Skip to content

非公式本サイトは非公式の日本語ドキュメントであり、Cloudflare 公式サイトではありません。最新情報はdevelopers.cloudflare.comをご確認ください。

Palo Alto Networks NGFW

最終更新 Markdown で表示Agent セットアップ

概要

このガイドでは、Palo Alto Networks Next-Generation Firewall(NGFW)を設定し、Cloudflare WAN への IPsec VPN トンネルを確立する手順を説明します。記載のファームウェアリリースで Cloudflare が検証済みです。対象は、Palo Alto Networks NGFW の管理に慣れており、有効な Cloudflare WAN サブスクリプションがあるネットワークエンジニアです。

テスト環境

項目
ベンダー Palo Alto Networks
モデル PA-440
リリース PAN-OS 11.2.8
テスト日 2026年3月

IKE/IPsec 暗号と関連設定

項目
トラフィック選択条件 Route-Based VPN
ルーティング Static
冗長トンネル Yes
トンネル負荷分散 Active/Active
IKE Version IKEv2
認証 Pre-Shared Key
アンチリプレイ保護 Disabled
NAT Traversal (NAT-T) 未テスト
NAT-T ポート 該当なし
Phase 1 - DH-Group Group 20
Phase 1 - Encryption AES-256-CBC
Phase 1 - Authentication/Integrity SHA-256
Phase 2 - DH-Group Group 20
Phase 2 - Transport ESP
Phase 2 - Encryption AES-256-CBC

Cloudflare WAN と Palo Alto Networks NGFW の設定

  • 手順を進めるときは、オブジェクト名と IP アドレスを、ご自身の環境に合わせて更新してください。
  • 実際の命名規則とネットワーク構成に合わせると、本番環境で正しく動作します。
  • 下記の例は検索と置換で解析し、名前とアドレスを更新して、一貫性を保ってください。

Cloudflare WAN - トンネル 01 / 02

属性 値 / アドレス
Name (required) CF_WAN_TUN_01
Description ---
IPv4 Interface Address (required) 169.254.250.0/31
IPv6 Interface Address ---
Customer Endpoint 203.0.113.100
Cloudflare Endpoint 162.159.135.1
Tunnel health checks True
Rate Medium
Type Request
Direction Bidirectional
Target Default
--- ---
Turn on replay protection False
Automatic return routing True
  • IKE Identity と Pre-shared Key(トンネル作成後に取得):
属性 値 / アドレス
FQDN ID bf6c493d03<REDACTED>.ipsec.cloudflare.com
Pre-shared key Cloudflare-WAN-T1-PSK-1234!

Cloudflare WAN - トンネル 02 / 02

属性 値 / アドレス
Name (required) CF_WAN_TUN_02
Description ---
IPv4 Interface Address (required) 169.254.250.2/31
IPv6 Interface Address ---
Customer Endpoint 203.0.113.100
Cloudflare Endpoint 172.64.135.1
Tunnel health checks True
Rate Medium
Type Request
Direction Bidirectional
Target Default
--- ---
Turn on replay protection False
Automatic return routing True
  • IKE Identity と Pre-shared Key(トンネル作成後に取得):
属性 値 / アドレス
FQDN ID 0287844e9d<REDACTED>.ipsec.cloudflare.com
Pre-shared key Cloudflare-WAN-T2-PSK-1234!

顧客構内設備 - Palo Alto Networks

WAN Interface トンネル 01 / 02 トンネル 02 / 02
WAN Interface ethernet1/1 ethernet1/1
IP Address 203.0.113.100/24 203.0.113.100/24
Security Zone untrust untrust
Virtual Tunnel Interface (VTI) トンネル 01 / 02 トンネル 02 / 02
Tunnel interface tunnel.1 tunnel.2
IP Address 169.254.250.1/31 169.254.250.3/31
Security Zone cloudflare cloudflare
LAN Interface トンネル 01 / 02 トンネル 02 / 02
LAN Interface ethernet1/2 ethernet1/2
IP Address 192.168.125.1/24 192.168.125.1/24
Security Zone trust trust

