<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec tunnel doesn't connect - no errors seen in VM-Series in the Private Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225736#M347</link>
    <description>&lt;P&gt;Confirmed with other side that they accidentally deleted the config for my second connection. But we all know it was no accident.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Apr 2025 16:59:27 GMT</pubDate>
    <dc:creator>1treelanedrv</dc:creator>
    <dc:date>2025-04-04T16:59:27Z</dc:date>
    <item>
      <title>IPsec tunnel doesn't connect - no errors seen</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225043#M335</link>
      <description>&lt;P&gt;Hi everyone, do you have any idea why this tunnel will not establish?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to connect with a partner company. The IPsec config is identical across two templates. &amp;nbsp;Both sites have their own unique public IP and are connecting to the same peer IP on the partner's side.&amp;nbsp;The&amp;nbsp;Secondary_Gateway connects fine. But this Primary_Gateway only shows this in the ikemgr.log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2025-03-28 10:45:44.375 -0500 debug: sysd_msg_send(daemon/panike_sysd_if.c:2487): iked sysd msg enqueue: ike_debug_handler&lt;BR /&gt;2025-03-28 10:45:49.287 -0500 debug: pan_msg_process(daemon/panike_sysd_if.c:2849): iked rcv msg ike_stats_handler(18).&lt;BR /&gt;2025-03-28 10:45:49.299 -0500 debug: sysd_msg_send(daemon/panike_sysd_if.c:2487): iked sysd msg enqueue: ike_stats_handler&lt;BR /&gt;2025-03-28 10:45:52.404 -0500 debug: pan_msg_process(daemon/panike_sysd_if.c:2849): iked rcv msg ike_stats_handler(18).&lt;BR /&gt;2025-03-28 10:45:52.416 -0500 debug: sysd_msg_send(daemon/panike_sysd_if.c:2487): iked sysd msg enqueue: ike_stats_handler&lt;BR /&gt;2025-03-28 10:46:03.083 -0500 debug: pan_msg_process(daemon/panike_sysd_if.c:2849): iked rcv msg ike_sa_handler(13).&lt;BR /&gt;2025-03-28 10:46:03.084 -0500 [INFO]: { 1: }: Primary_Gateway: IKEv2 SA test initiate start.&lt;BR /&gt;2025-03-28 10:46:03.099 -0500 [PNTF]: { 1: }: ====&amp;gt; IKEv2 IKE SA NEGOTIATION STARTED AS INITIATOR, non-rekey; gateway Primary_Gateway &amp;lt;====&lt;BR /&gt;====&amp;gt; Initiated SA: 10.1.1.1[500]-10.2.2.2[500] SPI:1a14bc5f2ee04e45:0000000000000000 SN:14 &amp;lt;====&lt;BR /&gt;2025-03-28 10:46:03.099 -0500 [DEBG]: { 1: 1}: ikev2_initiate: child_sa created: id 23&lt;BR /&gt;2025-03-28 10:46:03.183 -0500 [DEBG]: 10.1.1.1[500] - 10.2.2.2[500]:(nil) 1 times of 248 bytes message will be sent over socket 1024&lt;BR /&gt;2025-03-28 10:46:03.183 -0500 debug: sysd_msg_send(daemon/panike_sysd_if.c:2487): iked sysd msg enqueue: ike_sa_handler&lt;BR /&gt;2025-03-28 10:46:07.540 -0500 debug: pan_msg_process(daemon/panike_sysd_if.c:2849): iked rcv msg ipsec_sa_handler(14).&lt;BR /&gt;2025-03-28 10:46:07.540 -0500 [DEBG]: { 1: 1}: ikev2_initiate: child_sa created: id 24&lt;BR /&gt;2025-03-28 10:46:07.541 -0500 debug: sysd_msg_send(daemon/panike_sysd_if.c:2487): iked sysd msg enqueue: ipsec_sa_handler&lt;BR /&gt;2025-03-28 10:46:08.001 -0500 [DEBG]: { 1: }: IKEv2 retransmit, child id 0, retry cnt 1 limit 10&lt;BR /&gt;2025-03-28 10:46:08.001 -0500 [DEBG]: 10.1.1.1[500] - 10.2.2.2[500]:(nil) 1 times of 248 bytes message will be sent over socket 1024&lt;BR /&gt;2025-03-28 10:46:14.841 -0500 debug: pan_msg_process(daemon/panike_sysd_if.c:2849): iked rcv msg ike_sa_handler(13).&lt;BR /&gt;2025-03-28 10:46:14.841 -0500 debug: sysd_msg_send(daemon/panike_sysd_if.c:2487): iked sysd msg enqueue: ike_sa_handler&lt;BR /&gt;2025-03-28 10:46:18.000 -0500 [DEBG]: { 1: }: IKEv2 retransmit, child id 0, retry cnt 2 limit 10&lt;BR /&gt;2025-03-28 10:46:18.000 -0500 [DEBG]: 10.1.1.1[500] - 10.2.2.2[500]:(nil) 1 times of 248 bytes message will be sent over socket 1024&lt;BR /&gt;2025-03-28 10:46:18.052 -0500 debug: pan_msg_process(daemon/panike_sysd_if.c:2849): iked rcv msg ipsec_sa_handler(14).&lt;BR /&gt;2025-03-28 10:46:18.053 -0500 debug: sysd_msg_send(daemon/panike_sysd_if.c:2487): iked sysd msg enqueue: ipsec_sa_handler&lt;BR /&gt;2025-03-28 10:46:21.014 -0500 debug: pan_msg_process(daemon/panike_sysd_if.c:2849): iked rcv msg tunnel_cfg_handler(16).