このガイドでは、Palo Alto Networks Next-Generation Firewall(NGFW)を設定し、Cloudflare WAN への IPsec VPN トンネルを確立する手順を説明します。記載のファームウェアリリースで Cloudflare が検証済みです。対象は、Palo Alto Networks NGFW の管理に慣れており、有効な Cloudflare WAN サブスクリプションがあるネットワークエンジニアです。
| 項目 | 値 |
|---|---|
| ベンダー | Palo Alto Networks |
| モデル | PA-440 |
| リリース | PAN-OS 11.2.8 |
| テスト日 | 2026年3月 |
| 項目 | 値 |
|---|---|
| トラフィック選択条件 | Route-Based VPN |
| ルーティング | Static |
| 冗長トンネル | Yes |
| トンネル負荷分散 | Active/Active |
| IKE Version | IKEv2 |
| 認証 | Pre-Shared Key |
| アンチリプレイ保護 | Disabled |
| NAT Traversal (NAT-T) | 未テスト |
| NAT-T ポート | 該当なし |
| Phase 1 - DH-Group | Group 20 |
| Phase 1 - Encryption | AES-256-CBC |
| Phase 1 - Authentication/Integrity | SHA-256 |
| Phase 2 - DH-Group | Group 20 |
| Phase 2 - Transport | ESP |
| Phase 2 - Encryption | AES-256-CBC |
- 手順を進めるときは、オブジェクト名と IP アドレスを、ご自身の環境に合わせて更新してください。
- 実際の命名規則とネットワーク構成に合わせると、本番環境で正しく動作します。
- 下記の例は検索と置換で解析し、名前とアドレスを更新して、一貫性を保ってください。
| 属性 | 値 / アドレス |
|---|---|
| Name (required) | CF_WAN_TUN_01 |
| Description | --- |
| IPv4 Interface Address (required) | 169.254.250.0/31 |
| IPv6 Interface Address | --- |
| Customer Endpoint | 203.0.113.100 |
| Cloudflare Endpoint | 162.159.135.1 |
| Tunnel health checks | True |
| Rate | Medium |
| Type | Request |
| Direction | Bidirectional |
| Target | Default |
| --- | --- |
| Turn on replay protection | False |
| Automatic return routing | True |
- IKE Identity と Pre-shared Key(トンネル作成後に取得):
| 属性 | 値 / アドレス |
|---|---|
| FQDN ID | bf6c493d03<REDACTED>.ipsec.cloudflare.com |
| Pre-shared key | Cloudflare-WAN-T1-PSK-1234! |
| 属性 | 値 / アドレス |
|---|---|
| Name (required) | CF_WAN_TUN_02 |
| Description | --- |
| IPv4 Interface Address (required) | 169.254.250.2/31 |
| IPv6 Interface Address | --- |
| Customer Endpoint | 203.0.113.100 |
| Cloudflare Endpoint | 172.64.135.1 |
| Tunnel health checks | True |
| Rate | Medium |
| Type | Request |
| Direction | Bidirectional |
| Target | Default |
| --- | --- |
| Turn on replay protection | False |
| Automatic return routing | True |
- IKE Identity と Pre-shared Key(トンネル作成後に取得):
| 属性 | 値 / アドレス |
|---|---|
| FQDN ID | 0287844e9d<REDACTED>.ipsec.cloudflare.com |
| Pre-shared key | Cloudflare-WAN-T2-PSK-1234! |
| WAN Interface | トンネル 01 / 02 | トンネル 02 / 02 |
|---|---|---|
| WAN Interface | ethernet1/1 | ethernet1/1 |
| IP Address | 203.0.113.100/24 | 203.0.113.100/24 |
| Security Zone | untrust | untrust |
| Virtual Tunnel Interface (VTI) | トンネル 01 / 02 | トンネル 02 / 02 |
|---|---|---|
| Tunnel interface | tunnel.1 | tunnel.2 |
| IP Address | 169.254.250.1/31 | 169.254.250.3/31 |
