<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PANOS 10.2.8 NOT recommended: S2S VPN IKEv1, IKEv2 Prefered does not work anymore in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-2-8-not-recommended-s2s-vpn-ikev1-ikev2-prefered-does/m-p/580988#M2854</link>
    <description>&lt;P&gt;Hi Everybody,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We updated from 10.2.7 to 10.2.8 and had a lot of troubles with our Site-2-Site IKEv1, IKEv2 Prefered gateway connections. I'm not sure if the IKE Version is the root problem,&amp;nbsp;but that was the pattern that was visible in the short time for this change.&lt;/P&gt;
&lt;P&gt;Phase 1 came not up, initiated in both directions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are the msg in the logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;Us-2-endpoint: 'IKE phase-1 negotiation is failed as responder, main mode. Failed SA:&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Endpoint-2-us: the logs said always "Connection Timeout".&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sophos, FritzBox and Azure were the other endpoints, we were not able to etablish phase 1. After Downgrading to 10.2.7 everything worked, also with 10.2.7-h3 is everything working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We did not seen in the traffic monitor any traffic for the phase1, although we otherwise saw this connection traffic in an intrazone (Untrust-2-Untrust) rule. With PANOS 10.2.7 and H3 it was visible again&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also without Zone Protection, the connection came not up, it was like something was blocking the connection, without generating logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't find something in the release notes that point to this issue. Somebody else with this&amp;nbsp;experience?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy firewalling&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2024 06:01:30 GMT</pubDate>
    <dc:creator>FabioHufschmid</dc:creator>
    <dc:date>2024-03-20T06:01:30Z</dc:date>
    <item>
      <title>PANOS 10.2.8 NOT recommended: S2S VPN IKEv1, IKEv2 Prefered does not work anymore</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-2-8-not-recommended-s2s-vpn-ikev1-ikev2-prefered-does/m-p/580988#M2854</link>
      <description>&lt;P&gt;Hi Everybody,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We updated from 10.2.7 to 10.2.8 and had a lot of troubles with our Site-2-Site IKEv1, IKEv2 Prefered gateway connections. I'm not sure if the IKE Version is the root problem,&amp;nbsp;but that was the pattern that was visible in the short time for this change.&lt;/P&gt;
&lt;P&gt;Phase 1 came not up, initiated in both directions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are the msg in the logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;Us-2-endpoint: 'IKE phase-1 negotiation is failed as responder, main mode. Failed SA:&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Endpoint-2-us: the logs said always "Connection Timeout".&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sophos, FritzBox and Azure were the other endpoints, we were not able to etablish phase 1. After Downgrading to 10.2.7 everything worked, also with 10.2.7-h3 is everything working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We did not seen in the traffic monitor any traffic for the phase1, although we otherwise saw this connection traffic in an intrazone (Untrust-2-Untrust) rule. With PANOS 10.2.7 and H3 it was visible again&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also without Zone Protection, the connection came not up, it was like something was blocking the connection, without generating logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't find something in the release notes that point to this issue. Somebody else with this&amp;nbsp;experience?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy firewalling&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 06:01:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-2-8-not-recommended-s2s-vpn-ikev1-ikev2-prefered-does/m-p/580988#M2854</guid>
      <dc:creator>FabioHufschmid</dc:creator>
      <dc:date>2024-03-20T06:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 10.2.8 NOT recommended: S2S VPN IKEv1, IKEv2 Prefered does not work anymore</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-2-8-not-recommended-s2s-vpn-ikev1-ikev2-prefered-does/m-p/583989#M3001</link>
      <description>&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;There are two NAT rules (destination-translation) for the Exchange2019 mail server, starting from version 1.2.8 they stopped working.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;They work for some time, then they are blocked, there is no information in the logs.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;In version 1.2.9 the same thing.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 10:03:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-2-8-not-recommended-s2s-vpn-ikev1-ikev2-prefered-does/m-p/583989#M3001</guid>
      <dc:creator>MILAVITSA</dc:creator>
      <dc:date>2024-04-17T10:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS 10.2.8 NOT recommended: S2S VPN IKEv1, IKEv2 Prefered does not work anymore</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-2-8-not-recommended-s2s-vpn-ikev1-ikev2-prefered-does/m-p/584706#M3046</link>
      <description>&lt;P&gt;Thanks for providing valuable insight &lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/289740"&gt;@FabioHufschmid&lt;/a&gt;&lt;/SPAN&gt; ! If you ever have the time, please open up a support ticket and share details of your findings.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 02:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-10-2-8-not-recommended-s2s-vpn-ikev1-ikev2-prefered-does/m-p/584706#M3046</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-04-24T02:04:03Z</dc:date>
    </item>
  </channel>
</rss>

