NAT-Traversal), and IP Protocol 50 (ESP).<\/li>\n<li>Administrative access to both firewalls with rights to commit configuration changes.<\/li>\n<li>A secure, pre-shared key (PSK) generated for tunnel authentication.<\/li>\n<\/ul>\n<h2>Palo Alto Site to Site IPsec VPN Configuration Steps<\/h2>\n<p>The configuration steps below detail the setup process on the Head Office firewall (PA-HQ-FW). Apply the symmetric configuration to the Branch Office firewall (PA-BO-FW) by swapping local and remote IP addresses.<\/p>\n<h3>Step 1: Create the Tunnel Interface<\/h3>\n<p>Route-based VPNs use logical tunnel interfaces to pass traffic into the IPsec processing engine.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; Interfaces &gt; Tunnel<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> at the bottom of the screen.<\/li>\n<li>In the <strong>Config<\/strong> tab, set the interface <strong>Name<\/strong> to <code>tunnel.1<\/code>.<\/li>\n<li>Assign the interface to a <strong>Virtual Router<\/strong> (e.g., <code>default<\/code>).<\/li>\n<li>Assign the <strong>Security Zone<\/strong>. Create a dedicated zone named <code>VPN-Zone<\/code> (Layer 3 type) for simplified security management.<\/li>\n<li>In the <strong>IPv4<\/strong> tab, click <strong>Add<\/strong> and assign <code>10.255.255.1\/30<\/code>.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 2: Define the IKE Crypto Profile (Phase 1 Parameters)<\/h3>\n<p>The IKE Crypto Profile defines the encryption, authentication, and Diffie-Hellman algorithms used during Phase 1 tunnel negotiation.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; Network Profiles &gt; IKE Crypto<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> and name the profile <code>IKE-Crypto-Corporate<\/code>.<\/li>\n<li>Set <strong>DH Group<\/strong> to <code>group19<\/code>.<\/li>\n<li>Set <strong>Encryption<\/strong> to <code>aes-256-gcm<\/code>.<\/li>\n<li>Set <strong>Authentication<\/strong> to <code>sha256<\/code>.<\/li>\n<li>Set <strong>Lifetime<\/strong> to <code>8 Hours<\/code> (default).<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 3: Define the IKE Gateway<\/h3>\n<p>The IKE Gateway configures the identity and authentication parameters of the remote peer.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; Network Profiles &gt; IKE Gateways<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> and set the name to <code>IKE-GW-Branch<\/code>.<\/li>\n<li>In the <strong>General<\/strong> tab:\n<ul>\n<li>Set <strong>Version<\/strong> to <code>IKEv2 only mode<\/code> (or <code>IKEv2 preferred mode<\/code>).<\/li>\n<li>Set <strong>Address Type<\/strong> to <code>IPv4<\/code>.<\/li>\n<li>Set <strong>Interface<\/strong> to <code>ethernet1\/1<\/code> (the WAN interface).<\/li>\n<li>Set <strong>Local IP Address<\/strong> to <code>198.51.100.1\/24<\/code>.<\/li>\n<li>Set <strong>Peer Address<\/strong> to <code>203.0.113.1<\/code>.<\/li>\n<li>Select <strong>Pre-shared Key<\/strong> under Authentication, then enter and confirm your secret key.<\/li>\n<\/ul>\n<\/li>\n<li>In the <strong>Advanced Options<\/strong> tab:\n<ul>\n<li>Set <strong>IKE Crypto Profile<\/strong> to <code>IKE-Crypto-Corporate<\/code>.<\/li>\n<li>Enable <strong>Enable NAT Traversal<\/strong> if either endpoint resides behind dynamic NAT.<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 4: Define the IPsec Crypto Profile (Phase 2 Parameters)<\/h3>\n<p>The IPsec Crypto Profile specifies encryption and authentication protocols for protecting user payload data.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; Network Profiles &gt; IPsec Crypto<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> and name the profile <code>IPsec-Crypto-Corporate<\/code>.<\/li>\n<li>Set <strong>IPsec Protocol<\/strong> to <code>ESP<\/code>.<\/li>\n<li>Set <strong>Encryption<\/strong> to <code>aes-256-gcm<\/code>.<\/li>\n<li>Set <strong>Authentication<\/strong> to <code>sha256<\/code>.<\/li>\n<li>Set <strong>DH Group<\/strong> (Perfect Forward Secrecy) to <code>group19<\/code>.