<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo in AWS to Azure VPN Gateway in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-in-aws-to-azure-vpn-gateway/m-p/485525#M1555</link>
    <description>&lt;P&gt;Hi All, I am trying to setup a site-to-to site VPN between Palo (v9.0.1) and Azure VPN gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question and an issue that I am trying to resolve...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT-T should be enabled in the gateway settings since AWS NATs everything?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the error I keep getting...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.235 -0700 [INFO]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;received IKE request 21.50.80.20[500] to 10.10.50.20[500], found IKE gateway TEST_VPN&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.235 -0700 [PNTF]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;====&amp;gt; IKEv2 IKE SA NEGOTIATION STARTED AS RESPONDER, non-rekey; gateway TEST_VPN &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;====&amp;gt; Initiated SA&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500]-21.50.80.20[500] SPI:e6a2d4b06fcdec78:a017e7a7durt67ug SN:654 &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.235 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;received Notify type NAT_DETECTION_SOURCE_IP&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;received Notify type NAT_DETECTION_DESTINATION_IP&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [INFO]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;NAT detected&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;behind NAT&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [PWRN]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500] - 21.50.80.20[500]:0x555555a4c640 vendor id payload ignored&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [PWRN]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500] - 21.50.80.20[500]:0x555555a4c640 vendor id payload ignored&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [PWRN]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500] - 21.50.80.20[500]:0x555555a4c640 vendor id payload ignored&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [PWRN]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500] - 21.50.80.20[500]:0x555555a4c640 vendor id payload ignored&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;see whether there's matching transform&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;found same ID. compare attributes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;OK; advance to next of my transform type&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;see whether there's matching transform&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;found same ID. compare attributes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;OK; advance to next of my transform type&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;see whether there's matching transform&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;found same ID. compare attributes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;OK; advance to next of my transform type&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;see whether there's matching transform&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;found same ID. compare attributes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;OK; advance to next of my transform type&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;success&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;update request message_id 0x0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [INFO]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[4500] - 21.50.80.20[4500]:0x7fffd4109fc0 authentication result&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;success&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [PNTF]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;====&amp;gt; IKEv2 CHILD SA NEGOTIATION STARTED AS RESPONDER, non-rekey; gateway TEST_VPN &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;====&amp;gt; Initiated SA&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[4500]-21.50.80.20[4500] message id:0x00000001 parent SN:654 &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;update request message_id 0x1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [INFO]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[4500] - 21.50.80.20[4500]:(nil) closing IKEv2 SA TEST_VPN:954, code 15&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [PNTF]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;====&amp;gt; IKEv2 IKE SA NEGOTIATION FAILED AS RESPONDER, non-rekey; gateway TEST_VPN &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;====&amp;gt; Failed SA&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[4500]-21.50.80.20[4500] SPI:e6a2d4b06fcdec78:a017e7a7durt67ug SN 954 &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;SA dying from state RES_IKE_AUTH_RCVD, caller ikev2_abort&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;SA deleted&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;state DYING, caller ikev2_abort&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;stop retransmit for sa 0x7fffd406bb70 (DEAD), CID 0, child 0x7fffd406bb70&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Any help would be&amp;nbsp;appreciated...&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 06 May 2022 22:26:03 GMT</pubDate>
    <dc:creator>PaulZharyuk</dc:creator>
    <dc:date>2022-05-06T22:26:03Z</dc:date>
    <item>
      <title>Palo in AWS to Azure VPN Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-in-aws-to-azure-vpn-gateway/m-p/485525#M1555</link>
