<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cannot find matching phase-2 tunnel for received proxy ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/564356#M114196</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I'm experiencing the same issue:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2023/11/01 17:06:47 info vpn Foresi ike-neg 0 IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 172.24.150.146/32 type IPv4_address protocol 0 port 0, received remote id: 209.73.202.16/28 type IPv4_subnet protocol 0 port 0.&lt;BR /&gt;&lt;/SPAN&gt;I wanted to confirm the proxy id number on PA FW and the ASA FW, however I found that the Cisco ASA FW doesn't have any proxy id numbers. Is there any other way to confirm proxy ids on ASA FW. In my scenario, there are multiple proxy ids for individual IPs(local and remote) on PA and on ASA there are only 2 ip subnets in proxy&lt;/P&gt;</description>
    <pubDate>Fri, 03 Nov 2023 18:51:41 GMT</pubDate>
    <dc:creator>morahman</dc:creator>
    <dc:date>2023-11-03T18:51:41Z</dc:date>
    <item>
      <title>cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530545#M109477</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a site to site VPN setup between our PALO ALTO and a firewall of our customer that was allowing one IP. On the ipsec tunnel sec proxy-id allow local (172.18.23.61/32)&amp;nbsp;and remote&amp;nbsp;(172.21.88.191/32)&amp;nbsp;&lt;SPAN&gt;. When we made this the VPN is enabled, but we are seeing the following error from the external site&amp;nbsp;&lt;/SPAN&gt;trying&lt;SPAN&gt;&amp;nbsp;to access these IP's.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;Error&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;( description contains 'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 172.18.23.61/32 type IPv4_address protocol 1 port 0, received remote id: 172.21.88.191/32 type IPv4_address protocol 1 port 0.' )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For some reason now the connection does not see a matching encryption? Any ideas where to pinpoint this issue? I checked our crypto setting to make sure they match on the other end. The customer is using a cisco firewall. I had set no-pfs on the DH-Group. the tunnel is UP but the ping or any service on cisco firewall can be done.&lt;/P&gt;
&lt;P&gt;Any advise please??&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 20:18:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530545#M109477</guid>
      <dc:creator>a.mboukam</dc:creator>
      <dc:date>2023-02-09T20:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530551#M109479</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272928"&gt;@a.mboukam&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The encryption is fine.&amp;nbsp; The error is stating that the Proxy IDs don't match.&amp;nbsp; Best practice is to match Proxy IDs exactly on both sides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 21:00:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530551#M109479</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-02-09T21:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530660#M109486</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;well received. I will fix that and revert.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I initiate the traffic behind our Palo alto to the remote side, I have this error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;( description contains 'IKE phase-1 negotiation is failed as initiator, main mode. Failed SA: 129.0.25.116[500]-41.205.83.218[500] cookie:58cb247a9c9db2d8:0000000000000000. Due to timeout.' )&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when I initiate the traffic on remote site to our Palo Alto, Phase 1 and 2 work well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please can I have some advise about this.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 09:52:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530660#M109486</guid>
      <dc:creator>a.mboukam</dc:creator>
      <dc:date>2023-02-10T09:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530692#M109488</link>
      <description>&lt;P&gt;Remote side is also Palo?&lt;/P&gt;
&lt;P&gt;Then just leave ProxyID empty and Palo will send over 0.0.0.0/0&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo does not use ProxyID for traffic routing. It is just to make remote peer happy if remote peer is using policy based VPN and encryption domains.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 14:55:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530692#M109488</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-10T14:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530693#M109489</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272928"&gt;@a.mboukam&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a tough one.&amp;nbsp; If the tunnel comes up, then the algorithms are fine and connectivity is fine.&amp;nbsp; However, initial connectivity to the remote end fails (timeout = no response).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;As&amp;nbsp; mentioned below, make sure the Proxy IDs match on both sides.&lt;/LI&gt;
&lt;LI&gt;Check to see if your NGFW is blocking the initial outbound IKE packets.&amp;nbsp; You may have a rule allowing inbound, but not outbound.&amp;nbsp; You should see the packets in the traffic log.&lt;/LI&gt;
&lt;LI&gt;Check to see if the remote side firewall is blocking the initial IPsec inbound packets.&lt;/LI&gt;
&lt;LI&gt;Check to see if the remote device has initiator only or originate only in the IPsec configuration.&lt;/LI&gt;
&lt;LI&gt;If you have ECMP, check the packets are going out the correct interface (Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt; !).&lt;/LI&gt;
&lt;LI&gt;Check to see if the NGFW is blocking it because of a LAND attack -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGbCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGbCAK&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Check for something else?&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 15:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530693#M109489</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-02-14T15:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530694#M109490</link>