Palo Alto Networks NGFW のオブジェクト名

役割 ラベル / 名前 アドレス
CPE Security Zone - Trust Zone trust
CPE Security Zone - Untrust Zone untrust
CPE Security Zone - Cloudflare WAN Zone cloudflare
CPE IKE Crypto Profile Name IKE Crypto Profile ike-aes256cbc-sha256-dh20
CPE IPsec Crypto Profile Name IPsec Crypto Profile ipsec-aes256cbc-sha256-dh20

前提

このガイドは、次が当てはまることを前提とします。

  • Cloudflare ダッシュボードで IPsec トンネル静的ルート をすでに設定している
  • Cloudflare ダッシュボードで Local Identifier(FQDN / ホスト名)を取得し、各 IPsec トンネルの Pre-Shared Key を生成している
  • MSS clamping の重要性を理解し、Cloudflare WAN の IPsec トンネルを通過するトラフィックフローに合わせて調整する
  • 高可用性 / 耐障害性のある Palo Alto Networks NGFW 構成は可能ですが、対象外です。

手順の概要

  • 次の Address Object を作成します。
    • Virtual Tunnel Interface(2 つ)- ローカル(/31 ネットマスク)とリモート(/32 ネットマスク)
    • Cloudflare Anycast IP(2 つ)
    • ローカルサブネット
    • リモートの Cloudflare WAN サブネット
  • Interface Management Profile を作成する
  • Security Zone を作成する(推奨)
  • Tunnel インターフェースを定義する
  • IKE および IPsec Crypto Profile を定義する
  • Cloudflare の 2 本の IPsec トンネルそれぞれに、IKE Gateway を 1 つずつ追加する
  • Cloudflare の 2 本の IPsec トンネルそれぞれに、IPsec Tunnel を 1 つずつ追加する
  • Cloudflare WAN との間のトラフィックを許可する Security ポリシーを定義する
  • IPsec トンネル経由でトラフィックを選択的にルーティングする Policy-Based Forwarding ルールを定義する

Palo Alto Networks NGFW の設定

可能な箇所では、Command-Line Interface(CLI)と Web UI の両方の例を示します。

オブジェクトとアドレス

以降の設定全体で使う属性 / 値の組を表す Address Object を定義します。

CLI

set address cf_wan_anycast_01 ip-netmask 162.159.135.1
set address cf_wan_anycast_02 ip-netmask 172.64.135.1
set address cf-wan-ipsec-vti-01-local ip-netmask 169.254.250.1/31
set address cf-wan-ipsec-vti-02-local ip-netmask 169.254.250.3/31
set address cf-wan-ipsec-vti-01-remote ip-netmask 169.254.250.0/32
set address cf-wan-ipsec-vti-02-remote ip-netmask 169.254.250.2/32
set address lan-net-192-168-125-0--24 ip-netmask 192.168.125.0/24
set address internet_203-0-113-100--24 ip-netmask 203.0.113.100/24

Web UI

  1. Objects > Addresses を開きます。
  2. Add を選択します。
  3. 次のネットワークに対して、タイプ IP Netmask のオブジェクトを作成します。
    • cf_wan_anycast_01 - 162.159.135.1(または 162.159.135.1/32)を指定します
    • cf_wan_anycast_02 - 172.64.135.1(または 172.64.135.1/32)を指定します
    • cf-wan-ipsec-vti-01-local - 169.254.250.1/31 を指定します
    • cf-wan-ipsec-vti-02-local - 169.254.250.3/31 を指定します
    • cf-wan-ipsec-vti-01-remote - 169.254.250.0(または 169.254.250.0/32)を指定します
    • cf-wan-ipsec-vti-02-remote - 169.254.250.2(または 169.254.250.2/32)を指定します

Interface Management Profile

対象のネットワークインターフェースが ping(ICMP Echo Request)に応答できるようにします。Cloudflare WAN の Tunnel Health Check が Virtual Tunnel Interface 経由で到達性を確認するために必要です。

CLI

set network profiles interface-management-profile allow_ping ping yes

Web UI

  1. Network > Network Profiles > Interface Mgmt を開きます。
  2. Add を選択します。
  3. Name: allow_ping
  4. Network Services の下で Ping を選択します。
  5. OK を選択します。

Virtual Tunnel Interface(VTI)

