<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Simple IPsec tunnel interfaces not passing MAC address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545659#M111576</link>
    <description>&lt;P&gt;I've got a ticket open with support.&amp;nbsp; Hopefully I'll get an answer.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jun 2023 21:45:43 GMT</pubDate>
    <dc:creator>danoman2</dc:creator>
    <dc:date>2023-06-12T21:45:43Z</dc:date>
    <item>
      <title>Simple IPsec tunnel interfaces not passing MAC address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545648#M111570</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've got a simple site to site IPsec tunnel in non production that I'm having a problem with.&amp;nbsp; Currently I have the mgmt interface up.&amp;nbsp; I also have my trust/untrust interfaces connected to a Cisco switch on the appropriate VLAN's for the subs I have programed on my PA-440.&amp;nbsp; For some odd reason, I cannot see the MAC addresses of the interfaces of the Trust/Untrust int's on my cisco switch.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What should I be looking at to clear this up?&amp;nbsp; What would you like to see?&amp;nbsp; Switch interface settings, Firewall interface settings?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just looking for a place to start looking.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 19:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545648#M111570</guid>
      <dc:creator>danoman2</dc:creator>
      <dc:date>2023-06-12T19:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IPsec tunnel interfaces not passing MAC address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545659#M111576</link>
      <description>&lt;P&gt;I've got a ticket open with support.&amp;nbsp; Hopefully I'll get an answer.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 21:45:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545659#M111576</guid>
      <dc:creator>danoman2</dc:creator>
      <dc:date>2023-06-12T21:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IPsec tunnel interfaces not passing MAC address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545772#M111590</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133096"&gt;@danoman2&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Slightly confused on what your question is. You mention an IPSec tunnel and issues with that, but your question seems to center around the MAC address of your firewall's interfaces not presenting on your switch properly. I'm going to go with the MAC address question since that appears to be what you're asking, and that your trust/untrust interfaces are physical interfaces on the device in question.&lt;/P&gt;
&lt;P&gt;In the event that this isn't correct or otherwise isn't the entirety of your question, you might want to expand on things a bit more. Seems like you started with one question/problem, but we quickly got sidetracked to a completely different issue from how I'm interpreting what I read.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This can happen on the switch if you simply haven't attempted to reach the interface address. Log into your switch and just ping the interface address (this may fail depending on your interface management profile, don't worry about that) and then look at your table again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 14:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545772#M111590</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-06-13T14:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IPsec tunnel interfaces not passing MAC address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545816#M111595</link>
      <description>&lt;P&gt;Sorry about the confusion.&amp;nbsp; I see the MAC's now after ping from my L2 switch.&amp;nbsp; Now on to my tunnel issue.&amp;nbsp; I'm getting the following error on the system monitor.&amp;nbsp; [ike-gw:4] unauthenticated NO_PROPOSAL_CHOSEN received, you may need to check IKE settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll be checking those settings next.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 16:00:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545816#M111595</guid>
      <dc:creator>danoman2</dc:creator>
      <dc:date>2023-06-13T16:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: Simple IPsec tunnel interfaces not passing MAC address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545819#M111597</link>
      <description>&lt;P&gt;Also getting&lt;/P&gt;
&lt;P&gt;retransmission count exceeded the limit&lt;/P&gt;
&lt;P&gt;"Deleting a possible stale IKEv2 child SA SPI:xxxxxxxxxxxxxxxxxxx&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 16:24:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/simple-ipsec-tunnel-interfaces-not-passing-mac-address/m-p/545819#M111597</guid>
      <dc:creator>danoman2</dc:creator>
      <dc:date>2023-06-13T16:24:35Z</dc:date>
    </item>
  </channel>
</rss>

