<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Phase 2 Tunnel stuck in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-phase-2-tunnel-stuck/m-p/526238#M738</link>
    <description>&lt;P&gt;Just make your Palo Alto the VPN responder so you can see more details in the GUI System logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="page-body"&gt;&lt;LABEL style="background: #fef1e3; color: #f95147; text-align: center; font-weight: 500;"&gt; &lt;/LABEL&gt;
&lt;DIV class="container1"&gt;
&lt;DIV class="slds-scope"&gt;
&lt;DIV id="content1" class="content1"&gt;
&lt;H1 class="slds-text-heading_large"&gt;How to make Palo Alto Networks firewalls Responder-only in an IPSec tunnel&lt;/H1&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also maybe the other&amp;nbsp; firewall is using policy based VPN:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 class="slds-text-heading_large"&gt;Proxy-ID for VPNs Between Palo Alto Networks and Firewalls with Policy-based VPNs&lt;/H1&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClW8CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClW8CAK&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 07 Jan 2023 17:28:00 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2023-01-07T17:28:00Z</dc:date>
    <item>
      <title>VPN Phase 2 Tunnel stuck</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-phase-2-tunnel-stuck/m-p/526060#M736</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We have multiple S2S VPN with many vendors but facing issue with Fortinet.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On our side we observe Phase 2 tunnel is up and packets are going out through Tunnel interface but no reply. Other party saying no issue on their end but once we restart that Phase 2 Proxy id, it starts working.&lt;/P&gt;
&lt;P&gt;Just to inform you that we have multiple Proxy ids. all Proxy ids Tunnels comes up different time and face issue at different time so need to restart only that proxy id tunnel.&lt;/P&gt;
&lt;P&gt;Kindly let me know how to troubleshoot it either issue is at our end or their end.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 22:47:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-phase-2-tunnel-stuck/m-p/526060#M736</guid>
      <dc:creator>ISG-JHAH</dc:creator>
      <dc:date>2023-01-05T22:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Phase 2 Tunnel stuck</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-phase-2-tunnel-stuck/m-p/526238#M738</link>
      <description>&lt;P&gt;Just make your Palo Alto the VPN responder so you can see more details in the GUI System logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="page-body"&gt;&lt;LABEL style="background: #fef1e3; color: #f95147; text-align: center; font-weight: 500;"&gt; &lt;/LABEL&gt;
&lt;DIV class="container1"&gt;
&lt;DIV class="slds-scope"&gt;
&lt;DIV id="content1" class="content1"&gt;
&lt;H1 class="slds-text-heading_large"&gt;How to make Palo Alto Networks firewalls Responder-only in an IPSec tunnel&lt;/H1&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also maybe the other&amp;nbsp; firewall is using policy based VPN:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 class="slds-text-heading_large"&gt;Proxy-ID for VPNs Between Palo Alto Networks and Firewalls with Policy-based VPNs&lt;/H1&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClW8CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClW8CAK&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2023 17:28:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-phase-2-tunnel-stuck/m-p/526238#M738</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-01-07T17:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Phase 2 Tunnel stuck</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-phase-2-tunnel-stuck/m-p/526279#M740</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85350"&gt;@ISG-JHAH&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you checking the status of the IPSec from GUI? The status of the Phase-2 will stay UP (Green on GUI) as long as even 1 proxy ID is UP among all in Phase-2 tunnels. &lt;BR /&gt;Please check if the status of the proxy-ID is indeed UP? To check the status, run the below command from the CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show vpn tunnel name &amp;lt;name-of-proxy-id&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;You will get information like LOCAL PROXY ID, REMOTE PROXY ID, ports etc in output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The VPN logs generated as responder gives more information as suggested by&lt;BR /&gt;You can review the system logs and ikemgr logs, during the issue time frame.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also refer to the below KBs:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank" rel="noopener nofollow noreferrer"&gt;How to Troubleshoot IPSec VPN connectivity issues&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO" target="_blank" rel="noopener nofollow noreferrer"&gt;IKEv1 VPN error logs - Troubleshooting&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clh5CAC" target="_blank" rel="noopener nofollow noreferrer"&gt;IPSec and Tunneling Resource list on Configuring and Troubleshooting&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 06:59:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-phase-2-tunnel-stuck/m-p/526279#M740</guid>
      <dc:creator>Arnesh</dc:creator>
      <dc:date>2023-01-09T06:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Phase 2 Tunnel stuck</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-phase-2-tunnel-stuck/m-p/526365#M741</link>
      <description>&lt;P&gt;Yes as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/253055"&gt;@Arnesh&lt;/a&gt; mentioned if needed enable debug for extra info. This is also a usefull link: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcKCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcKCAS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 17:30:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/vpn-phase-2-tunnel-stuck/m-p/526365#M741</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-01-09T17:30:54Z</dc:date>
    </item>
  </channel>
</rss>

