<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues without using Proxy IDs on IPSEC tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/555107#M112756</link>
    <description>&lt;P&gt;Hi Team&lt;/P&gt;
&lt;P&gt;Any help in understanding what could have caused this issue?&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2023 16:37:27 GMT</pubDate>
    <dc:creator>UtkarshKumar</dc:creator>
    <dc:date>2023-08-24T16:37:27Z</dc:date>
    <item>
      <title>Issues without using Proxy IDs on IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/552825#M112453</link>
      <description>&lt;P&gt;We are running into issues with VPN when we chose not to use PROXY ids between two PA firewalls.&lt;/P&gt;
&lt;P&gt;We see it works fine when we add the proxy ids, but we shouldn't need to if both of them are Palo Alto, isn't it?&lt;/P&gt;
&lt;P&gt;We see phase 2 keeps failing and the tunnel would not come up.&lt;/P&gt;
&lt;P&gt;"IKE phase-2 negotiation failed when processing proxy ID. Cannot find matching phase-2 tunnel for received proxy ID..."&lt;/P&gt;
&lt;P&gt;We have already tried disabling the gateways, deleting and recreating the gateway as well as the tunnel again&amp;nbsp; - doesn't help either.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Made sure there were no stale sessions still existing.&lt;/P&gt;
&lt;P&gt;We lastly also tried to upgrade to the preferred version&amp;nbsp;&lt;SPAN&gt;10.1.10-h1 - and we still see the same behavior.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any help or suggestions are appreciated. TIA&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/226122"&gt;@Didar_Bajwa&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 23:39:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/552825#M112453</guid>
      <dc:creator>Param_Upadhyay</dc:creator>
      <dc:date>2023-08-07T23:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Issues without using Proxy IDs on IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/552935#M112466</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220048"&gt;@Param_Upadhyay&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You cut out the most important part from a troubleshooting aspect; what does that error say the received local id and received remote id are?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 13:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/552935#M112466</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-08-08T13:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Issues without using Proxy IDs on IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/552965#M112474</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; The only error we see is:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UtkarshKumar_0-1691514325858.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52601i5CFF8ED2D378AE1B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="UtkarshKumar_0-1691514325858.png" alt="UtkarshKumar_0-1691514325858.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The strange part is as soon as we put in the Proxy ID on both the PA firewall tunnel comes up correctly with no issues. If we remove the proxy Phase-2 fails and we see Local ID and Remote ID still the same. We have already deleted the IKE gateway and IPSEC tunnel as well completely but still once we try and build the tunnel without proxy Phase-2 fails with same error.&lt;BR /&gt;&lt;BR /&gt;Customer has also upgraded the software version to&amp;nbsp;&lt;SPAN&gt;10.1.10-h1.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 17:10:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/552965#M112474</guid>
      <dc:creator>UtkarshKumar</dc:creator>
      <dc:date>2023-08-08T17:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: Issues without using Proxy IDs on IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/553516#M112542</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; If you could please review this and help us here. Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 19:32:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/553516#M112542</guid>
      <dc:creator>Param_Upadhyay</dc:creator>
      <dc:date>2023-08-11T19:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Issues without using Proxy IDs on IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/553654#M112561</link>
      <description>&lt;P&gt;Any Help?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have also rebooted a couple of times but still same&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 16:39:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/553654#M112561</guid>
      <dc:creator>UtkarshKumar</dc:creator>
      <dc:date>2023-08-14T16:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issues without using Proxy IDs on IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/555107#M112756</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;
&lt;P&gt;Any help in understanding what could have caused this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 16:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/555107#M112756</guid>
      <dc:creator>UtkarshKumar</dc:creator>
      <dc:date>2023-08-24T16:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issues without using Proxy IDs on IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/555435#M112823</link>
      <description>&lt;P&gt;Could you show us the ipsec configurations of both sides? Because the screenshot you showed actually means that there are proxy IDs configured and because of that your firewall is not able to find a matching entry. If the tunnel is only built up in the direction from your customer to you, then your proxy IDs can be empty as your firewall will accept any entry (as long there is only one. If there are more then you will have issues as the tunnel changes over and over).&lt;/P&gt;</description>
      <pubDate>Sun, 27 Aug 2023 07:08:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/555435#M112823</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2023-08-27T07:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Issues without using Proxy IDs on IPSEC tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/555603#M112851</link>
      <description>&lt;P&gt;Does the P2 makes match in both FW? Can I see your configuration in both sides?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 02:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-without-using-proxy-ids-on-ipsec-tunnel/m-p/555603#M112851</guid>
      <dc:creator>CesarSanchez</dc:creator>
      <dc:date>2023-08-29T02:14:06Z</dc:date>
    </item>
  </channel>
</rss>