&lt;BR /&gt;2025-03-28 10:46:21.014 -0500 debug: sysd_msg_send(daemon/panike_sysd_if.c:2487): iked sysd msg enqueue: tunnel_cfg_handler&lt;BR /&gt;2025-03-28 10:46:38.000 -0500 [DEBG]: { 1: }: IKEv2 retransmit, child id 0, retry cnt 3 limit 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 20:45:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225043#M335</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2025-03-28T20:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel doesn't connect - no errors seen</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225071#M336</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/301695"&gt;@1treelanedrv&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't see anything under Monitor &amp;gt; Logs &amp;gt; System, the next step is to check if you see the packets under Monitor &amp;gt; Logs &amp;gt; Traffic.&amp;nbsp; You should see 2-way traffic or drops.&amp;nbsp; In order to see drops, you may need to Override the interzone-default rule and configure logging.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 29 Mar 2025 02:54:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225071#M336</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-03-29T02:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel doesn't connect - no errors seen</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225232#M340</link>
      <description>&lt;P&gt;Today I issued "test vpn ike-sa" at 10:24.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1treelanedrv_0-1743436576977.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66865i572ADC6F7A0968A4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1treelanedrv_0-1743436576977.png" alt="1treelanedrv_0-1743436576977.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1treelanedrv_1-1743436748067.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66866iC2080D866933724E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1treelanedrv_1-1743436748067.png" alt="1treelanedrv_1-1743436748067.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 15:59:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225232#M340</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2025-03-31T15:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel doesn't connect - no errors seen</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225235#M341</link>
      <description>&lt;P&gt;Well, I only had "logging at end" enabled for this rule. I've enabled "logging at start". Which, as you can imagine, shows the opening of the session. No two-way. I don't think they are responding.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other firewall doesn't show any logs even though its VPN shows connected after doing the test vpn ike-sa. haha&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just don't know.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm meeting with them later today. If we find the fix, I'll update this thread.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 16:36:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225235#M341</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2025-03-31T16:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel doesn't connect - no errors seen</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225237#M342</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/301695"&gt;@1treelanedrv&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Correct.&amp;nbsp; Your System and Traffic logs both confirm no response from the other side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 16:55:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225237#M342</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-03-31T16:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel doesn't connect - no errors seen</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225736#M347</link>
      <description>&lt;P&gt;Confirmed with other side that they accidentally deleted the config for my second connection. But we all know it was no accident.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 16:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-private-cloud/ipsec-tunnel-doesn-t-connect-no-errors-seen/m-p/1225736#M347</guid>
      <dc:creator>1treelanedrv</dc:creator>
      <dc:date>2025-04-04T16:59:27Z</dc:date>
    </item>
  </channel>
</rss>