<\/li>\n<li>Set <strong>Lifetime<\/strong> to <code>1 Hours<\/code>.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 5: Create the IPsec Tunnel<\/h3>\n<p>The IPsec Tunnel object binds the tunnel interface, the IKE Gateway, and the Phase 2 crypto parameters together.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; IPSec Tunnels<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong> and name the tunnel <code>IPsec-Tunnel-Branch<\/code>.<\/li>\n<li>Select <strong>Tunnel Interface<\/strong> <code>tunnel.1<\/code>.<\/li>\n<li>Select <strong>IKE Gateway<\/strong> <code>IKE-GW-Branch<\/code>.<\/li>\n<li>Select <strong>IPsec Crypto Profile<\/strong> <code>IPsec-Crypto-Corporate<\/code>.<\/li>\n<li><em>Proxy IDs (Optional):<\/em> Leave Proxy IDs blank when connecting two Palo Alto firewalls using route-based configurations. If connecting to a policy-based firewall (such as older legacy systems), explicitly define local and remote subnets in the <strong>Proxy ID<\/strong> tab.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 6: Configure Static Routes<\/h3>\n<p>Traffic must be routed to the tunnel interface for the firewall to perform IPsec encapsulation.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; Virtual Routers<\/strong> and select your virtual router (e.g., <code>default<\/code>).<\/li>\n<li>Click <strong>Static Routes<\/strong>, then click <strong>Add<\/strong>.<\/li>\n<li>Set <strong>Name<\/strong> to <code>Route-To-Branch<\/code>.<\/li>\n<li>Set <strong>Destination<\/strong> to <code>10.20.20.0\/24<\/code> (the Branch internal subnet).<\/li>\n<li>Set <strong>Interface<\/strong> to <code>tunnel.1<\/code>.<\/li>\n<li>Set <strong>Next Hop<\/strong> to <code>None<\/code> (or specify <code>10.255.255.2<\/code>).<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 7: Define Security Policies<\/h3>\n<p>Because traffic passes between distinct security zones (<code>Trust<\/code> and <code>VPN-Zone<\/code>), security policy rules must permit flow in both directions.<\/p>\n<ol>\n<li>Navigate to <strong>Policies &gt; Security<\/strong>.<\/li>\n<li>Add a rule named <code>Allow-HQ-To-Branch<\/code>:\n<ul>\n<li><strong>Source Zone:<\/strong> <code>Trust<\/code><\/li>\n<li><strong>Source Address:<\/strong> <code>10.10.10.0\/24<\/code><\/li>\n<li><strong>Destination Zone:<\/strong> <code>VPN-Zone<\/code><\/li>\n<li><strong>Destination Address:<\/strong> <code>10.20.20.0\/24<\/code><\/li>\n<li><strong>Application\/Service:<\/strong> <code>any<\/code> (or specify required applications)<\/li>\n<li><strong>Action:<\/strong> <code>Allow<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Add a reciprocal rule named <code>Allow-Branch-To-HQ<\/code>:\n<ul>\n<li><strong>Source Zone:<\/strong> <code>VPN-Zone<\/code><\/li>\n<li><strong>Source Address:<\/strong> <code>10.20.20.0\/24<\/code><\/li>\n<li><strong>Destination Zone:<\/strong> <code>Trust<\/code><\/li>\n<li><strong>Destination Address:<\/strong> <code>10.10.10.0\/24<\/code><\/li>\n<li><strong>Action:<\/strong> <code>Allow<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>Commit<\/strong> to save and activate the configuration.<\/li>\n<\/ol>\n<h2>CLI Commands<\/h2>\n<p>The PAN-OS command line interface provides efficient verification and management of IPsec configurations. The following validated CLI commands allow administrators to view tunnel state and clear active Security Associations (SAs) during testing.<\/p>\n<p>To view active Phase 1 IKE gateways and status:<\/p>\n<pre>show ike gateway<\/pre>\n<p>To view Phase 1 IKE Security Associations (IKE-SAs):<\/p>\n<pre>show vpn ike-sa<\/pre>\n<p>To view Phase 2 IPsec Security Associations (IPsec-SAs):<\/p>\n<pre>show vpn ipsec-sa<\/pre>\n<p>To view operational details for a specific IPsec tunnel:<\/p>\n<pre>show vpn flow name IPsec-Tunnel-Branch<\/pre>\n<p>To manually initiate IKE Phase 1 negotiation for testing:<\/p>\n<pre>test vpn ike-sa gateway IKE-GW-Branch<\/pre>\n<p>To manually initiate IPsec Phase 2 negotiation:<\/p>\n<pre>test vpn ipsec-sa tunnel IPsec-Tunnel-Branch<\/pre>\n<div class=\"caution\">\n    <strong>CAUTION:<\/strong> Resetting active Security Associations interrupts live user traffic traversing the tunnel. Only clear active SAs during maintenance windows or initial lab deployments.