<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec VPN between Fortigate and Palo Alto in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586190#M3168</link>
    <description>&lt;P&gt;Hello, I've found an error... ipsec SA keeps being established and going down every second or two seconds. I don't know why but I least it's a clue&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="luishoracioarizaga_0-1715178295937.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59582i883D5B24E6EF3CE5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="luishoracioarizaga_0-1715178295937.png" alt="luishoracioarizaga_0-1715178295937.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2024 14:25:19 GMT</pubDate>
    <dc:creator>luishoracio.arizaga</dc:creator>
    <dc:date>2024-05-08T14:25:19Z</dc:date>
    <item>
      <title>IPsec VPN between Fortigate and Palo Alto (slowness)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586169#M3160</link>
      <description>&lt;P&gt;Hello I've established a vpn w/ a Fortigate using PA-1410. Connections are extremely slow. Can someone provide some guidance to troubleshoot the issues please? Here are some outputs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;tunnel  X:XX
        id:                     35
        type:                   IPSec
        gateway id:             14
        local ip:               X.X.X.X
        peer ip:                X.X.X.X
        inner interface:        tunnel.9
        outer interface:        ethernet1/1
        state:                  active
        session:                837652
        tunnel mtu:             1400
        soft lifetime:          3510
        hard lifetime:          3600
        lifetime remain:        3599 sec
        lifesize remain:        4607999 kb
        latest rekey:           1 seconds ago
        monitor:                off
          monitor packets seen: 0
          monitor packets reply:0
        en/decap context:       4371
        local spi:              DD9790D6
        remote spi:             B55B01EA
        key type:               auto key
        protocol:               ESP
        auth algorithm:         SHA1
        enc  algorithm:         AES128
        traffic selector:
          protocol:             0
          local ip range:       10.72.X.X - 10.72.X.X
          local port range:     0 - 65535
          remote ip range:      10.35.X.X - 10.35.X.X
          remote port range:    0 - 65535
        ipsec mode:             tunnel
        anti replay check:      yes
        anti replay window:     1024
        copy tos:               no
        enable gre encap:       no
        initiator:              yes
        authentication errors:  0
        decryption errors:      0
        inner packet warnings:  0
        replay packets:         0
        packets received
          when lifetime expired:0
          when lifesize expired:0
        sending sequence:       1
        receive sequence:       0
        encap packets:          30292
        decap packets:          8730
        encap bytes:            6511296
        decap bytes:            4974032
        encap IPv4 packets:     30292
        decap IPv4 packets:     8730
        encap IPv4 bytes:       6511296
        decap IPv4 bytes:       4974032
        encap IPv6 packets:     0
        decap IPv6 packets:     0
        encap IPv6 bytes:       0
        decap IPv6 bytes:       0
        key acquire requests:   1
        owner state:            0
        owner cpuid:            s1dp0
        ownership:              1&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 14:25:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586169#M3160</guid>
      <dc:creator>luishoracio.arizaga</dc:creator>
      <dc:date>2024-05-10T14:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Fortigate and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586174#M3161</link>
      <description>&lt;P&gt;What do you use to measure speed?&lt;/P&gt;
&lt;P&gt;Packet loss?&lt;/P&gt;
&lt;P&gt;Fragmentation?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:47:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586174#M3161</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-05-08T13:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Fortigate and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586178#M3162</link>
      <description>&lt;P&gt;The server takes too long to answer. Websites do not load or take 5,10 minutes to load.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:54:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586178#M3162</guid>
      <dc:creator>luishoracio.arizaga</dc:creator>
      <dc:date>2024-05-08T13:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Fortigate and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586190#M3168</link>
      <description>&lt;P&gt;Hello, I've found an error... ipsec SA keeps being established and going down every second or two seconds. I don't know why but I least it's a clue&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="luishoracioarizaga_0-1715178295937.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59582i883D5B24E6EF3CE5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="luishoracioarizaga_0-1715178295937.png" alt="luishoracioarizaga_0-1715178295937.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 14:25:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586190#M3168</guid>
      <dc:creator>luishoracio.arizaga</dc:creator>
      <dc:date>2024-05-08T14:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Fortigate and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586196#M3169</link>
      <description>&lt;P&gt;This points to mismatching proxy-ids.&lt;/P&gt;
&lt;P&gt;Check that encryption domain / proxy-id is exactly the same on both side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you switch temporarily to IKEv1 then you can see in system log what proxy-id's Fortigate sends to Palo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise you need to troubleshoot in cli to get this info.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 15:16:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586196#M3169</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-05-08T15:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Fortigate and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586384#M3180</link>
      <description>&lt;P&gt;Hello just for everybody's information... Actually vpn tunnel was being established and closed every two seconds or so. I could check this in the logs. On the monitoring part of the firewall everything seemed normal (Network =&amp;gt; IPsec tunnels) but the TS associations were going up and down and traffic was being impacted of course. To check the logs go to Monitor =&amp;gt; System and go for this kind of messages (I've filtered using the SPI id on the description). Look for TS association errors =&amp;gt; This means proxy ID aren't matching between your Palo Alto firewall and the FW on the other end. You need exact matches. We replaced ASA w/ Palo Alto and the same configuration for crypto maps was not working. Hope this helps someone on the future :).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="luishoracioarizaga_1-1715350966293.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59618i6D81709CF532507C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="luishoracioarizaga_1-1715350966293.png" alt="luishoracioarizaga_1-1715350966293.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 14:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-between-fortigate-and-palo-alto-slowness/m-p/586384#M3180</guid>
      <dc:creator>luishoracio.arizaga</dc:creator>
      <dc:date>2024-05-10T14:24:02Z</dc:date>
    </item>
  </channel>
</rss>