| Security Zone | cloudflare | cloudflare |
| LAN Interface | トンネル 01 / 02 | トンネル 02 / 02 |
|---|---|---|
| LAN Interface | ethernet1/2 | ethernet1/2 |
| IP Address | 192.168.125.1/24 | 192.168.125.1/24 |
| Security Zone | trust | trust |
| 役割 | ラベル / 名前 | アドレス |
|---|---|---|
| CPE Security Zone - Trust | Zone | trust |
| CPE Security Zone - Untrust | Zone | untrust |
| CPE Security Zone - Cloudflare WAN | Zone | cloudflare |
| CPE IKE Crypto Profile Name | IKE Crypto Profile | ike-aes256cbc-sha256-dh20 |
| CPE IPsec Crypto Profile Name | IPsec Crypto Profile | ipsec-aes256cbc-sha256-dh20 |
このガイドは、次が当てはまることを前提とします。
- Cloudflare ダッシュボードで IPsec トンネル と 静的ルート をすでに設定している
- Cloudflare ダッシュボードで Local Identifier(FQDN / ホスト名)を取得し、各 IPsec トンネルの Pre-Shared Key を生成している
- MSS clamping の重要性を理解し、Cloudflare WAN の IPsec トンネルを通過するトラフィックフローに合わせて調整する
- 高可用性 / 耐障害性のある Palo Alto Networks NGFW 構成は可能ですが、対象外です。
- 次の Address Object を作成します。
- Virtual Tunnel Interface(2 つ)- ローカル(
/31ネットマスク)とリモート(/32ネットマスク) - Cloudflare Anycast IP(2 つ)
- ローカルサブネット
- リモートの Cloudflare WAN サブネット
- Virtual Tunnel Interface(2 つ)- ローカル(
- Interface Management Profile を作成する
- Security Zone を作成する(推奨)
- Tunnel インターフェースを定義する
- IKE および IPsec Crypto Profile を定義する
- Cloudflare の 2 本の IPsec トンネルそれぞれに、IKE Gateway を 1 つずつ追加する
- Cloudflare の 2 本の IPsec トンネルそれぞれに、IPsec Tunnel を 1 つずつ追加する
- Cloudflare WAN との間のトラフィックを許可する Security ポリシーを定義する
- IPsec トンネル経由でトラフィックを選択的にルーティングする Policy-Based Forwarding ルールを定義する
可能な箇所では、Command-Line Interface(CLI)と Web UI の両方の例を示します。
以降の設定全体で使う属性 / 値の組を表す Address Object を定義します。
set address cf_wan_anycast_01 ip-netmask 162.159.135.1
set address cf_wan_anycast_02 ip-netmask 172.64.135.1
set address cf-wan-ipsec-vti-01-local ip-netmask 169.254.250.1/31
set address cf-wan-ipsec-vti-02-local ip-netmask 169.254.250.3/31
set address cf-wan-ipsec-vti-01-remote ip-netmask 169.254.250.0/32
set address cf-wan-ipsec-vti-02-remote ip-netmask 169.254.250.2/32
set address lan-net-192-168-125-0--24 ip-netmask 192.168.125.0/24
set address internet_203-0-113-100--24 ip-netmask 203.0.113.100/24- Objects > Addresses を開きます。
- Add を選択します。
- 次のネットワークに対して、タイプ
IP Netmaskのオブジェクトを作成します。cf_wan_anycast_01- 162.159.135.1(または 162.159.135.1/32)を指定しますcf_wan_anycast_02- 172.64.135.1(または 172.64.135.1/32)を指定しますcf-wan-ipsec-vti-01-local- 169.254.250.1/31 を指定しますcf-wan-ipsec-vti-02-local- 169.254.250.3/31 を指定しますcf-wan-ipsec-vti-01-remote- 169.254.250.0(または 169.254.250.0/32)を指定しますcf-wan-ipsec-vti-02-remote- 169.254.250.2(または 169.254.250.2/32)を指定します
対象のネットワークインターフェースが ping(ICMP Echo Request)に応答できるようにします。Cloudflare WAN の Tunnel Health Check が Virtual Tunnel Interface 経由で到達性を確認するために必要です。