Cloudflare の 2 本の IPsec トンネルそれぞれに、トンネルインターフェースを 1 つずつ追加します。

注: CLI と Web UI では手順が異なることがあります。

CLI - トンネルインターフェースを追加する

先に設定した Address Object と Interface Management Profile を使って、トンネルインターフェースを 2 つ追加します。

set network interface tunnel units tunnel.1 ip cf-wan-ipsec-vti-01-local
set network interface tunnel units tunnel.1 interface-management-profile allow_ping

set network interface tunnel units tunnel.2 ip cf-wan-ipsec-vti-02-local
set network interface tunnel units tunnel.2 interface-management-profile allow_ping

CLI - トンネルインターフェースを Virtual Router に割り当てる

両方の tunnel インターフェースをデフォルトの Virtual Router に割り当てます。

set network virtual-router default interface tunnel.1
set network virtual-router default interface tunnel.2

CLI - トンネルインターフェースを Security Zone に割り当てる

cloudflare セキュリティゾーンがまだない場合は作成し、tunnel.1tunnel.2 インターフェースをバインドします。

set zone cloudflare network layer3  [ tunnel.1 tunnel.2 ]

Web UI - トンネルインターフェースを追加する

  1. Network > Interfaces > Tunnel を開きます。
  2. Add を選択します。
  3. "Interface Name" の右の欄に 1 を入力します。
  4. Config Tab > Virtual Router: default
  5. Config Tab > Security Zone: cloudflare(セキュリティポリシーに応じて trust に割り当てても構いません)
  6. IPv4 Tab > ドロップダウンから cf-wan-ipsec-vti-01-local を選択します。
  7. Advanced tab > Management Profile: allow_ping
  8. OK を選択します。

トンネル 2 でも手順を繰り返します。

  1. Network > Interfaces > Tunnel を開きます。
  2. Add を選択します。
  3. "Interface Name" の右の欄に 2 を入力します。
  4. Config Tab > Virtual Router: default
  5. Config Tab > Security Zone: cloudflare(セキュリティポリシーに応じて trust に割り当てても構いません)
  6. IPv4 Tab > ドロップダウンから cf-wan-ipsec-vti-02-local を選択します。
  7. Advanced tab > Management Profile: allow_ping
  8. OK を選択します。

IPsec トンネルの設定

Phase 1 - IKE

暗号設定を定義する

次の設定で IKE Crypto Profile を定義します。

属性
hash sha256
dh-group group20
encryption aes-256-cbc
lifetime hours 8
CLI
set network ike crypto-profiles ike-crypto-profiles ike-aes256cbc-sha256-dh20 hash sha256
set network ike crypto-profiles ike-crypto-profiles ike-aes256cbc-sha256-dh20 dh-group group20
set network ike crypto-profiles ike-crypto-profiles ike-aes256cbc-sha256-dh20 encryption aes-256-cbc
set network ike crypto-profiles ike-crypto-profiles ike-aes256cbc-sha256-dh20 lifetime hours 8
Web UI
  1. Network > Network Profiles > IKE Crypto を開きます。
  2. Add を選択します。
  3. Name: ike-aes256cbc-sha256-dh20
  4. DH Group: group20
  5. Authentication: sha256
  6. Encryption: aes-256-cbc
  7. Timers - Key Lifetime: 8 hours
IKE Gateway オブジェクトを定義する

各トンネルには固有の Pre-Shared Key と Local ID(FQDN / ホスト名)があります。Cloudflare ダッシュボードから値を取得して更新してください。

CLI
set network ike gateway cf-wan-ike-gw-01 authentication pre-shared-key key "Cloudflare-WAN-T1-PSK-1234!"
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 pq-ppk enabled no
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 pq-ppk negotiation-mode preferred
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 pq-kem enable no
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 pq-kem block-vulnerable-cipher yes
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 ikev2-fragment enable no
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 dpd enable yes
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 ike-crypto-profile ike-aes256cbc-sha256-dh20
set network ike gateway cf-wan-ike-gw-01 protocol ikev1 dpd enable yes
set network ike gateway cf-wan-ike-gw-01 protocol version ikev2
set network ike gateway cf-wan-ike-gw-01 local-address interface ethernet1/1 ip internet_203-0-113-100--24
set network ike gateway cf-wan-ike-gw-01 protocol-common nat-traversal enable no
set network ike gateway cf-wan-ike-gw-01 protocol-common fragmentation enable no
set network ike gateway cf-wan-ike-gw-01 peer-address ip cf_wan_anycast_01
set network ike gateway cf-wan-ike-gw-01 local-id type fqdn id "bf6c493d03<REDACTED>.ipsec.cloudflare.com"

