StudyToCert

All certifications / NGFW Engineer / Lessons

Palo Alto Networks Certified Next-Generation Firewall Engineer NGFW-Engineer · Domain 1: PAN-OS networking configuration

Site-to-site IPsec: IKE gateway, IKE and IPsec crypto profiles, tunnel interfaces, proxy IDs, tunnel monitoring

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Palo Alto firewalls build route-based site-to-site VPNs (virtual private networks). Instead of a policy saying 'encrypt traffic from A to B', you create a tunnel interface and route the remote networks to it. Anything routed into the tunnel is protected with IPsec (IP Security). This keeps VPN logic in routing, where static routes or dynamic protocols such as OSPF and BGP can steer traffic, and it makes the tunnel look like any other interface in a zone.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study NGFW Engineer for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the NGFW Engineer study plan