site to site vpn - server to server (socket to socket) connection

eitan Posts: 9  Freshman Member
First Comment
edited 2021 14 in Security

I need help with my next challenge and that is to create a site to site vpn. It has to be what cisco refers to as the extranet scenario. My partner's company and my company want to establish a site to site vpn between two servers. The vpn is to be restricted to only allow two servers (two sockets) to communicate securely across the internet. One server  at my company the other at my partners'. We do not want to share subnets etc...
i believe my peer ip is I want to use (which is my first usable public ip) as the vpn public ip for the the server at my location, internally my servers address is Port to use on my server will be 2111. No internal IPs will be visible between the two companies. 
I will use my partner's peer public IP as, and the public ip, and port, of my partner's server as 
Thank you in advance

All Replies

  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    50 Answers 500 Comments Friend Collector Fourth Anniversary
    Your application is that you want the can access peer internal device via and will actually mapping to the server IP

  • eitan
    eitan Posts: 9  Freshman Member
    First Comment
  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    50 Answers 500 Comments Friend Collector Fourth Anniversary
    Regrading to this case, 
    you need to configure extra SNAT on VPN page and policy routing on your own Palo Alto,
    here is an example(on Palo Alto)

    Here is Guide as your reference.
    SNAT on VPN environment