set network ike gateway cf-wan-ike-gw-02 authentication pre-shared-key key "Cloudflare-WAN-T2-PSK-1234!"
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 pq-ppk enabled no
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 pq-ppk negotiation-mode preferred
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 pq-kem enable no
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 pq-kem block-vulnerable-cipher yes
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 ikev2-fragment enable no
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 dpd enable yes
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 ike-crypto-profile ike-aes256cbc-sha256-dh20
set network ike gateway cf-wan-ike-gw-02 protocol ikev1 dpd enable yes
set network ike gateway cf-wan-ike-gw-02 protocol version ikev2
set network ike gateway cf-wan-ike-gw-02 local-address interface ethernet1/1 ip internet_203-0-113-100--24
set network ike gateway cf-wan-ike-gw-02 protocol-common nat-traversal enable no
set network ike gateway cf-wan-ike-gw-02 protocol-common fragmentation enable no
set network ike gateway cf-wan-ike-gw-02 peer-address ip cf_wan_anycast_02
set network ike gateway cf-wan-ike-gw-02 local-id type fqdn id "0287844e9d<REDACTED>.ipsec.cloudflare.com"
Web UI
  1. Network > Network Profiles > IKE Gateways を開きます。
  2. Add を選択します。
  3. Name: cf-wan-ike-gw-01
  4. Version: IKEv2 only mode
  5. Address Type: IPv4
  6. Interface: ethernet1/1
  7. Local IP Address: internet_203-0-113-100--24
  8. Peer IP Address Type: IP
  9. Authentication: Pre-Shared Key
  10. Pre-shared key を入力し、値を確認します(Cloudflare ダッシュボードから取得します)。
  11. Local Identification: FQDN (hostname)(Cloudflare ダッシュボードからトンネル 1 の FQDN 値を取得します)。
  12. Advanced Options tab > General > IKE Crypto Profile: ike-aes256cbc-sha256-dh20
  13. OK を選択します。

トンネル 2 でも手順を繰り返します。

  1. Network > Network Profiles > IKE Gateways を開きます。
  2. Add を選択します。
  3. Name: cf-wan-ike-gw-02
  4. Version: IKEv2 only mode
  5. Address Type: IPv4
  6. Interface: ethernet1/1
  7. Local IP Address: internet_203-0-113-100--24
  8. Peer IP Address Type: IP
  9. Authentication: Pre-Shared Key
  10. Pre-shared key を入力し、値を確認します(Cloudflare ダッシュボードから取得します)。
  11. Local Identification: FQDN (hostname)(Cloudflare ダッシュボードからトンネル 2 の FQDN 値を取得します)。
  12. Advanced Options tab > General > IKE Crypto Profile: ike-aes256cbc-sha256-dh20
  13. OK を選択します。

IPsec(Phase 2)

暗号設定を定義する

次の設定で IPsec Crypto Profile を定義します。

属性
dh-group group20
esp encryption aes-256-cbc
esp authentication sha256
lifetime hours 8
CLI
set network ike crypto-profiles ipsec-crypto-profiles ipsec-aes256cbc-sha256-dh20 esp authentication sha256
set network ike crypto-profiles ipsec-crypto-profiles ipsec-aes256cbc-sha256-dh20 esp encryption aes-256-cbc
set network ike crypto-profiles ipsec-crypto-profiles ipsec-aes256cbc-sha256-dh20 lifetime hours 8
set network ike crypto-profiles ipsec-crypto-profiles ipsec-aes256cbc-sha256-dh20 dh-group group20
Web UI
  1. Network > Network Profiles > IPsec Crypto を開きます。
  2. Add を選択します。
  3. Name: ipsec-aes256cbc-sha256-dh20
  4. IPsec Protocol: ESP
  5. Encryption: aes-256-cbc
  6. Authentication: sha256
  7. DH Group: group20
  8. Lifetime (Hours): 8
IPsec トンネルオブジェクトを定義する
CLI - IPsec トンネルを定義する
  • トンネル 1
set network tunnel ipsec cf-wan-ipsec-tun-01 auto-key ike-gateway cf-wan-ike-gw-01
set network tunnel ipsec cf-wan-ipsec-tun-01 auto-key ipsec-crypto-profile ipsec-aes256cbc-sha256-dh20
set network tunnel ipsec cf-wan-ipsec-tun-01 tunnel-monitor enable no
set network tunnel ipsec cf-wan-ipsec-tun-01 tunnel-interface tunnel.1
set network tunnel ipsec cf-wan-ipsec-tun-01 anti-replay no

