<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN with Azure falling down in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vpn-with-azure-falling-down/m-p/134444#M11</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l had a very interesting experience with Azure VPN. Few&amp;nbsp;things to check check:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) PA has to be in passive mode so only Azure can initiate a VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Suggested config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKEv2&lt;BR /&gt;Diffie-Hellman Group Group 2&lt;BR /&gt;Authentication Method SHA1&lt;BR /&gt;Encryption Algorithms AES256, 3DES&lt;BR /&gt;Phase 1 Security Association (SA) Lifetime (Time) 28,800 seconds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CHILD_SA&lt;BR /&gt;Encryption Algorithms AES128, 3DES&lt;BR /&gt;Authentication Method SHA1&lt;BR /&gt;Phase 2 Security Association (SA) Lifetime (Time) 5,400 (Azure side 3,600 seconds)&lt;BR /&gt;Perfect Forward Secrecy (PFS) no-pfs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Disable "Liveness Check"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More info here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/VPN-to-Azure-dropouts/td-p/98936/page/3" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/VPN-to-Azure-dropouts/td-p/98936/page/3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
    <pubDate>Fri, 23 Dec 2016 11:57:23 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2016-12-23T11:57:23Z</dc:date>
    <item>
      <title>VPN with Azure falling down</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vpn-with-azure-falling-down/m-p/133949#M10</link>
      <description>&lt;P&gt;Hi at all!&lt;/P&gt;&lt;P&gt;I have a problem with a VPN with Azure, after 50 minutes circa the VPN stops working and doesn't restart.&lt;/P&gt;&lt;P&gt;I checked the configuration and everything is right.&lt;/P&gt;&lt;P&gt;This message appears in logs: "IKEv2 child SA negotiation is failed message lacks KE payload".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help me to resolve this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 10:15:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vpn-with-azure-falling-down/m-p/133949#M10</guid>
      <dc:creator>DKanta</dc:creator>
      <dc:date>2016-12-21T10:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with Azure falling down</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vpn-with-azure-falling-down/m-p/134444#M11</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l had a very interesting experience with Azure VPN. Few&amp;nbsp;things to check check:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) PA has to be in passive mode so only Azure can initiate a VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Suggested config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKEv2&lt;BR /&gt;Diffie-Hellman Group Group 2&lt;BR /&gt;Authentication Method SHA1&lt;BR /&gt;Encryption Algorithms AES256, 3DES&lt;BR /&gt;Phase 1 Security Association (SA) Lifetime (Time) 28,800 seconds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CHILD_SA&lt;BR /&gt;Encryption Algorithms AES128, 3DES&lt;BR /&gt;Authentication Method SHA1&lt;BR /&gt;Phase 2 Security Association (SA) Lifetime (Time) 5,400 (Azure side 3,600 seconds)&lt;BR /&gt;Perfect Forward Secrecy (PFS) no-pfs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Disable "Liveness Check"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More info here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/VPN-to-Azure-dropouts/td-p/98936/page/3" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/VPN-to-Azure-dropouts/td-p/98936/page/3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2016 11:57:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vpn-with-azure-falling-down/m-p/134444#M11</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-23T11:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with Azure falling down</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vpn-with-azure-falling-down/m-p/134960#M12</link>
      <description>&lt;P&gt;Hi Myky,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank for your suggestion, we solved it some days ago checking on Microsoft site (&lt;A href="https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-devices" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-devices&lt;/A&gt;), we used 'no-pfs' instead of DH group 2 on IPSEC Crypto key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Daniele&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2016 10:35:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/vpn-with-azure-falling-down/m-p/134960#M12</guid>
      <dc:creator>DKanta</dc:creator>
      <dc:date>2016-12-29T10:35:30Z</dc:date>
    </item>
  </channel>
</rss>

