Provisioning an SC-CAN in Panorama
When configuring a service connection in Panorama, a few different steps need to be taken. The service connection itself needs to be provisioned, but the IKE Gateway and IPSec tunnel also need to be created. The latter can be accomplished by creating them from the traditional location in Panorama | Templates, or via the provisioning popup that allows you to create objects on the spot. I’ll recommend creating the IKE Gateway and IPSec tunnel beforehand, so the service connection provisioning step is a little less cluttered.
First, navigate to Templates | Network and switch the template to the Service_Conn_Template
. Next, open Network Profiles | IKE Crypto. You’ll notice Palo Alto has already created a couple of default profiles for some well-known vendors, and a generic profile as you can see in the following screenshot:
Figure 4.14 – IKE Crypto
We will, of course, create a fresh IKE Crypto profile...