<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LSVPN Satellite fails to authenticate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-fails-to-authenticate/m-p/543102#M111218</link>
    <description>&lt;P&gt;Another vote for regular IPSec tunnels.&lt;/P&gt;
&lt;P&gt;Satellites are more hassle and no real benefit.&lt;/P&gt;
&lt;P&gt;Even with more tunnels just export out VPN setup in set commands to avoid clicking through all in GUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 May 2023 20:39:22 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-05-23T20:39:22Z</dc:date>
    <item>
      <title>LSVPN Satellite fails to authenticate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-fails-to-authenticate/m-p/543030#M111205</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;I'm struggling to setup a (not so) large scale VPN solution with one PA-820 ha pair and three PA-410 satellites. I'm using local CA in PA820. At some point I had some success - portal connection succeeded and certificates were issued to satellite, however gateway connections didn't worked. Then I realized that I leaved local CA lifetime to default 365 days, which is not acceptable for a CA, so I made a renew of CA certificate. From that point on I'm in a series of all kind of certificate and authentication errors. I even factory erased PA-410 two times, deleted and recreated CA, Portal(s) Gateway(s) to no success.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My current problem is that LSVPN portal does not recognize satellite. It says "Fail to find device from config". I checked several times portal config, deleted and recreated it, added again satellite's serial numbers using copy/paste from satellite dashboard page - nothing helped! I'll be grateful if someone points me where to look for cause or is there some CLI command which could help me to debug this or to clear some certificate or cookie cache so I can start over from clean config. Here is the error I see in the monitor:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GeorgeAPH_0-1684838429150.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50296iAE69C6ACC96617C3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GeorgeAPH_0-1684838429150.png" alt="GeorgeAPH_0-1684838429150.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Versions of both firewalls are 10.1.x (the last number differs, but I don't think it's a problem)&lt;/P&gt;
&lt;P&gt;regards, George&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 10:59:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-fails-to-authenticate/m-p/543030#M111205</guid>
      <dc:creator>GeorgeAPH</dc:creator>
      <dc:date>2023-05-23T10:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Satellite fails to authenticate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-fails-to-authenticate/m-p/543069#M111211</link>
      <description>&lt;P&gt;Have you considered setting up regular dynamic ipsec tunnels? They're a little more work, but since you have very few firewalls that should not be a biggie, but it will be so much easier to troubleshoot since you can rely on actual logs (and debug commands) that tell you what is going on vs the globalprotect version&lt;/P&gt;
&lt;P&gt;You'll also have more control over which encryption is used etc...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 16:11:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-fails-to-authenticate/m-p/543069#M111211</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-05-23T16:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Satellite fails to authenticate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-fails-to-authenticate/m-p/543075#M111214</link>
      <description>&lt;P&gt;Your proposal seems more than reasonable now, after spending so much time with something which is supposed to be more easy and &lt;SPAN&gt;straightforward&lt;/SPAN&gt;, being native to Palo Alto.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 16:29:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-fails-to-authenticate/m-p/543075#M111214</guid>
      <dc:creator>GeorgeAPH</dc:creator>
      <dc:date>2023-05-23T16:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Satellite fails to authenticate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-fails-to-authenticate/m-p/543102#M111218</link>
      <description>&lt;P&gt;Another vote for regular IPSec tunnels.&lt;/P&gt;
&lt;P&gt;Satellites are more hassle and no real benefit.&lt;/P&gt;
&lt;P&gt;Even with more tunnels just export out VPN setup in set commands to avoid clicking through all in GUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2023 20:39:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-satellite-fails-to-authenticate/m-p/543102#M111218</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-05-23T20:39:22Z</dc:date>
    </item>
  </channel>
</rss>

