<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/513338#M106643</link>
    <description>&lt;P&gt;hi, is fqdn must be in format&amp;nbsp;&lt;SPAN&gt;Name.Domain.Com or i can put IP address ??&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Aug 2022 07:02:15 GMT</pubDate>
    <dc:creator>mhm_ameen</dc:creator>
    <dc:date>2022-08-30T07:02:15Z</dc:date>
    <item>
      <title>IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217511#M62924</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an IPSec tunnel up and running with no issues using a staic IP for the peer in the IKE gateway, but it won't work when&amp;nbsp; I set it to Dynamic and use the FQDN (hostname).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I ping from the command line it translates to the correct IP, and replies with no issue, but the tunnel will not come up.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there some FQDN or DNS settings I need to change or is there a way to verify it works? Or am I putting the FQDN in using an incorrect format? ( name.domain.com )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 13:19:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217511#M62924</guid>
      <dc:creator>StephenJennings</dc:creator>
      <dc:date>2018-06-12T13:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217528#M62927</link>
      <description>&lt;P&gt;Hi Stephen,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has "local/peer identification" been configured on the peer device with the matching confgiuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What error messages do you see in the system logs when attempting to use FQDN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 13:42:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217528#M62927</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-12T13:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217540#M62930</link>
      <description>&lt;P&gt;Hi, thanks for helping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other side is configured and working when I use the staic IP, but not when I use FQDN. That's the only change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the logs say "ikev2 ike sa negotiation is failed as initiator non-rekey"&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 14:23:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217540#M62930</guid>
      <dc:creator>StephenJennings</dc:creator>
      <dc:date>2018-06-12T14:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217542#M62931</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say you "use FQDN" please confirm if you you have an FQDN in the "local/peer identifdication"? of the IKE gateway? If yes: local/peer identification will need to be configured on peer end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it does not work after configuring this, could you ascertain detailed logs from:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;tail follow yes mp-log ikemgr.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 14:27:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217542#M62931</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-12T14:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217543#M62932</link>
      <description>&lt;P&gt;You do not mention it specifically in your question, but take note - only one side of an IPSEC tunnel can be dynamic.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 14:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217543#M62932</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-06-12T14:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217548#M62935</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91132"&gt;@StephenJennings&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I think your issue is what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;is getting at. When you configure the initiator or the responder to use FQDN in the peer identification it really doesn't matter what you put here as long as it matches. I can configure the Peer Identification as FQDN with the value 'SEN19' on my responder as long as my initiator has the local identification as FQDN and matches 'SEN19'. If these values don't match this will fail. The FQDN you enter doesn't matter at all, as long as the configured FQDN value matches on either end it doesn't need to resolve to anything or be the actual hostname of the device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 15:23:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217548#M62935</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-12T15:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217553#M62939</link>
      <description>&lt;P&gt;Hey, thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the IKE Gateway I've selcted Peer Type Dynamic, and the Peer Identification as FQDN (Houstname) Name.Domain.Com.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there somewhere else I need to enter the FQDN on the Palo Alto, or do I need to make a change on the peer device?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 15:46:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217553#M62939</guid>
      <dc:creator>StephenJennings</dc:creator>
      <dc:date>2018-06-12T15:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217587#M62942</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91132"&gt;@StephenJennings&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The peer device needs to have it's local identification set as FQDN as Name.Domain.Com.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 18:31:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217587#M62942</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-12T18:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217589#M62944</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91132"&gt;@StephenJennings&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Essentially how it works is&amp;nbsp;one will have the Local Identification set as FQDN with whatever FQDN value you are setting, then the peer to that would need the&amp;nbsp;&lt;EM&gt;Peer Identification&lt;/EM&gt; set as FQDN with whatever FQDN value you setup above. These values&amp;nbsp;&lt;STRONG&gt;must&lt;/STRONG&gt; match.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 18:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217589#M62944</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-12T18:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217672#M62952</link>
      <description>&lt;P&gt;Thanks, that was it.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 06:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/217672#M62952</guid>
      <dc:creator>StephenJennings</dc:creator>
      <dc:date>2018-06-13T06:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel Works with Static Peer, but not with Dynamic FQDN Peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/513338#M106643</link>
      <description>&lt;P&gt;hi, is fqdn must be in format&amp;nbsp;&lt;SPAN&gt;Name.Domain.Com or i can put IP address ??&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 07:02:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-works-with-static-peer-but-not-with-dynamic-fqdn/m-p/513338#M106643</guid>
      <dc:creator>mhm_ameen</dc:creator>
      <dc:date>2022-08-30T07:02:15Z</dc:date>
    </item>
  </channel>
</rss>