\n<\/div>\n<p>To clear a running IKE gateway session:<\/p>\n<pre>clear vpn ike-sa gateway IKE-GW-Branch<\/pre>\n<p>To clear an active IPsec SA session:<\/p>\n<pre>clear vpn ipsec-sa tunnel IPsec-Tunnel-Branch<\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding packet flow through the Palo Alto Networks architecture helps when auditing traffic and writing firewall rules. The step-by-step path for an outbound packet originating from the HQ local area network is detailed below:<\/p>\n<ol>\n<li><strong>Ingress Lookup:<\/strong> A host at <code>10.10.10.50<\/code> sends a packet destination-bound to <code>10.20.20.100<\/code>. The packet arrives at interface <code>ethernet1\/2<\/code> (Zone: <code>Trust<\/code>).<\/li>\n<li><strong>Routing Lookup (Pre-NAT):<\/strong> The virtual router evaluates its Forwarding Information Base (FIB). The best matching static route for <code>10.20.20.0\/24<\/code> dictates the egress interface as <code>tunnel.1<\/code>.<\/li>\n<li><strong>Security Policy Evaluation:<\/strong> The firewall checks security policies using the original (pre-NAT) addresses and zones. The flow context matches <strong>Source Zone:<\/strong> <code>Trust<\/code> to <strong>Destination Zone:<\/strong> <code>VPN-Zone<\/code>. The packet is permitted.<\/li>\n<li><strong>IPsec Encapsulation:<\/strong> The packet enters interface <code>tunnel.1<\/code>. The IPsec engine encapsulates the original IP packet inside an Encapsulating Security Payload (ESP) header using symmetric keys negotiated during Phase 2.<\/li>\n<li><strong>Outer Packet Forwarding:<\/strong> The firewall constructs a new outer IP header. The outer source address is <code>198.51.100.1<\/code>, and the outer destination address is <code>203.0.113.1<\/code>.<\/li>\n<li><strong>Egress Routing Lookup:<\/strong> The virtual router evaluates the path for the outer destination address (<code>203.0.113.1<\/code>). The route points out interface <code>ethernet1\/1<\/code> (Zone: <code>Untrust<\/code>).<\/li>\n<li><strong>Egress Transmission:<\/strong> The encapsulated ESP packet is sent over the internet to the Branch Office firewall.<\/li>\n<\/ol>\n<h2>Verification<\/h2>\n<p>Confirm proper tunnel initialization using both the Web Interface and the CLI.<\/p>\n<h3>1. Web Interface Status Checks<\/h3>\n<p>Navigate to <strong>Network &gt; IPSec Tunnels<\/strong>. Look at the status indicators next to the tunnel name:<\/p>\n<ul>\n<li><strong>Status Icon (IKE Phase 1):<\/strong> Green indicates that Phase 1 IKE negotiation is active and authenticated.<\/li>\n<li><strong>Tunnel Status Icon (IPsec Phase 2):<\/strong> Green indicates that Phase 2 IPsec SAs are active and established.<\/li>\n<\/ul>\n<h3>2. CLI Verification Commands<\/h3>\n<p>Run the operational commands to confirm active key associations:<\/p>\n<pre>\nadmin@PA-HQ-FW&gt; show vpn ike-sa\n\nIKEv2 SAs\nGateway             ID           Peer IP          Role  State    Algorithm\n-------             --           -------          ----  -----    ---------\nIKE-GW-Branch       101          203.0.113.1      Init  ESTAB    AES256-GCM\/SHA256\/DH19\n<\/pre>\n<p>Next, verify Phase 2 IPsec Security Associations:<\/p>\n<pre>\nadmin@PA-HQ-FW&gt; show vpn ipsec-sa\n\nID     Name                Gateway        Interface   State   Encapsulation\n--     ----                -------        ---------   -----   -------------\n201    IPsec-Tunnel-Branch IKE-GW-Branch  tunnel.1    active  ESP\n<\/pre>\n<h3>3. Data Plane Testing<\/h3>\n<p>Initiate traffic from a device on the HQ local subnet to an internal IP address on the Branch local subnet. Alternatively, run an extended ping test directly from the firewall CLI, ensuring you specify the source IP address matching the local Trust interface:<\/p>\n<pre>ping source 10.10.10.1 host 10.20.20.1<\/pre>\n<h2>Troubleshooting<\/h2>\n<p>When an IPsec tunnel fails to connect or drops packets, isolate the failure to Phase 1, Phase 2, or general forwarding issues using this structured troubleshooting sequence.