      <description>&lt;P&gt;One thing to add to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;is if you have ECMP and multiple ISPs you need to have static route towards peer IP to make sure it takes correct path.&lt;/P&gt;
&lt;P&gt;Otherwise remote side sees your incoming traffic from IP it does not have IKE configuration for.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 15:03:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530694#M109490</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-10T15:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530698#M109493</link>
      <description>&lt;P&gt;Remote side is a CISCO ASA Firewall&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 16:09:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530698#M109493</guid>
      <dc:creator>a.mboukam</dc:creator>
      <dc:date>2023-02-10T16:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530699#M109494</link>
      <description>&lt;P&gt;With ASA as peer you need to match ProxyID on Palo with encryption domains on ASA.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 16:21:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/530699#M109494</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-02-10T16:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/531071#M109521</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Sorry&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp; I forgot to update this but thank you for the information, I found out what the encryption domain/proxy id where. Thank you for responding and sorry about.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 12:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/531071#M109521</guid>
      <dc:creator>a.mboukam</dc:creator>
      <dc:date>2023-02-14T12:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/531075#M109522</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Sorry &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;I forgot to update this but thank you for the information.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I found out what the encryption domain/proxy id where and&amp;nbsp;the remote side firewall was blocking the initial IPsec inbound packets.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you for responding and sorry about.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 12:45:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/531075#M109522</guid>
      <dc:creator>a.mboukam</dc:creator>
      <dc:date>2023-02-14T12:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/564356#M114196</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I'm experiencing the same issue:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2023/11/01 17:06:47 info vpn Foresi ike-neg 0 IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 172.24.150.146/32 type IPv4_address protocol 0 port 0, received remote id: 209.73.202.16/28 type IPv4_subnet protocol 0 port 0.&lt;BR /&gt;&lt;/SPAN&gt;I wanted to confirm the proxy id number on PA FW and the ASA FW, however I found that the Cisco ASA FW doesn't have any proxy id numbers. Is there any other way to confirm proxy ids on ASA FW. In my scenario, there are multiple proxy ids for individual IPs(local and remote) on PA and on ASA there are only 2 ip subnets in proxy&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 18:51:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/564356#M114196</guid>
      <dc:creator>morahman</dc:creator>
      <dc:date>2023-11-03T18:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/564364#M114199</link>
      <description>&lt;P&gt;Check if Palo has ProxyID with following settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;local - 172.24.150.146/32 &lt;BR /&gt;remote - 209.73.202.16/28&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 19:59:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/564364#M114199</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-03T19:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/564532#M114233</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Palo does not have the&amp;nbsp;&lt;SPAN&gt;ProxyID with following settings:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;local - 172.24.150.146/32&lt;BR /&gt;remote - 209.73.202.16/28&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Palo has all proxy ids with local and remote IP as a IPv4 only NO subnet. Here are the proxy IDs:&lt;/P&gt;
&lt;P&gt;local- 172.24.150.146&lt;/P&gt;
&lt;P&gt;remote-&amp;nbsp;&lt;SPAN&gt;209.73.202.19&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;remote-&amp;nbsp;209.73.202.24&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;remote-&amp;nbsp;209.73.202.20&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;remote-&amp;nbsp;209.73.202.25&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;remote-&amp;nbsp;209.73.202.21&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;remote-&amp;nbsp;209.73.202.22&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;remote-&amp;nbsp;209.73.202.23&lt;BR /&gt;Note: There is no Proxy ID with&amp;nbsp;local- 172.24.150.146 remote - 209.73.202.16&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 16:20:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/564532#M114233</guid>
      <dc:creator>morahman</dc:creator>
      <dc:date>2023-11-06T16:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find matching phase-2 tunnel for received proxy ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/564533#M114234</link>
      <description>&lt;P&gt;You get those errors because encryption domain at other side is configured with&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;remote - 172.24.150.146/32&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;local - 209.73.202.16/28&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So you need to match it on palo side as&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;local - 172.24.150.146/32&lt;BR /&gt;remote - 209.73.202.16/28&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 16:24:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-matching-phase-2-tunnel-for-received-proxy-id/m-p/564533#M114234</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-06T16:24:12Z</dc:date>
    </item>
  </channel>
</rss>

