<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto troubleshooting tool for IPsec in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/453984#M101410</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;To check routing click the Networking tab at the top -&amp;gt;Virtual routers -&amp;gt; More Runtime Stats&lt;/P&gt;
&lt;P&gt;Then look for a subnet that is on the Cisco side of the tunnel, then make sure it points to the tunnel.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 17 Dec 2021 16:55:36 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2021-12-17T16:55:36Z</dc:date>
    <item>
      <title>Palo Alto troubleshooting tool for IPsec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/453573#M101370</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I established an Ipsec tunnel (policy based) between palo Alto and Cisco FW.&lt;/P&gt;&lt;P&gt;phase 1 &amp;amp; phase 2 are up and running but trying to transfer data, fail.&lt;/P&gt;&lt;P&gt;Capture packet (merge recieved and transmit) shown&lt;/P&gt;&lt;P&gt;Source : SYN&lt;/P&gt;&lt;P&gt;Dest : SYN ACK&lt;/P&gt;&lt;P&gt;And then Dest :&amp;nbsp; retransmit SYN ACK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this capture is within transmit pcap, this mean the re transmission packet have been forwarded&amp;nbsp; into the IPSEC Tunnel (egress interface) ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="transmit.png" style="width: 970px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38177i8F1091BC49D214CA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="transmit.png" alt="transmit.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Previoulsy, I was working with Checkpoint and able to use command line FW MONITOR to know if my packet was forward/encrypted to the tunnel. (this mean problem is located on FW itself or after the FW.&lt;/P&gt;&lt;P&gt;Is it a tool that permitting to know if this SYN ACK packet is forwarded into Interface tunnel or not ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 08:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/453573#M101370</guid>
      <dc:creator>didier.bonato</dc:creator>
      <dc:date>2021-12-16T08:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto troubleshooting tool for IPsec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/453788#M101390</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check the traffic logs to see why the traffic is getting blocked. Before this make sure you enable logging on your security policies. This should tell you where and why the traffic is getting blocked.&lt;/P&gt;
&lt;P&gt;Security policy basics:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClWZCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClWZCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Could also be routing, make sure you put the destination subnet into your virtual router and point the destination at the tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 22:29:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/453788#M101390</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-16T22:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto troubleshooting tool for IPsec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/453886#M101396</link>
      <description>&lt;P&gt;Thanks for your reply,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, I don't have traffic blocked in logs (allowed but aged out), and the tcp handshake start with SYN and ACK, this mean not blocked.&lt;/P&gt;&lt;P&gt;I was suspecting routing issue, that's why (even the route is set as static route) I would like to know how to be sure, this ACK reply has been properly "pushed" to my tunnel interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 07:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/453886#M101396</guid>
      <dc:creator>didier.bonato</dc:creator>
      <dc:date>2021-12-17T07:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto troubleshooting tool for IPsec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/453984#M101410</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;To check routing click the Networking tab at the top -&amp;gt;Virtual routers -&amp;gt; More Runtime Stats&lt;/P&gt;
&lt;P&gt;Then look for a subnet that is on the Cisco side of the tunnel, then make sure it points to the tunnel.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 16:55:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/453984#M101410</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-17T16:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto troubleshooting tool for IPsec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/454016#M101411</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Also here are some additional articles that have additional information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clh5CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clh5CAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 19:10:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/454016#M101411</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-17T19:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto troubleshooting tool for IPsec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/454137#M101432</link>
      <description>&lt;P&gt;I had the same issue with failing Data transfer, however i found this discussion and thanks for your helpful articles links, I manage my issue, waiting more useful discussion about&amp;nbsp;&lt;SPAN&gt;Ipsec tunnel.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Dec 2021 20:07:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/454137#M101432</guid>
      <dc:creator>KarD5d</dc:creator>
      <dc:date>2021-12-18T20:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto troubleshooting tool for IPsec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/454473#M101468</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Glad you found it useful. Always feel free to post any questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 20:53:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-troubleshooting-tool-for-ipsec/m-p/454473#M101468</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-20T20:53:26Z</dc:date>
    </item>
  </channel>
</rss>

