<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IpSec Tunnel Phase2 Red But Ike Side Green in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-phase2-red-but-ike-side-green/m-p/481660#M104191</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have several TpLink Archer Mr400 4G Router. I setup Ipsec VPN tunnel between PA-220 and them many times. But new one is not success at Phase2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase1 IKE is green so devices communicate. But Phase2 Tunnel Info is red and i can't see any tunnel when i click Tunnel Info. I have read the losg and find below things;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2022-04-19 16:50:25.878 +0300 [PNTF]: { 15: }: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS RESPONDER, (QUICK MODE) &amp;lt;====&lt;BR /&gt;====&amp;gt; Initiated SA: &lt;STRONG&gt;PaloAlto_Wan_Ip_here&lt;/STRONG&gt;[500]-&lt;U&gt;&lt;STRONG&gt;router_wan_ip_here&lt;/STRONG&gt;&lt;/U&gt;[500] message id:0xBE906F60 &amp;lt;====&lt;BR /&gt;2022-04-19 16:50:25.879 +0300 [ERR ]: { 15: }: can't find matching selector&lt;BR /&gt;2022-04-19 16:50:25.879 +0300 [PERR]: { 15: }: failed to get sainfo.&lt;BR /&gt;2022-04-19 16:50:25.879 +0300 [ERR ]: failed to pre-process packet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I double check both side PA220 and Tplink phase2 configuration and everyting is same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TPlink Archer MR400 Phase2 Profile;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tplink_ArcherMr400_phase2.PNG" style="width: 717px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40240iBBC69B0A895CE8E4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Tplink_ArcherMr400_phase2.PNG" alt="Tplink_ArcherMr400_phase2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PA220 IpSec Crypto Profile;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Phase2_ipsecCrypto.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40241i9318D19CE47F435E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Phase2_ipsecCrypto.PNG" alt="PA_Phase2_ipsecCrypto.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IpSec Tunnel Status;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Phase2.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40242i265FBACB1D5C6361/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Phase2.PNG" alt="PA_Phase2.PNG" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am stuck at this point. Any help appreciated.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2022 19:58:57 GMT</pubDate>
    <dc:creator>tsenturk</dc:creator>
    <dc:date>2022-04-21T19:58:57Z</dc:date>
    <item>
      <title>IpSec Tunnel Phase2 Red But Ike Side Green</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-phase2-red-but-ike-side-green/m-p/481660#M104191</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have several TpLink Archer Mr400 4G Router. I setup Ipsec VPN tunnel between PA-220 and them many times. But new one is not success at Phase2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase1 IKE is green so devices communicate. But Phase2 Tunnel Info is red and i can't see any tunnel when i click Tunnel Info. I have read the losg and find below things;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2022-04-19 16:50:25.878 +0300 [PNTF]: { 15: }: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS RESPONDER, (QUICK MODE) &amp;lt;====&lt;BR /&gt;====&amp;gt; Initiated SA: &lt;STRONG&gt;PaloAlto_Wan_Ip_here&lt;/STRONG&gt;[500]-&lt;U&gt;&lt;STRONG&gt;router_wan_ip_here&lt;/STRONG&gt;&lt;/U&gt;[500] message id:0xBE906F60 &amp;lt;====&lt;BR /&gt;2022-04-19 16:50:25.879 +0300 [ERR ]: { 15: }: can't find matching selector&lt;BR /&gt;2022-04-19 16:50:25.879 +0300 [PERR]: { 15: }: failed to get sainfo.&lt;BR /&gt;2022-04-19 16:50:25.879 +0300 [ERR ]: failed to pre-process packet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I double check both side PA220 and Tplink phase2 configuration and everyting is same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TPlink Archer MR400 Phase2 Profile;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tplink_ArcherMr400_phase2.PNG" style="width: 717px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40240iBBC69B0A895CE8E4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Tplink_ArcherMr400_phase2.PNG" alt="Tplink_ArcherMr400_phase2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PA220 IpSec Crypto Profile;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Phase2_ipsecCrypto.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40241i9318D19CE47F435E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Phase2_ipsecCrypto.PNG" alt="PA_Phase2_ipsecCrypto.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IpSec Tunnel Status;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA_Phase2.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40242i265FBACB1D5C6361/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA_Phase2.PNG" alt="PA_Phase2.PNG" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am stuck at this point. Any help appreciated.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 19:58:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-phase2-red-but-ike-side-green/m-p/481660#M104191</guid>
      <dc:creator>tsenturk</dc:creator>
      <dc:date>2022-04-21T19:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: IpSec Tunnel Phase2 Red But Ike Side Green</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-phase2-red-but-ike-side-green/m-p/481833#M104210</link>
      <description>&lt;P&gt;Problem resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TPLink router side "Ip Address of VPN" should be 192.168.1.0/24 instead 192.168.1.1/24&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 06:14:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-phase2-red-but-ike-side-green/m-p/481833#M104210</guid>
      <dc:creator>tsenturk</dc:creator>
      <dc:date>2022-04-22T06:14:20Z</dc:date>
    </item>
  </channel>
</rss>

