<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site to Site RSA_verify failed , error rsa routines (PaloAlto to checkpoint SMB) in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/525132#M705</link>
    <description>&lt;P&gt;trying to establish S2S VPN between Palo Alto 850 and Checkpoint SMB&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certificate based authentication (MS enterprise CA)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ikev2 is complaining :&lt;/P&gt;
&lt;P&gt;====&amp;gt; Initiated SA: XXX.XXX.XXX.XXX[500]-YYY.YYY.YYY.YYY[500] SPI:dcb4c37f6f955782:0898ce67edab9913 SN:8962 &amp;lt;====&lt;BR /&gt;2022-12-26 23:34:49.355 +0200 [PWRN]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:0x19961dc0 ignoring unauthenticated notify payload (NAT_DETECTION_SOURCE_IP)&lt;BR /&gt;2022-12-26 23:34:49.355 +0200 [PWRN]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:0x19961dc0 ignoring unauthenticated notify payload (NAT_DETECTION_DESTINATION_IP)&lt;BR /&gt;2022-12-26 23:34:49.363 +0200 [INFO]: { 4: }: build IKEv2 CR payload[0]: 'CN=ABC Root CA'&lt;BR /&gt;2022-12-26 23:34:49.363 +0200 [INFO]: { 4: }: build IKEv2 CR payload[1]: 'CN=ABC Issuing CA 1,DC=ABC,DC=local'&lt;BR /&gt;2022-12-26 23:34:49.363 +0200 [INFO]: { 4: }: build IKEv2 CR payload[2]: 'O=AA:SS:AA:SS:AA:SS..8d67yo'&lt;BR /&gt;2022-12-26 23:34:49.394 +0200 [INFO]: { 4: }: cert received: subject=CN=CPGW&lt;BR /&gt;2022-12-26 23:34:49.394 +0200 [INFO]: { 4: }: cert received: issuer=CN=ABC Issuing CA 1,DC=ABC,DC=local[ee?]&lt;BR /&gt;2022-12-26 23:34:49.394 +0200 [INFO]: { 4: }: CR 'CN=ABC Issuing CA 1,DC=ABC,DC=local' received, trust CA founABCCA1&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [PERR]: RSA_verify failed: 0:error:04091068:rsa routines:int_rsa_verify:bad signature:crypto/rsa/rsa_sign.c:228:&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [PERR]: Invalid SIG.&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [PERR]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:0xffcc0f19a0 authentication failure&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [INFO]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:0xffcc0f19a0 authentication result: failure&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [INFO]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:(nil) closing IKEv2 SA CPGW-Site:8962, code 15&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [PNTF]: { 4: }: ====&amp;gt; IKEv2 IKE SA NEGOTIATION FAILED AS RESPONDER, non-rekey; gateway CPGW-Site &amp;lt;====&lt;BR /&gt;====&amp;gt; Failed SA: XXX.XXX.XXX.XXX[500]-YYY.YYY.YYY.YYY[500] SPI:dcb4c37f6f955782:0898ce67edab9913 SN 8962 &amp;lt;====&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could not find something specific for the&amp;nbsp;RSA_verify , Invalid SIG.&lt;/P&gt;
&lt;P&gt;Any thoughts what could be the issue?&lt;/P&gt;</description>
    <pubDate>Mon, 26 Dec 2022 21:40:26 GMT</pubDate>
    <dc:creator>MEDOCHEMIE</dc:creator>
    <dc:date>2022-12-26T21:40:26Z</dc:date>
    <item>
      <title>Site to Site RSA_verify failed , error rsa routines (PaloAlto to checkpoint SMB)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/525132#M705</link>
      <description>&lt;P&gt;trying to establish S2S VPN between Palo Alto 850 and Checkpoint SMB&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certificate based authentication (MS enterprise CA)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ikev2 is complaining :&lt;/P&gt;
&lt;P&gt;====&amp;gt; Initiated SA: XXX.XXX.XXX.XXX[500]-YYY.YYY.YYY.YYY[500] SPI:dcb4c37f6f955782:0898ce67edab9913 SN:8962 &amp;lt;====&lt;BR /&gt;2022-12-26 23:34:49.355 +0200 [PWRN]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:0x19961dc0 ignoring unauthenticated notify payload (NAT_DETECTION_SOURCE_IP)&lt;BR /&gt;2022-12-26 23:34:49.355 +0200 [PWRN]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:0x19961dc0 ignoring unauthenticated notify payload (NAT_DETECTION_DESTINATION_IP)&lt;BR /&gt;2022-12-26 23:34:49.363 +0200 [INFO]: { 4: }: build IKEv2 CR payload[0]: 'CN=ABC Root CA'&lt;BR /&gt;2022-12-26 23:34:49.363 +0200 [INFO]: { 4: }: build IKEv2 CR payload[1]: 'CN=ABC Issuing CA 1,DC=ABC,DC=local'&lt;BR /&gt;2022-12-26 23:34:49.363 +0200 [INFO]: { 4: }: build IKEv2 CR payload[2]: 'O=AA:SS:AA:SS:AA:SS..8d67yo'&lt;BR /&gt;2022-12-26 23:34:49.394 +0200 [INFO]: { 4: }: cert received: subject=CN=CPGW&lt;BR /&gt;2022-12-26 23:34:49.394 +0200 [INFO]: { 4: }: cert received: issuer=CN=ABC Issuing CA 1,DC=ABC,DC=local[ee?]