set network profiles interface-management-profile allow_ping ping yes- Network > Network Profiles > Interface Mgmt を開きます。
- Add を選択します。
- Name:
allow_ping Network Servicesの下でPingを選択します。- OK を選択します。
Cloudflare の 2 本の IPsec トンネルそれぞれに、トンネルインターフェースを 1 つずつ追加します。
注: CLI と Web UI では手順が異なることがあります。
先に設定した Address Object と Interface Management Profile を使って、トンネルインターフェースを 2 つ追加します。
set network interface tunnel units tunnel.1 ip cf-wan-ipsec-vti-01-local
set network interface tunnel units tunnel.1 interface-management-profile allow_ping
set network interface tunnel units tunnel.2 ip cf-wan-ipsec-vti-02-local
set network interface tunnel units tunnel.2 interface-management-profile allow_ping両方の tunnel インターフェースをデフォルトの Virtual Router に割り当てます。
set network virtual-router default interface tunnel.1
set network virtual-router default interface tunnel.2cloudflare セキュリティゾーンがまだない場合は作成し、tunnel.1 と tunnel.2 インターフェースをバインドします。
set zone cloudflare network layer3 [ tunnel.1 tunnel.2 ]- Network > Interfaces > Tunnel を開きます。
- Add を選択します。
- "Interface Name" の右の欄に 1 を入力します。
- Config Tab > Virtual Router:
default - Config Tab > Security Zone:
cloudflare(セキュリティポリシーに応じてtrustに割り当てても構いません) - IPv4 Tab > ドロップダウンから
cf-wan-ipsec-vti-01-localを選択します。 - Advanced tab > Management Profile:
allow_ping - OK を選択します。
トンネル 2 でも手順を繰り返します。
- Network > Interfaces > Tunnel を開きます。
- Add を選択します。
- "Interface Name" の右の欄に 2 を入力します。
- Config Tab > Virtual Router:
default - Config Tab > Security Zone:
cloudflare(セキュリティポリシーに応じてtrustに割り当てても構いません) - IPv4 Tab > ドロップダウンから
cf-wan-ipsec-vti-02-localを選択します。 - Advanced tab > Management Profile:
allow_ping - OK を選択します。
次の設定で IKE Crypto Profile を定義します。
| 属性 | 値 |
|---|---|
| hash | sha256 |
| dh-group | group20 |
| encryption | aes-256-cbc |
| lifetime hours | 8 |
set network ike crypto-profiles ike-crypto-profiles ike-aes256cbc-sha256-dh20 hash sha256
set network ike crypto-profiles ike-crypto-profiles ike-aes256cbc-sha256-dh20 dh-group group20
set network ike crypto-profiles ike-crypto-profiles ike-aes256cbc-sha256-dh20 encryption aes-256-cbc
set network ike crypto-profiles ike-crypto-profiles ike-aes256cbc-sha256-dh20 lifetime hours 8- Network > Network Profiles > IKE Crypto を開きます。
- Add を選択します。
- Name:
ike-aes256cbc-sha256-dh20 - DH Group:
group20 - Authentication:
sha256 - Encryption:
aes-256-cbc - Timers - Key Lifetime: 8 hours
各トンネルには固有の Pre-Shared Key と Local ID(FQDN / ホスト名)があります。Cloudflare ダッシュボードから値を取得して更新してください。
set network ike gateway cf-wan-ike-gw-01 authentication pre-shared-key key "Cloudflare-WAN-T1-PSK-1234!"
