<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up an IPSEC VPN Tunnel on AWS in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/setting-up-an-ipsec-vpn-tunnel-on-aws/m-p/251560#M539</link>
    <description>&lt;P&gt;So the support team resolved it.. it was due to the tunnel endpoint sitting on the same subnet as the private subnet on VPC 1.. apparently you need some subnet indicator on the 10.60.66.14 or it won't know where the gateway is, even if you hardcode the ARP. We solved the issue by making another subnet at 10.60.0.0/24 and used that for E1/1 in VPC 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also needed to setup static routing config on the virtual router for E1/1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finally, we needed to run the following two commands to manually initiate the tunnel.&lt;/P&gt;&lt;P&gt;test vpn ike-sa gateway [ike gateway name]&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel [tunnel name]&lt;/P&gt;</description>
    <pubDate>Wed, 27 Feb 2019 18:10:33 GMT</pubDate>
    <dc:creator>rockyyuan</dc:creator>
    <dc:date>2019-02-27T18:10:33Z</dc:date>
    <item>
      <title>Setting up an IPSEC VPN Tunnel on AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/setting-up-an-ipsec-vpn-tunnel-on-aws/m-p/251432#M537</link>
      <description>&lt;P&gt;Hi Palo Alto community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been trying to follow this guide to set up a static IPSEC tunnel on AWS between two VPCs but having a bit of trouble:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/servlet/fileField?entityId=ka10g000000D8OjAAK&amp;amp;field=Attachment_1__Body__s" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/servlet/fileField?entityId=ka10g000000D8OjAAK&amp;amp;field=Attachment_1__Body__s&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is my network diagram:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="range drawing palo alto.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18886i3D609EF68944B70F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="range drawing palo alto.png" alt="range drawing palo alto.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is my configuration for the firewall in VPC A:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18889i83A96D2ADB1A7689/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18890i2E7C7CF93B81E836/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18888i41242B3429ED0DC2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="3.PNG" alt="3.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18891i807B8E02219550D4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="4.PNG" alt="4.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18892i89521ABECD377C78/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="5.PNG" alt="5.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is my configuration for the firewall in VPC B:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="r2_1.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18894iB9F26836255F4EC9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="r2_1.PNG" alt="r2_1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="r2_2.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18893i6FDF4415B1388C0E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="r2_2.PNG" alt="r2_2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="r2_3.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18895iED0A45419EC6F338/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="r2_3.PNG" alt="r2_3.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="r2_4.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18896i6F5BBE78440F879F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="r2_4.PNG" alt="r2_4.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="r2_5.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18897iD0C38957ED234241/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="r2_5.PNG" alt="r2_5.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I had also added some firewall rules that weren't in the screenshots according to the guide but that didn't help turn the IPSEC tunnel status green either.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I also ran the command show vpn flow in the CLI but the state remains "init" on the tunnel:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="show vpn flow.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18887i4345AC4BE8E83DDA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="show vpn flow.PNG" alt="show vpn flow.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any suggestions would be appreciated, pretty new to using PA as I've been using mostly cisco/pfSense up to this point, thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 19:08:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/setting-up-an-ipsec-vpn-tunnel-on-aws/m-p/251432#M537</guid>
      <dc:creator>rockyyuan</dc:creator>
      <dc:date>2019-02-26T19:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up an IPSEC VPN Tunnel on AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/setting-up-an-ipsec-vpn-tunnel-on-aws/m-p/251456#M538</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Check the logs to see if the packets are getting from one pan to the other. If not it could be the AWS ACL firewall or your security groups are preventing the communication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 22:56:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/setting-up-an-ipsec-vpn-tunnel-on-aws/m-p/251456#M538</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-02-26T22:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up an IPSEC VPN Tunnel on AWS</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/setting-up-an-ipsec-vpn-tunnel-on-aws/m-p/251560#M539</link>
      <description>&lt;P&gt;So the support team resolved it.. it was due to the tunnel endpoint sitting on the same subnet as the private subnet on VPC 1.. apparently you need some subnet indicator on the 10.60.66.14 or it won't know where the gateway is, even if you hardcode the ARP. We solved the issue by making another subnet at 10.60.0.0/24 and used that for E1/1 in VPC 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also needed to setup static routing config on the virtual router for E1/1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finally, we needed to run the following two commands to manually initiate the tunnel.&lt;/P&gt;&lt;P&gt;test vpn ike-sa gateway [ike gateway name]&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel [tunnel name]&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 18:10:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/setting-up-an-ipsec-vpn-tunnel-on-aws/m-p/251560#M539</guid>
      <dc:creator>rockyyuan</dc:creator>
      <dc:date>2019-02-27T18:10:33Z</dc:date>
    </item>
  </channel>
</rss>