set network tunnel ipsec cf-wan-ipsec-tun-02 auto-key ike-gateway cf-wan-ike-gw-02
set network tunnel ipsec cf-wan-ipsec-tun-02 auto-key ipsec-crypto-profile ipsec-aes256cbc-sha256-dh20
set network tunnel ipsec cf-wan-ipsec-tun-02 tunnel-monitor enable no
set network tunnel ipsec cf-wan-ipsec-tun-02 tunnel-interface tunnel.2
set network tunnel ipsec cf-wan-ipsec-tun-02 anti-replay no
Web UI - IPsec トンネルを定義する
  1. Network > IPsec Tunnels を開きます。
  2. Add を選択します。
  3. Name: cf-wan-ipsec-tun-01
  4. Tunnel interface: tunnel.1
  5. Type: Auto Key
  6. Address Type: IPv4
  7. IKE Gateway: cf-wan-ike-gw-01
  8. IPsec Crypto Profile: ipsec-aes256cbc-sha256-dh20
  9. Show Advanced Options - チェックボックスをオンにします。
  10. Enable Replay Protection のチェックを外します。
  11. IPsec Mode: Tunnel

トンネル 2 でも手順を繰り返します。

  1. Network > IPsec Tunnels を開きます。
  2. Add を選択します。
  3. Name: cf-wan-ipsec-tun-02
  4. Tunnel interface: tunnel.2
  5. Type: Auto Key
  6. Address Type: IPv4
  7. IKE Gateway: cf-wan-ike-gw-02
  8. IPsec Crypto Profile: ipsec-aes256cbc-sha256-dh20
  9. Show Advanced Options - チェックボックスをオンにします。
  10. Enable Replay Protection のチェックを外します。
  11. IPsec Mode: Tunnel

変更をコミットする

ここで一度止めて Commit を実行し、設定を適用するのがよいタイミングです。トンネル接続が確立されたことを確認できるはずです。

IPsec トンネルの確認

Web UI - IPsec トンネルの状態を表示する

  1. Network > IPsec Tunnels を開きます。

赤 / 緑のインジケーターの状態を確認します。リアルタイムの状態を見るには Tunnel InfoIKE Info を選択します。

Web UI - IPsec ログの詳細を表示する

  1. Monitor > Logs > System を開きます。
  2. 上部のフィルター / 検索ダイアログに次を追加します: ( subtype eq vpn )

IKE / IPsec の Phase 1 および Phase 2 の状態とエラーメッセージに関する有用な情報が得られます。

Security ポリシー

Palo Alto Networks NGFW は、同じゾーンを送信元および宛先とするトラフィック(ゾーン内トラフィック)を自動で許可します。tunnel.1tunnel.2 を別の Security Zone に入れた場合は、trust から cloudflare、および cloudflare から trust へのトラフィックを許可する明示的なファイアウォールルールが必要です。

CLI - trust から cloudflare への Security ポリシーを追加する

move rulebase security rules <RULE_NAME> [after|before|top|bottom] <RULE_NAME - Desired position> を使います。

set rulebase security rules trust-to-cloudflare to cloudflare
set rulebase security rules trust-to-cloudflare from trust
set rulebase security rules trust-to-cloudflare source any
set rulebase security rules trust-to-cloudflare destination any
set rulebase security rules trust-to-cloudflare application any
set rulebase security rules trust-to-cloudflare service application-default
set rulebase security rules trust-to-cloudflare action allow
set rulebase security rules trust-to-cloudflare log-start no
set rulebase security rules trust-to-cloudflare log-end yes
set rulebase security rules trust-to-cloudflare rule-type universal