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 pq-ppk enabled no
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 pq-ppk negotiation-mode preferred
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 pq-kem enable no
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 pq-kem block-vulnerable-cipher yes
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 ikev2-fragment enable no
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 dpd enable yes
set network ike gateway cf-wan-ike-gw-01 protocol ikev2 ike-crypto-profile ike-aes256cbc-sha256-dh20
set network ike gateway cf-wan-ike-gw-01 protocol ikev1 dpd enable yes
set network ike gateway cf-wan-ike-gw-01 protocol version ikev2
set network ike gateway cf-wan-ike-gw-01 local-address interface ethernet1/1 ip internet_203-0-113-100--24
set network ike gateway cf-wan-ike-gw-01 protocol-common nat-traversal enable no
set network ike gateway cf-wan-ike-gw-01 protocol-common fragmentation enable no
set network ike gateway cf-wan-ike-gw-01 peer-address ip cf_wan_anycast_01
set network ike gateway cf-wan-ike-gw-01 local-id type fqdn id "bf6c493d03<REDACTED>.ipsec.cloudflare.com"
set network ike gateway cf-wan-ike-gw-02 authentication pre-shared-key key "Cloudflare-WAN-T2-PSK-1234!"
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 pq-ppk enabled no
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 pq-ppk negotiation-mode preferred
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 pq-kem enable no
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 pq-kem block-vulnerable-cipher yes
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 ikev2-fragment enable no
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 dpd enable yes
set network ike gateway cf-wan-ike-gw-02 protocol ikev2 ike-crypto-profile ike-aes256cbc-sha256-dh20
set network ike gateway cf-wan-ike-gw-02 protocol ikev1 dpd enable yes
set network ike gateway cf-wan-ike-gw-02 protocol version ikev2
set network ike gateway cf-wan-ike-gw-02 local-address interface ethernet1/1 ip internet_203-0-113-100--24
set network ike gateway cf-wan-ike-gw-02 protocol-common nat-traversal enable no
set network ike gateway cf-wan-ike-gw-02 protocol-common fragmentation enable no
set network ike gateway cf-wan-ike-gw-02 peer-address ip cf_wan_anycast_02
set network ike gateway cf-wan-ike-gw-02 local-id type fqdn id "0287844e9d<REDACTED>.ipsec.cloudflare.com"- Network > Network Profiles > IKE Gateways を開きます。
- Add を選択します。
- Name:
cf-wan-ike-gw-01 - Version:
IKEv2 only mode - Address Type:
IPv4 - Interface:
ethernet1/1 - Local IP Address:
internet_203-0-113-100--24 - Peer IP Address Type:
IP - Authentication:
Pre-Shared Key - Pre-shared key を入力し、値を確認します(Cloudflare ダッシュボードから取得します)。
- Local Identification:
FQDN (hostname)(Cloudflare ダッシュボードからトンネル 1 の FQDN 値を取得します)。 - Advanced Options tab > General > IKE Crypto Profile:
ike-aes256cbc-sha256-dh20 - OK を選択します。
トンネル 2 でも手順を繰り返します。
- Network > Network Profiles > IKE Gateways を開きます。
- Add を選択します。
- Name:
cf-wan-ike-gw-02 - Version:
IKEv2 only mode - Address Type:
IPv4 - Interface:
ethernet1/1 - Local IP Address:
internet_203-0-113-100--24 - Peer IP Address Type:
IP - Authentication:
Pre-Shared Key - Pre-shared key を入力し、値を確認します(Cloudflare ダッシュボードから取得します)。
- Local Identification:
FQDN (hostname)(Cloudflare ダッシュボードからトンネル 2 の FQDN 値を取得します)。 - Advanced Options tab > General > IKE Crypto Profile:
ike-aes256cbc-sha256-dh20 - OK を選択します。
次の設定で IPsec Crypto Profile を定義します。
| 属性 | 値 |
|---|---|
| dh-group | group20 |
| esp encryption | aes-256-cbc |
| esp authentication | sha256 |
| lifetime hours | 8 |
set network ike crypto-profiles ipsec-crypto-profiles ipsec-aes256cbc-sha256-dh20 esp authentication sha256
set network ike crypto-profiles ipsec-crypto-profiles ipsec-aes256cbc-sha256-dh20 esp encryption aes-256-cbc
set network ike crypto-profiles ipsec-crypto-profiles ipsec-aes256cbc-sha256-dh20 lifetime hours 8
set network ike crypto-profiles ipsec-crypto-profiles ipsec-aes256cbc-sha256-dh20 dh-group group20- Network > Network Profiles > IPsec Crypto を開きます。
- Add を選択します。
- Name:
ipsec-aes256cbc-sha256-dh20 - IPsec Protocol:
ESP - Encryption:
aes-256-cbc - Authentication:
sha256 - DH Group:
group20 - Lifetime (Hours):
8
- トンネル 1
set network tunnel ipsec cf-wan-ipsec-tun-01 auto-key ike-gateway cf-wan-ike-gw-01
set network tunnel ipsec cf-wan-ipsec-tun-01 auto-key ipsec-crypto-profile ipsec-aes256cbc-sha256-dh20
set network tunnel ipsec cf-wan-ipsec-tun-01 tunnel-monitor enable no
set network tunnel ipsec cf-wan-ipsec-tun-01 tunnel-interface tunnel.1
set network tunnel ipsec cf-wan-ipsec-tun-01 anti-replay no
set network tunnel ipsec cf-wan-ipsec-tun-02 auto-key ike-gateway cf-wan-ike-gw-02
set network tunnel ipsec cf-wan-ipsec-tun-02 auto-key ipsec-crypto-profile ipsec-aes256cbc-sha256-dh20
set network tunnel ipsec cf-wan-ipsec-tun-02 tunnel-monitor enable no
set network tunnel ipsec cf-wan-ipsec-tun-02 tunnel-interface tunnel.2
set network tunnel ipsec cf-wan-ipsec-tun-02 anti-replay no- Network > IPsec Tunnels を開きます。
- Add を選択します。
- Name:
cf-wan-ipsec-tun-01 - Tunnel interface:
tunnel.1 - Type:
Auto Key - Address Type:
IPv4 - IKE Gateway:
cf-wan-ike-gw-01 - IPsec Crypto Profile:
ipsec-aes256cbc-sha256-dh20 - Show Advanced Options - チェックボックスをオンにします。
Enable Replay Protectionのチェックを外します。- IPsec Mode:
Tunnel
トンネル 2 でも手順を繰り返します。
- Network > IPsec Tunnels を開きます。
- Add を選択します。
- Name:
cf-wan-ipsec-tun-02 - Tunnel interface:
tunnel.2 - Type:
Auto Key - Address Type:
IPv4 - IKE Gateway:
cf-wan-ike-gw-02 - IPsec Crypto Profile:
ipsec-aes256cbc-sha256-dh20 - Show Advanced Options - チェックボックスをオンにします。
Enable Replay Protectionのチェックを外します。- IPsec Mode:
Tunnel
ここで一度止めて Commit を実行し、設定を適用するのがよいタイミングです。トンネル接続が確立されたことを確認できるはずです。
- Network > IPsec Tunnels を開きます。
赤 / 緑のインジケーターの状態を確認します。リアルタイムの状態を見るには Tunnel Info と IKE Info を選択します。
- Monitor > Logs > System を開きます。
- 上部のフィルター / 検索ダイアログに次を追加します:
( subtype eq vpn )
IKE / IPsec の Phase 1 および Phase 2 の状態とエラーメッセージに関する有用な情報が得られます。
Palo Alto Networks NGFW は、同じゾーンを送信元および宛先とするトラフィック(ゾーン内トラフィック)を自動で許可します。tunnel.1 と tunnel.2 を別の Security Zone に入れた場合は、trust から cloudflare、および cloudflare から trust へのトラフィックを許可する明示的なファイアウォールルールが必要です。
move rulebase security rules <RULE_NAME> [after|before|top|bottom] <RULE_NAME - Desired position> を使います。
set rulebase security rules trust-to-cloudflare to cloudflare
