<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site-to-Site Palo Alto VPN is Failing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-palo-alto-vpn-is-failing/m-p/472726#M103239</link>
    <description>&lt;P&gt;I apologize if this is posted in the wrong message board. It is unclear to me where I should specifically be asking this type of question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured a site-to-site IPSec VPN between two Palo Alto's and they are both failing on Phase 1 and Phase 2. The local addresses are in the same IP address range and I am not able to change them. A test VPN was setup with different internal IP ranges works, but to try and make the internal ranges work, we are NATing the internal ranges to a unique NAT range.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had followed the directions from this article and double checked the configuration:&amp;nbsp;&lt;A href="https://faatech.be/palo-alto-networks-ipsec-site-to-site-with-overlapping-subnets-networks/" target="_blank" rel="nofollow noreferrer noopener"&gt;https://faatech.be/palo-alto-networks-ipsec-site-to-site-with-overlapping-subnets-networks/&lt;/A&gt;. We will also need to configure both network with additional zones traversing the tunnel, but have not done anything with that yet as we cannot get the first zone working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am happy to provide any error messages and configs if anyone needs them. Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Mon, 14 Mar 2022 02:52:02 GMT</pubDate>
    <dc:creator>sophia.legare</dc:creator>
    <dc:date>2022-03-14T02:52:02Z</dc:date>
    <item>
      <title>Site-to-Site Palo Alto VPN is Failing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-palo-alto-vpn-is-failing/m-p/472726#M103239</link>
      <description>&lt;P&gt;I apologize if this is posted in the wrong message board. It is unclear to me where I should specifically be asking this type of question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured a site-to-site IPSec VPN between two Palo Alto's and they are both failing on Phase 1 and Phase 2. The local addresses are in the same IP address range and I am not able to change them. A test VPN was setup with different internal IP ranges works, but to try and make the internal ranges work, we are NATing the internal ranges to a unique NAT range.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had followed the directions from this article and double checked the configuration:&amp;nbsp;&lt;A href="https://faatech.be/palo-alto-networks-ipsec-site-to-site-with-overlapping-subnets-networks/" target="_blank" rel="nofollow noreferrer noopener"&gt;https://faatech.be/palo-alto-networks-ipsec-site-to-site-with-overlapping-subnets-networks/&lt;/A&gt;. We will also need to configure both network with additional zones traversing the tunnel, but have not done anything with that yet as we cannot get the first zone working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am happy to provide any error messages and configs if anyone needs them. Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 02:52:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-palo-alto-vpn-is-failing/m-p/472726#M103239</guid>
      <dc:creator>sophia.legare</dc:creator>
      <dc:date>2022-03-14T02:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site Palo Alto VPN is Failing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-palo-alto-vpn-is-failing/m-p/473385#M103288</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Option 1;&lt;/P&gt;&lt;P&gt;-Use nat on both side and enter routes for nat ip adresses.&lt;/P&gt;&lt;P&gt;-I know if both side is Palo Alto you do not need to enter a Proxy id. but I am entering as 0.0.0.0/0 in both side every time (My behaveior &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; )&lt;/P&gt;&lt;P&gt;-Option 2;&lt;/P&gt;&lt;P&gt;-İf NAT is not an option and devices are directly connect to Firewall you can use PBR only for source and destionation ip addresses and ports. More specific is more accurate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope these solutions helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 20:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-palo-alto-vpn-is-failing/m-p/473385#M103288</guid>
      <dc:creator>upelister</dc:creator>
      <dc:date>2022-03-15T20:32:19Z</dc:date>
    </item>
  </channel>
</rss>