<\/p>\n<h3>Phase 1 Failure (IKE Gateway Issues)<\/h3>\n<ul>\n<li><strong>Symptom:<\/strong> IKE status light remains red\/gray; <code>show vpn ike-sa<\/code> returns no active SAs.<\/li>\n<li><strong>Common Causes:<\/strong> Pre-shared key mismatch, incorrect Peer IP, mismatched IKE versions, or upstream intermediate devices dropping UDP 500 \/ UDP 4500 traffic.<\/li>\n<li><strong>Action:<\/strong> Check system logs for detailed error messaging:\n<pre>show log system feature eq ike direction backward<\/pre>\n<p>    Look for messages indicating <code>Authentication failed<\/code> (PSK mismatch) or <code>No response from peer<\/code> (routing\/firewall block).<\/li>\n<\/ul>\n<h3>Phase 2 Failure (IPsec Tunnel Issues)<\/h3>\n<ul>\n<li><strong>Symptom:<\/strong> Phase 1 status is green, but Phase 2 status remains red\/gray.<\/li>\n<li><strong>Common Causes:<\/strong> IPsec profile parameters mismatch (mismatched DH group or hash settings), mismatched Proxy ID configurations when interconnecting with policy-based systems, or proposal rejections.<\/li>\n<li><strong>Action:<\/strong> Run the operational CLI test to force negotiation and observe output errors:\n<pre>test vpn ipsec-sa tunnel IPsec-Tunnel-Branch<\/pre>\n<\/li>\n<\/ul>\n<h3>Traffic Passing Failure (Data Plane Issues)<\/h3>\n<ul>\n<li><strong>Symptom:<\/strong> Both Phase 1 and Phase 2 status indicators show green, but traffic fails to traverse the tunnel.<\/li>\n<li><strong>Common Causes:<\/strong>\n<ul>\n<li>Missing static route pointing destination subnets to the <code>tunnel.x<\/code> interface.<\/li>\n<li>Security policies dropping traffic between <code>Trust<\/code> and <code>VPN-Zone<\/code>.<\/li>\n<li>Unintended NAT policies translating local source addresses into public egress interface addresses prior to tunnel entry.<\/li>\n<li>Missing reverse routes on the destination network firewall.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Action:<\/strong> Inspect active sessions in the traffic log under <strong>Monitor &gt; Logs &gt; Traffic<\/strong>. Search for destination subnets to confirm whether traffic is being allowed or dropped by security policies.<\/li>\n<\/ul>\n<h2>Common Mistakes<\/h2>\n<ol>\n<li><strong>Incorrect Security Policy Zones:<\/strong> Placing the tunnel interface in the <code>Untrust<\/code> zone instead of a dedicated <code>VPN-Zone<\/code>. Assigning tunnel interfaces to a dedicated zone makes writing clean security policies easier and prevents unintended access rules.<\/li>\n<li><strong>Overlapping NAT Rules:<\/strong> Failing to exclude VPN subnets from outbound Internet Source NAT policies. Check that generic outbound NAT rules do not match traffic destined for remote internal VPN networks.<\/li>\n<li><strong>Ignoring Path MTU and TCP MSS:<\/strong> Large packets transmitted across IPsec tunnels experience extra overhead from ESP encapsulation. If the resulting packet exceeds the WAN MTU, packets fragment or drop. Set TCP MSS adjustment on the logical tunnel interface to prevent PMTU black-hole issues:\n<ol>\n<li>Navigate to <strong>Network &gt; Interfaces &gt; Tunnel<\/strong> and select <code>tunnel.1<\/code>.<\/li>\n<li>In the <strong>Advanced<\/strong> tab, enable <strong>Adjust TCP MSS<\/strong>.<\/li>\n<li>Set IPv4 MSS value to <code>1350<\/code> (or <code>1400<\/code>).<\/li>\n<\/ol>\n<\/li>\n<li><strong>Proxy ID Mismatches with Legacy Peers:<\/strong> Route-based VPNs do not strictly require Proxy IDs when both firewalls use route-based designs. However, connecting to a policy-based firewall requires configuring matching Proxy IDs explicitly under the IPsec Tunnel settings.