      <description>&lt;P&gt;Hi All, I am trying to setup a site-to-to site VPN between Palo (v9.0.1) and Azure VPN gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question and an issue that I am trying to resolve...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT-T should be enabled in the gateway settings since AWS NATs everything?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the error I keep getting...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.235 -0700 [INFO]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;received IKE request 21.50.80.20[500] to 10.10.50.20[500], found IKE gateway TEST_VPN&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.235 -0700 [PNTF]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;====&amp;gt; IKEv2 IKE SA NEGOTIATION STARTED AS RESPONDER, non-rekey; gateway TEST_VPN &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;====&amp;gt; Initiated SA&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500]-21.50.80.20[500] SPI:e6a2d4b06fcdec78:a017e7a7durt67ug SN:654 &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.235 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;received Notify type NAT_DETECTION_SOURCE_IP&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;received Notify type NAT_DETECTION_DESTINATION_IP&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [INFO]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;NAT detected&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;behind NAT&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [PWRN]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500] - 21.50.80.20[500]:0x555555a4c640 vendor id payload ignored&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [PWRN]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500] - 21.50.80.20[500]:0x555555a4c640 vendor id payload ignored&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [PWRN]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500] - 21.50.80.20[500]:0x555555a4c640 vendor id payload ignored&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [PWRN]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[500] - 21.50.80.20[500]:0x555555a4c640 vendor id payload ignored&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;see whether there's matching transform&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;found same ID. compare attributes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;OK; advance to next of my transform type&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;see whether there's matching transform&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;found same ID. compare attributes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;OK; advance to next of my transform type&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;see whether there's matching transform&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;found same ID. compare attributes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;OK; advance to next of my transform type&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;see whether there's matching transform&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;found same ID. compare attributes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;OK; advance to next of my transform type&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;success&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.236 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;update request message_id 0x0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [INFO]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[4500] - 21.50.80.20[4500]:0x7fffd4109fc0 authentication result&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;success&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [PNTF]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;====&amp;gt; IKEv2 CHILD SA NEGOTIATION STARTED AS RESPONDER, non-rekey; gateway TEST_VPN &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;====&amp;gt; Initiated SA&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[4500]-21.50.80.20[4500] message id:0x00000001 parent SN:654 &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;update request message_id 0x1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [INFO]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[4500] - 21.50.80.20[4500]:(nil) closing IKEv2 SA TEST_VPN:954, code 15&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [PNTF]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;====&amp;gt; IKEv2 IKE SA NEGOTIATION FAILED AS RESPONDER, non-rekey; gateway TEST_VPN &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;====&amp;gt; Failed SA&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;10.10.50.20[4500]-21.50.80.20[4500] SPI:e6a2d4b06fcdec78:a017e7a7durt67ug SN 954 &amp;lt;====&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;SA dying from state RES_IKE_AUTH_RCVD, caller ikev2_abort&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;SA deleted&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;state DYING, caller ikev2_abort&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2022-05-06 15:09:24.240 -0700 [DEBG]&lt;/SPAN&gt;&lt;SPAN&gt;: { &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;: }: &lt;/SPAN&gt;&lt;SPAN&gt;stop retransmit for sa 0x7fffd406bb70 (DEAD), CID 0, child 0x7fffd406bb70&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Any help would be&amp;nbsp;appreciated...&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 06 May 2022 22:26:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-in-aws-to-azure-vpn-gateway/m-p/485525#M1555</guid>
      <dc:creator>PaulZharyuk</dc:creator>
      <dc:date>2022-05-06T22:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Palo in AWS to Azure VPN Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-in-aws-to-azure-vpn-gateway/m-p/504129#M1586</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/201927"&gt;@PaulZharyuk&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;You need to put the private IP addresses as IKE peer ID when defining the IKE Gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1655369419774.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41835iE5671120678B9BE4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1655369419774.png" alt="Astardzhiev_0-1655369419774.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't define anything (leave the default of none), firewalls will use IP addresses as peer identifiers. But when behind NAT device will send the private address as local peer (because that is assigned on its interface), while the remote peer will expect to see the public IP (because you have defind the public IP as remote peer).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For that reason when behind NAT, in addition to NAT-T you need to change IKE peer identification to use the private addresses.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. I hope you have upgraded your firewall as 9.0 is out of support since March.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 08:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/palo-in-aws-to-azure-vpn-gateway/m-p/504129#M1586</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-06-16T08:53:40Z</dc:date>
    </item>
  </channel>
</rss>