Web UI - trust から cloudflare への Security ポリシーを追加する

  1. Policies > Security を開きます。
  2. Add を選択します。
  3. General > Name: trust-to-cloudflare
  4. Rule Type: universal (default) または interzone
  5. Source > Source Zone: trust
  6. Destination > Destination Zone: cloudflare
  7. Application > Any
  8. Service/URL Category > application-default
  9. Actions > Action setting: Allow
  10. Log Setting: Log at Session End

CLI - cloudflare から trust への Security ポリシーを追加する

move rulebase security rules <RULE_NAME> [after|before|top|bottom] <RULE_NAME - Desired position> を使います。

set rulebase security rules cloudflare-to-trust to trust
set rulebase security rules cloudflare-to-trust from cloudflare
set rulebase security rules cloudflare-to-trust source any
set rulebase security rules cloudflare-to-trust destination any
set rulebase security rules cloudflare-to-trust application any
set rulebase security rules cloudflare-to-trust service application-default
set rulebase security rules cloudflare-to-trust action allow
set rulebase security rules cloudflare-to-trust log-start no
set rulebase security rules cloudflare-to-trust log-end yes
set rulebase security rules cloudflare-to-trust rule-type universal

Web UI - cloudflare から trust への Security ポリシーを追加する

  1. Policies > Security を開きます。
  2. Add を選択します。
  3. General > Name: cloudflare-to-trust
  4. Rule Type: universal (default) または interzone
  5. Source > Source Zone: cloudflare
  6. Destination > Destination Zone: trust
  7. Application > Any
  8. Service/URL Category > application-default
  9. Actions > Action setting: Allow
  10. Log Setting: Log at Session End

Policy Based Forwarding

Policy Based Forwarding(Policy-Based Routing とも呼ばれます)では、特定のトラフィックフローに追加の一致条件を適用し、Virtual Router 内で定義したルートを上書きできます。

別の Cloudflare WAN サイト宛てだけを Cloudflare WAN 経由にし、インターネット向けトラフィックはローカルの Internet breakout へ直接転送し続ける、という使い方ができます。

次の例では、NGFW 背後の LAN サブネット(192.168.125.0/24)からの すべての トラフィックを、Cloudflare WAN の IPsec トンネル経由でルーティングします。これで Cloudflare Secure Web Gateway の機能を使えます。

宛先の一致条件にサブネットを追加するだけで、特定の宛先へトラフィックをルーティングできます。

Policy Based Forwarding で処理するトラフィックフローは、NAT ポリシーから除外してください。インターネット向けトラフィックへの NAT は、ローカルデバイス上のポリシーなしで Cloudflare Gateway が適用します。

CLI - Policy Based Forwarding ルールを追加する

  • トンネル 1
set rulebase pbf rules cf-wan-to-internet-01 action forward nexthop ip-address cf-wan-ipsec-vti-01-remote
set rulebase pbf rules cf-wan-to-internet-01 action forward egress-interface tunnel.1
set rulebase pbf rules cf-wan-to-internet-01 from zone trust
set rulebase pbf rules cf-wan-to-internet-01 enforce-symmetric-return enabled no
set rulebase pbf rules cf-wan-to-internet-01 source lan-net-192-168-125-0--24
set rulebase pbf rules cf-wan-to-internet-01 destination any
set rulebase pbf rules cf-wan-to-internet-01 source-user any
set rulebase pbf rules cf-wan-to-internet-01 application any
set rulebase pbf rules cf-wan-to-internet-01 service any
  • トンネル 2
set rulebase pbf rules cf-wan-to-internet-02 action forward nexthop ip-address cf-wan-ipsec-vti-02-remote
set rulebase pbf rules cf-wan-to-internet-02 action forward egress-interface tunnel.2
set rulebase pbf rules cf-wan-to-internet-02 from zone trust
set rulebase pbf rules cf-wan-to-internet-02 enforce-symmetric-return enabled no
set rulebase pbf rules cf-wan-to-internet-02 source lan-net-192-168-125-0--24
set rulebase pbf rules cf-wan-to-internet-02 destination any
set rulebase pbf rules cf-wan-to-internet-02 source-user any
set rulebase pbf rules cf-wan-to-internet-02 application any
set rulebase pbf rules cf-wan-to-internet-02 service any