<\/li>\n<\/ol>\n<h2>Production Considerations<\/h2>\n<p>When deploying IPsec site-to-site tunnels in business-critical enterprise environments, consider applying these operational optimizations:<\/p>\n<h3>Tunnel Monitoring and Failover<\/h3>\n<p>Enable Tunnel Monitoring on critical IPSec connections. Tunnel Monitoring sends periodic ICMP pings across the tunnel to an IP address at the far end (e.g., the remote tunnel IP address). If the remote host fails to reply, the firewall marks the tunnel down. This action can automatically clear static routes or initiate a path failover to a backup link.<\/p>\n<p>To enable this, navigate to <strong>Network &gt; IPSec Tunnels &gt; [Tunnel Name] &gt; Auto Key &gt; Tunnel Monitor<\/strong>, specify the destination monitor IP (e.g., <code>10.255.255.2<\/code>), and assign a failover profile.<\/p>\n<h3>Cryptography Standard Guidelines<\/h3>\n<p>Avoid legacy algorithms that are cryptographically vulnerable or computationally inefficient on modern platforms. Avoid using MD5, SHA-1, DES, 3DES, or Diffie-Hellman Groups 1, 2, and 5. Standardize on modern proposals such as AES-256-GCM or AES-128-GCM combined with DH Group 19 (ECDH 256-bit) or Group 20 for efficient hardware acceleration and security.<\/p>\n<h3>Dynamic Routing over IPsec<\/h3>\n<p>In environments with multiple branch offices or dynamic path requirements, consider running BGP across the tunnel interfaces instead of relying entirely on static routes. Using dynamic routing simplifies policy updates, offers fast path convergence, and automates failover when redundant IPsec tunnels are deployed.<\/p>\n<h2>Related Palo Alto Guides<\/h2>\n<ul>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-ipsec-vpn-troubleshooting\/\">Palo Alto IPsec VPN troubleshooting<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/\">Palo Alto GlobalProtect<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-log-forwarding-syslog-siem\/\">Palo Alto Syslog\/SIEM<\/a><\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>Configuring a <strong>Palo Alto site to site IPsec VPN<\/strong> requires setting up a logical tunnel interface, matching Phase 1 and Phase 2 crypto profiles, binding these components within an IPsec tunnel configuration, and defining clear routing and security policies. Isolating VPN traffic into a dedicated security zone gives you precise visibility and granular access control over corporate networks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn Palo Alto site to site IPsec VPN with a practical real-life example, step-by-step configuration, verification and troubleshooting.<\/p>","protected":false},"author":2,"featured_media":733,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[5],"tags":[29,73,32,115,31,116],"class_list":["post-734","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-palo","tag-firewall-tutorial","tag-intermediate","tag-palo-alto-networks","tag-palo-alto-site-to-site-ipsec-vpn","tag-pan-os","tag-vpn"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Palo Alto Site-to-Site IPsec VPN Configuration Guide<\/title>\n<meta name=\"description\" content=\"Configure a Palo Alto site-to-site IPsec VPN with a branch office example, including IKE, IPsec, tunnel interfaces, routing, policy and verification.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Palo Alto Site-to-Site IPsec VPN Configuration with a Branch Office Example\" \/>\n<meta property=\"og:description\" content=\"Configure a Palo Alto site-to-site IPsec VPN with a branch office example, including IKE, IPsec, tunnel interfaces, routing, policy and verification.