set rulebase security rules trust-to-cloudflare from trust
set rulebase security rules trust-to-cloudflare source any
set rulebase security rules trust-to-cloudflare destination any
set rulebase security rules trust-to-cloudflare application any
set rulebase security rules trust-to-cloudflare service application-default
set rulebase security rules trust-to-cloudflare action allow
set rulebase security rules trust-to-cloudflare log-start no
set rulebase security rules trust-to-cloudflare log-end yes
set rulebase security rules trust-to-cloudflare rule-type universal- Policies > Security を開きます。
- Add を選択します。
- General > Name:
trust-to-cloudflare - Rule Type:
universal (default)またはinterzone - Source > Source Zone:
trust - Destination > Destination Zone:
cloudflare - Application >
Any - Service/URL Category >
application-default - Actions > Action setting:
Allow - Log Setting:
Log at Session End
move rulebase security rules <RULE_NAME> [after|before|top|bottom] <RULE_NAME - Desired position> を使います。
set rulebase security rules cloudflare-to-trust to trust
set rulebase security rules cloudflare-to-trust from cloudflare
set rulebase security rules cloudflare-to-trust source any
set rulebase security rules cloudflare-to-trust destination any
set rulebase security rules cloudflare-to-trust application any
set rulebase security rules cloudflare-to-trust service application-default
set rulebase security rules cloudflare-to-trust action allow
set rulebase security rules cloudflare-to-trust log-start no
set rulebase security rules cloudflare-to-trust log-end yes
set rulebase security rules cloudflare-to-trust rule-type universal- Policies > Security を開きます。
- Add を選択します。
- General > Name:
cloudflare-to-trust - Rule Type:
universal (default)またはinterzone - Source > Source Zone:
cloudflare - Destination > Destination Zone:
trust - Application >
Any - Service/URL Category >
application-default - Actions > Action setting:
Allow - Log Setting:
Log at Session End
Policy Based Forwarding ↗(Policy-Based Routing とも呼ばれます)では、特定のトラフィックフローに追加の一致条件を適用し、Virtual Router 内で定義したルートを上書きできます。
別の Cloudflare WAN サイト宛てだけを Cloudflare WAN 経由にし、インターネット向けトラフィックはローカルの Internet breakout へ直接転送し続ける、という使い方ができます。
次の例では、NGFW 背後の LAN サブネット(192.168.125.0/24)からの すべての トラフィックを、Cloudflare WAN の IPsec トンネル経由でルーティングします。これで Cloudflare Secure Web Gateway の機能を使えます。
宛先の一致条件にサブネットを追加するだけで、特定の宛先へトラフィックをルーティングできます。
Policy Based Forwarding で処理するトラフィックフローは、NAT ポリシーから除外してください。インターネット向けトラフィックへの NAT は、ローカルデバイス上のポリシーなしで Cloudflare Gateway が適用します。
- トンネル 1
set rulebase pbf rules cf-wan-to-internet-01 action forward nexthop ip-address cf-wan-ipsec-vti-01-remote
set rulebase pbf rules cf-wan-to-internet-01 action forward egress-interface tunnel.1
set rulebase pbf rules cf-wan-to-internet-01 from zone trust
set rulebase pbf rules cf-wan-to-internet-01 enforce-symmetric-return enabled no
set rulebase pbf rules cf-wan-to-internet-01 source lan-net-192-168-125-0--24
set rulebase pbf rules cf-wan-to-internet-01 destination any
set rulebase pbf rules cf-wan-to-internet-01 source-user any
set rulebase pbf rules cf-wan-to-internet-01 application any
set rulebase pbf rules cf-wan-to-internet-01 service any- トンネル 2