Web UI - Policy Based Forwarding ルールを追加する

  • トンネル 1:
  1. Policies > Policy Based Forwarding を開きます。
  2. Add を選択します。
  3. Name: cf-wan-to-internet-01
  4. Source Zone: trust
  5. Source Address: lan-net-192-168-125-0--24
  6. Destination/Application/Service - Any/Any/Any
  7. Forwarding > Action: Forward、Egress Interface: tunnel.1、Next Hop - IP Address: cf-wan-ipsec-vti-01-remote
  • トンネル 2:
  1. Policies > Policy Based Forwarding を開きます。
  2. Add を選択します。
  3. Name: cf-wan-to-internet-02
  4. Source Zone: trust
  5. Source Address: lan-net-192-168-125-0--24
  6. Destination/Application/Service - Any/Any/Any
  7. Forwarding > Action: Forward、Egress Interface: tunnel.2、Next Hop - IP Address: cf-wan-ipsec-vti-02-remote

変更をコミットしたあと、192.168.125.0/24 サブネット上のホストからトラフィックをテストし、Cloudflare WAN の IPsec トンネル経由で転送されることを確認します。

トラブルシューティング

よくある問題

  • IKE Phase 1 と IPsec Phase 2 が正常にネゴシエートされたかを、必ず確認します。ログで "no proposal chosen" を探します
  • Pre-Shared-Key および / または Local-Identity の値が正確で、正しいトンネルに割り当てられていることを確認します
  • ping を使い、CPE 側と Cloudflare 側の VTI 間の到達性を確認します
    • トンネル 1: CPE VTI から Cloudflare VTI: ping source 169.254.250.1 169.254.250.0
    • トンネル 2: CPE VTI から Cloudflare VTI: ping source 169.254.250.3 169.254.250.2

クイックリファレンス

IKE と IPsec のセキュリティアソシエーションを表示する

show コマンドで Phase 1 と Phase 2 のセキュリティアソシエーションを表示します。

admin@panfw01> show vpn ike-sa

IKEv2 SAs
Gateway ID      Peer-Address       Gateway Name       Role SN    Algorithm             Established     Expiration      Xt Child  ST
----------      ------------       ------------       ---- --    ---------             -----------     ----------      -- -----  --
1               162.159.135.1      cf-wan-ike-gw-01   Init 46    PSK/DH14/A256/SHA256  Mar.22 23:14:24 Mar.23 07:14:24 0  1      Established
2               172.64.135.1       cf-wan-ike-gw-02   Init 45    PSK/DH14/A256/SHA256  Mar.22 23:05:02 Mar.23 07:05:02 0  1      Established
IKEv2 IPSec Child SAs
Gateway Name                   TnID     Tunnel                     ID       Parent   Role SPI(in)  SPI(out) MsgID    ST              
------------                   ----     ------                     --       ------   ---- -------  -------- -----    --              
cf-wan-ike-gw-01               1        cf-wan-ipsec-tun-01        452741   97       Init B7D055D3 4CB26B43 00000001 Mature           
cf-wan-ike-gw-02               2        cf-wan-ipsec-tun-02        452742   98       Init B4629A07 165D416C 00000001 Mature           

Show IKEv2 SA: Total 2 gateways found. 2 ike sa found.

IKE と IPsec のセキュリティアソシエーションを手動で開始する

test コマンドで Phase 1 と Phase 2 のセキュリティアソシエーションを強制します。

admin@panfw01> test vpn ike-sa gateway cf-wan-ike-gw-01 

Start time: Mar.30 21:23:23
Initiate 1 IKE SA.

admin@panfw01> test vpn ike-sa gateway cf-wan-ike-gw-02

Start time: Mar.30 21:23:24
Initiate 1 IKE SA.
admin@panfw01> test vpn ipsec-sa tunnel cf-wan-ipsec-tun-01 

Start time: Mar.30 21:26:50
Initiate 1 IPSec SA for tunnel cf-wan-ipsec-tun-01.

admin@panfw01> test vpn ipsec-sa tunnel cf-wan-ipsec-tun-02

Start time: Mar.30 21:26:52
Initiate 1 IPSec SA for tunnel cf-wan-ipsec-tun-02.

Palo Alto Networks のドキュメント

Palo Alto Networks Knowledge Base

役に立ちましたか?