&lt;BR /&gt;2022-12-26 23:34:49.394 +0200 [INFO]: { 4: }: CR 'CN=ABC Issuing CA 1,DC=ABC,DC=local' received, trust CA founABCCA1&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [PERR]: RSA_verify failed: 0:error:04091068:rsa routines:int_rsa_verify:bad signature:crypto/rsa/rsa_sign.c:228:&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [PERR]: Invalid SIG.&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [PERR]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:0xffcc0f19a0 authentication failure&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [INFO]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:0xffcc0f19a0 authentication result: failure&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [INFO]: { 4: }: XXX.XXX.XXX.XXX[500] - YYY.YYY.YYY.YYY[500]:(nil) closing IKEv2 SA CPGW-Site:8962, code 15&lt;BR /&gt;2022-12-26 23:34:49.397 +0200 [PNTF]: { 4: }: ====&amp;gt; IKEv2 IKE SA NEGOTIATION FAILED AS RESPONDER, non-rekey; gateway CPGW-Site &amp;lt;====&lt;BR /&gt;====&amp;gt; Failed SA: XXX.XXX.XXX.XXX[500]-YYY.YYY.YYY.YYY[500] SPI:dcb4c37f6f955782:0898ce67edab9913 SN 8962 &amp;lt;====&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could not find something specific for the&amp;nbsp;RSA_verify , Invalid SIG.&lt;/P&gt;
&lt;P&gt;Any thoughts what could be the issue?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 21:40:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/525132#M705</guid>
      <dc:creator>MEDOCHEMIE</dc:creator>
      <dc:date>2022-12-26T21:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site RSA_verify failed , error rsa routines (PaloAlto to checkpoint SMB)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/525234#M706</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Try IKEv1 and see what happens. I've seen this a few times where the IKEv2 between two different or even same manufactures, doesnt play well for some reason.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 16:56:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/525234#M706</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-12-27T16:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site RSA_verify failed , error rsa routines (PaloAlto to checkpoint SMB)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/526832#M752</link>
      <description>&lt;P&gt;Hello MEDOCHEMIE,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you manage to fix this issue with the Invalid SIG? I have the same problem with S2S VPN between Paloalto and Cradlepoint router&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 19:17:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/526832#M752</guid>
      <dc:creator>leszeksroka</dc:creator>
      <dc:date>2023-01-12T19:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site RSA_verify failed , error rsa routines (PaloAlto to checkpoint SMB)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/527270#M763</link>
      <description>&lt;P&gt;Could there be some nat in the way and nat traversal to be needed?&lt;/P&gt;
&lt;H1 class="slds-text-heading_large"&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1 class="slds-text-heading_large"&gt;IPSec VPN Tunnel with NAT Traversal&lt;/H1&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClopCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClopCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also check this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 class="slds-text-heading_large"&gt;Proxy-ID for VPNs Between Palo Alto Networks and Firewalls with Policy-based VPNs&lt;/H1&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClW8CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClW8CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And if needed enable ike debug:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 class="slds-text-heading_large"&gt;How to Troubleshoot IPSec VPN connectivity issues&lt;/H1&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 21:08:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/527270#M763</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-01-16T21:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site RSA_verify failed , error rsa routines (PaloAlto to checkpoint SMB)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/529449#M841</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/252351"&gt;@MEDOCHEMIE&lt;/a&gt; , Did you manage to find the solution?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 11:13:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/site-to-site-rsa-verify-failed-error-rsa-routines-paloalto-to/m-p/529449#M841</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-02-01T11:13:00Z</dc:date>
    </item>
  </channel>
</rss>

