<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN cannot work between two PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552864#M112454</link>
    <description>&lt;P&gt;The routing is pointing to the tunnel interface, that should be fine.&lt;/P&gt;
&lt;P&gt;Can you provide the output for the below commands from both the firewalls (remember to remove confidential details such as IPs)&lt;BR /&gt;&amp;gt;&amp;nbsp;show vpn ike-sa detail gateway &amp;lt;gateway-name&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;show vpn ipsec-sa tunnel &amp;lt;tunnel-name&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;show vpn flow tunnel-id &amp;lt;tunnel-id-number&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure the firewalls are allowing the user traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2023 03:58:40 GMT</pubDate>
    <dc:creator>akuzhuppilly</dc:creator>
    <dc:date>2023-08-08T03:58:40Z</dc:date>
    <item>
      <title>VPN cannot work between two PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552791#M112445</link>
      <description>&lt;P&gt;Hi VPN is configured at two PA based on the below link and the two PA can ping each other, but the vpn cannot work. I tested it with below commands. Anyone can help to fix it? Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGkCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGkCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@PA-VM&amp;gt; test vpn ipsec-sa&lt;/P&gt;
&lt;P&gt;Start time: Aug.07 07:48:19&lt;BR /&gt;Initiate 2 IPSec SA.&lt;/P&gt;
&lt;P&gt;admin@PA-VM&amp;gt;&lt;BR /&gt;admin@PA-VM&amp;gt; show vpn ipsec-sa&lt;/P&gt;
&lt;P&gt;There is no IPSec SA found.&lt;/P&gt;
&lt;P&gt;admin@PA-VM&amp;gt;&lt;BR /&gt;admin@PA-VM&amp;gt; show vpn ike-sa&lt;/P&gt;
&lt;P&gt;There is no IKEv1 phase-1 SA found.&lt;/P&gt;
&lt;P&gt;There is no IKEv1 phase-2 SA found.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;IKEv2 SAs&lt;BR /&gt;Gateway ID Peer-Address Gateway Name Role SN Algorithm Established Expiration Xt Child ST&lt;BR /&gt;---------- ------------ ------------ ---- -- --------- ----------- ---------- -- ----- --&lt;BR /&gt;2 10.2.0.1 IKE-Gateway123 Init 16 PSK/ / / 5 2 INIT sent&lt;/P&gt;
&lt;P&gt;IKEv2 IPSec Child SAs&lt;BR /&gt;Gateway Name TnID Tunnel ID Parent Role SPI(in) SPI(out) MsgID ST&lt;BR /&gt;------------ ---- ------ -- ------ ---- ------- -------- ----- --&lt;BR /&gt;IKE-Gateway123 2 IPSec-Tunnel123 8 16 Init 00000000 00000000 00000000 GetSPI done&lt;BR /&gt;00000000 00000000 00000000 GetSPI done&lt;/P&gt;
&lt;P&gt;Show IKEv2 SA: Total 1 gateways found. 1 ike sa found.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 14:53:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552791#M112445</guid>
      <dc:creator>kevinospf</dc:creator>
      <dc:date>2023-08-07T14:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN cannot work between two PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552797#M112446</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306700"&gt;@kevinospf&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find more details about what is causing the failure in the system logs and the ikemgr logs (less mp-log ikemgr.log).&lt;/P&gt;
&lt;P&gt;The following KB might be helpful:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_new"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 15:26:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552797#M112446</guid>
      <dc:creator>akuzhuppilly</dc:creator>
      <dc:date>2023-08-07T15:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN cannot work between two PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552810#M112450</link>
      <description>&lt;P&gt;Thanks for your reply!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IPSect tunnel is up, but users behind PA cannot ping user in other side. I got the below result after entering command "show routing route"&lt;/P&gt;
&lt;P&gt;The nexthop is "0.0.0.0". I checked virtual router configuration. I did not find something wrong. Is this security issue or routing issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kevinospf_0-1691434685393.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52579iFDB47229AA1461CF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="kevinospf_0-1691434685393.png" alt="kevinospf_0-1691434685393.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 19:00:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552810#M112450</guid>
      <dc:creator>kevinospf</dc:creator>
      <dc:date>2023-08-07T19:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN cannot work between two PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552864#M112454</link>
      <description>&lt;P&gt;The routing is pointing to the tunnel interface, that should be fine.&lt;/P&gt;
&lt;P&gt;Can you provide the output for the below commands from both the firewalls (remember to remove confidential details such as IPs)&lt;BR /&gt;&amp;gt;&amp;nbsp;show vpn ike-sa detail gateway &amp;lt;gateway-name&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;show vpn ipsec-sa tunnel &amp;lt;tunnel-name&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;show vpn flow tunnel-id &amp;lt;tunnel-id-number&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make sure the firewalls are allowing the user traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 03:58:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552864#M112454</guid>
      <dc:creator>akuzhuppilly</dc:creator>
      <dc:date>2023-08-08T03:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN cannot work between two PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552949#M112470</link>
      <description>&lt;P&gt;the issue is resolved due to your question. Thanks for your questions&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 14:14:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-cannot-work-between-two-pa/m-p/552949#M112470</guid>
      <dc:creator>kevinospf</dc:creator>
      <dc:date>2023-08-08T14:14:18Z</dc:date>
    </item>
  </channel>
</rss>