set rulebase pbf rules cf-wan-to-internet-02 action forward nexthop ip-address cf-wan-ipsec-vti-02-remote
set rulebase pbf rules cf-wan-to-internet-02 action forward egress-interface tunnel.2
set rulebase pbf rules cf-wan-to-internet-02 from zone trust
set rulebase pbf rules cf-wan-to-internet-02 enforce-symmetric-return enabled no
set rulebase pbf rules cf-wan-to-internet-02 source lan-net-192-168-125-0--24
set rulebase pbf rules cf-wan-to-internet-02 destination any
set rulebase pbf rules cf-wan-to-internet-02 source-user any
set rulebase pbf rules cf-wan-to-internet-02 application any
set rulebase pbf rules cf-wan-to-internet-02 service any- トンネル 1:
- Policies > Policy Based Forwarding を開きます。
- Add を選択します。
- Name:
cf-wan-to-internet-01 - Source Zone:
trust - Source Address:
lan-net-192-168-125-0--24 - Destination/Application/Service - Any/Any/Any
- Forwarding > Action: Forward、Egress Interface: tunnel.1、Next Hop - IP Address:
cf-wan-ipsec-vti-01-remote
- トンネル 2:
- Policies > Policy Based Forwarding を開きます。
- Add を選択します。
- Name:
cf-wan-to-internet-02 - Source Zone:
trust - Source Address:
lan-net-192-168-125-0--24 - Destination/Application/Service - Any/Any/Any
- Forwarding > Action: Forward、Egress Interface: tunnel.2、Next Hop - IP Address:
cf-wan-ipsec-vti-02-remote
変更をコミットしたあと、192.168.125.0/24 サブネット上のホストからトラフィックをテストし、Cloudflare WAN の IPsec トンネル経由で転送されることを確認します。
- IKE Phase 1 と IPsec Phase 2 が正常にネゴシエートされたかを、必ず確認します。ログで "no proposal chosen" を探します
- Pre-Shared-Key および / または Local-Identity の値が正確で、正しいトンネルに割り当てられていることを確認します
- ping を使い、CPE 側と Cloudflare 側の VTI 間の到達性を確認します
- トンネル 1: CPE VTI から Cloudflare VTI:
ping source 169.254.250.1 169.254.250.0 - トンネル 2: CPE VTI から Cloudflare VTI:
ping source 169.254.250.3 169.254.250.2
- トンネル 1: CPE VTI から Cloudflare VTI:
show ↗ コマンドで Phase 1 と Phase 2 のセキュリティアソシエーションを表示します。
admin@panfw01> show vpn ike-sa
IKEv2 SAs
Gateway ID Peer-Address Gateway Name Role SN Algorithm Established Expiration Xt Child ST
---------- ------------ ------------ ---- -- --------- ----------- ---------- -- ----- --
1 162.159.135.1 cf-wan-ike-gw-01 Init 46 PSK/DH14/A256/SHA256 Mar.22 23:14:24 Mar.23 07:14:24 0 1 Established
2 172.64.135.1 cf-wan-ike-gw-02 Init 45 PSK/DH14/A256/SHA256 Mar.22 23:05:02 Mar.23 07:05:02 0 1 EstablishedIKEv2 IPSec Child SAs
Gateway Name TnID Tunnel ID Parent Role SPI(in) SPI(out) MsgID ST
------------ ---- ------ -- ------ ---- ------- -------- ----- --
cf-wan-ike-gw-01 1 cf-wan-ipsec-tun-01 452741 97 Init B7D055D3 4CB26B43 00000001 Mature
cf-wan-ike-gw-02 2 cf-wan-ipsec-tun-02 452742 98 Init B4629A07 165D416C 00000001 Mature
Show IKEv2 SA: Total 2 gateways found. 2 ike sa found.test ↗ コマンドで Phase 1 と Phase 2 のセキュリティアソシエーションを強制します。
admin@panfw01> test vpn ike-sa gateway cf-wan-ike-gw-01
Start time: Mar.30 21:23:23
Initiate 1 IKE SA.
admin@panfw01> test vpn ike-sa gateway cf-wan-ike-gw-02
Start time: Mar.30 21:23:24
Initiate 1 IKE SA.admin@panfw01> test vpn ipsec-sa tunnel cf-wan-ipsec-tun-01
Start time: Mar.30 21:26:50
Initiate 1 IPSec SA for tunnel cf-wan-ipsec-tun-01.
admin@panfw01> test vpn ipsec-sa tunnel cf-wan-ipsec-tun-02
Start time: Mar.30 21:26:52
Initiate 1 IPSec SA for tunnel cf-wan-ipsec-tun-02.