<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Site to site IPSec Tunnel not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484881#M104467</link>
    <description>&lt;P&gt;Hi Pavel,&lt;BR /&gt;&lt;BR /&gt;I'm able to capture the traffic now. Many thanks again!&lt;/P&gt;</description>
    <pubDate>Wed, 04 May 2022 14:03:09 GMT</pubDate>
    <dc:creator>smshafek</dc:creator>
    <dc:date>2022-05-04T14:03:09Z</dc:date>
    <item>
      <title>VPN Site to site IPSec Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484810#M104458</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I've configured a VPN Tunnel from a PA220 to a PA200. They are able to ping each other but I don't see any ESP Packets in Wireshark. What should I do to get the packets to be encapsulated?&lt;BR /&gt;&lt;BR /&gt;Many thanks in advanced.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 12:41:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484810#M104458</guid>
      <dc:creator>smshafek</dc:creator>
      <dc:date>2022-05-04T12:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to site IPSec Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484842#M104459</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/217724"&gt;@smshafek&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you see the ipsec tunnel up with packets being encapsulated/decapsulated and routing is set correctly to go through tunnel, there is no other extra step to do for traffic to be encapsulated. Could you please confirm how did you take packet capture? What interface did you use to capture traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 13:14:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484842#M104459</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-05-04T13:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to site IPSec Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484870#M104464</link>
      <description>&lt;P&gt;Hi Pavel,&lt;BR /&gt;&lt;BR /&gt;I'm capturing traffic on the two hosts. One connected to the LAN of PA220 and the other to the LAN of PA200.&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 13:37:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484870#M104464</guid>
      <dc:creator>smshafek</dc:creator>
      <dc:date>2022-05-04T13:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to site IPSec Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484878#M104466</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/217724"&gt;@smshafek&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ipsec tunnel between two PA Firewalls does not provide host to host end to end encryption. You will only see ESP traffic on interfaces that are used to build ipsec tunnel. This is typically WAN interface of the Firewall. You can refer to this in ike gateway configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to do further verification of the tunnel configuration, I would recommend to take a look into this KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTbCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTbCAK&lt;/A&gt;&amp;nbsp;Please refer to the section: "Tunnel is up but the traffic is not passing". In the output from: "show vpn flow tunnel-id &amp;lt;tunnel id&amp;gt;" the inner interface is where naked traffic comes in and outer interface is where you will only see ESP traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 13:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484878#M104466</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-05-04T13:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to site IPSec Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484881#M104467</link>
      <description>&lt;P&gt;Hi Pavel,&lt;BR /&gt;&lt;BR /&gt;I'm able to capture the traffic now. Many thanks again!&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 14:03:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-ipsec-tunnel-not-working/m-p/484881#M104467</guid>
      <dc:creator>smshafek</dc:creator>
      <dc:date>2022-05-04T14:03:09Z</dc:date>
    </item>
  </channel>
</rss>

