<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC s2s VPN between VM-50 and PA-3220 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-vm-50-and-pa-3220/m-p/485466#M104529</link>
    <description>&lt;P&gt;To add more info:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Outside interface is receiving DHCP from a CradlePoint on a Verizon cellular connection&lt;/LI&gt;&lt;LI&gt;ESXi version is 6.7&lt;/LI&gt;&lt;LI&gt;PAN OS version is 10.1.4&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Fri, 06 May 2022 16:08:48 GMT</pubDate>
    <dc:creator>popeja</dc:creator>
    <dc:date>2022-05-06T16:08:48Z</dc:date>
    <item>
      <title>IPSEC s2s VPN between VM-50 and PA-3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-vm-50-and-pa-3220/m-p/485452#M104525</link>
      <description>&lt;P&gt;We've done plenty of s2s IPSEC VPN tunnels between our DC firewalls and branch offices. I have a new branch office which we are configuring the same way as the others, yet the IPSEC VPN is not operating as expected. The tunnel is showing as up and the IKE Phase 1 &amp;amp; 2 are successful. However, on both firewalls, when I go into Tunnel Info all I'm showing is packets &amp;amp; bytes being encapsulated with the number incrementing but the decap column stays at 0.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone experienced this issue and what have you done to resolve? I've confirmed my configuration looks good, I've rebooted the ESXi host, and rebooted the firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 15:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-vm-50-and-pa-3220/m-p/485452#M104525</guid>
      <dc:creator>popeja</dc:creator>
      <dc:date>2022-05-06T15:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC s2s VPN between VM-50 and PA-3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-vm-50-and-pa-3220/m-p/485455#M104526</link>
      <description>&lt;P&gt;Hi Mate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;you would need to check the filtered global counters.. Good article on same below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUyCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUyCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;MTU, replay attack issue or possible environmental issue with the esxi host or networking i suspect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 15:34:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-vm-50-and-pa-3220/m-p/485455#M104526</guid>
      <dc:creator>rdonohoe23</dc:creator>
      <dc:date>2022-05-06T15:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC s2s VPN between VM-50 and PA-3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-vm-50-and-pa-3220/m-p/485462#M104528</link>
      <description>&lt;P&gt;Thanks for that article. I did forget to mention that I tried enabled replay protection on both ends and also disabling replay protection on both ends with no success and still getting the&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;I&gt;flow_tunnel_decap_err.&lt;/I&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a case open with TAC on this and will probably wait for them to decrypt the IKE &amp;amp; ESP traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 16:06:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-vm-50-and-pa-3220/m-p/485462#M104528</guid>
      <dc:creator>popeja</dc:creator>
      <dc:date>2022-05-06T16:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC s2s VPN between VM-50 and PA-3220</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-vm-50-and-pa-3220/m-p/485466#M104529</link>
      <description>&lt;P&gt;To add more info:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Outside interface is receiving DHCP from a CradlePoint on a Verizon cellular connection&lt;/LI&gt;&lt;LI&gt;ESXi version is 6.7&lt;/LI&gt;&lt;LI&gt;PAN OS version is 10.1.4&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 06 May 2022 16:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-vm-50-and-pa-3220/m-p/485466#M104529</guid>
      <dc:creator>popeja</dc:creator>
      <dc:date>2022-05-06T16:08:48Z</dc:date>
    </item>
  </channel>
</rss>