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-26T02:32:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T09:25:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"Palo Alto Site-to-Site IPsec VPN Configuration with a Branch Office Example\",\"datePublished\":\"2026-08-26T02:32:49+00:00\",\"dateModified\":\"2026-09-30T09:25:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/\"},\"wordCount\":2022,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png\",\"keywords\":[\"Firewall Tutorial\",\"Intermediate\",\"Palo Alto Networks\",\"Palo Alto site to site IPsec VPN\",\"PAN-OS\",\"VPN\"],\"articleSection\":[\"Palo Alto\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/\",\"name\":\"Palo Alto Site-to-Site IPsec VPN Configuration Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png\",\"datePublished\":\"2026-08-26T02:32:49+00:00\",\"dateModified\":\"2026-09-30T09:25:17+00:00\",\"description\":\"Configure a Palo Alto site-to-site IPsec VPN with a branch office example, including IKE, IPsec, tunnel interfaces, routing, policy and verification.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png\",\"width\":1600,\"height\":900,\"caption\":\"Palo Alto Site-to-Site IPsec VPN Configuration with a Branch Office Example\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-site-to-site-ipsec-vpn\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Palo Alto Site-to-Site IPsec VPN Configuration with a Branch Office Example\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Palo Alto Site-to-Site IPsec VPN Configuration Guide","description":"Configure a Palo Alto site-to-site IPsec VPN with a branch office example, including IKE, IPsec, tunnel interfaces, routing, policy and verification.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/","og_locale":"en_US","og_type":"article","og_title":"Palo Alto Site-to-Site IPsec VPN Configuration with a Branch Office Example","og_description":"Configure a Palo Alto site-to-site IPsec VPN with a branch office example, including IKE, IPsec, tunnel interfaces, routing, policy and verification.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/","og_site_name":"NetworkFix","article_published_time":"2026-08-26T02:32:49+00:00","article_modified_time":"2026-09-30T09:25:17+00:00","og_image":[{"width":1600,"height":900,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png","type":"image\/png"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"Palo Alto Site-to-Site IPsec VPN Configuration with a Branch Office Example","datePublished":"2026-08-26T02:32:49+00:00","dateModified":"2026-09-30T09:25:17+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/"},"wordCount":2022,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png","keywords":["Firewall Tutorial","Intermediate","Palo Alto Networks","Palo Alto site to site IPsec VPN","PAN-OS","VPN"],"articleSection":["Palo Alto"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/","url":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/","name":"Palo Alto Site-to-Site IPsec VPN Configuration Guide","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png","datePublished":"2026-08-26T02:32:49+00:00","dateModified":"2026-09-30T09:25:17+00:00","description":"Configure a Palo Alto site-to-site IPsec VPN with a branch office example, including IKE, IPsec, tunnel interfaces, routing, policy and verification.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/palo-alto-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.png","width":1600,"height":900,"caption":"Palo Alto Site-to-Site IPsec VPN Configuration with a Branch Office Example"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-site-to-site-ipsec-vpn\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"Palo Alto Site-to-Site IPsec VPN Configuration with a Branch Office Example"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/734","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=734"}],"version-history":[{"count":2,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/734\/revisions"}],"predecessor-version":[{"id":1628,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/734\/revisions\/1628"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/733"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=734"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=734"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=734"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}