<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec Phase 1 tunnel not connecting in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-1-tunnel-not-connecting/m-p/568220#M114697</link>
    <description>&lt;P&gt;looks like an issue with either the local/peer ID, or maybe the preshared secret (or security policy)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is either of these devices behind a NAT gateway? if thats the case you'll need to enable NAT traversal and configure local and peer IDs for the device behind NAT&lt;/P&gt;
&lt;P&gt;else try to reset your PSK&lt;/P&gt;
&lt;P&gt;(also double check if both are set to the same IKE version&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also check if ipsec is allowed via security policy on both sides&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2023 14:43:38 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2023-12-04T14:43:38Z</dc:date>
    <item>
      <title>IPSec Phase 1 tunnel not connecting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-1-tunnel-not-connecting/m-p/568140#M114691</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need your support to fix a FW to FW PA IPSec Phase 1 tunnel not connecting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have checked the setting with the vendor and configuration is same at both the ends.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are the debug logs from PA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2023-11-30 14:30:40.000 +0400 [DEBG]: { 3: }: 180 bytes from 5.41.58.98[500] to 215.70.10.151[500]&lt;BR /&gt;2023-11-30 14:30:40.000 +0400 [DEBG]: 5.41.58.98[500] - 215.70.10.151[500]:(nil) 1 times of 180 bytes message will be sent over socket 1024&lt;BR /&gt;2023-11-30 14:30:40.000 +0400 [DEBG]: { 3: }: resend phase1 packet 440c0aafbf89757a:29c7baa57f364bfa, retry 1&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: processing isakmp packet&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: ===&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: 92 bytes message received from 215.70.10.151&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: chk packet 50089829:20 size 92, rcp 2, NF rc -1&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: begin decryption.&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: encryption(3des)&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: IV was saved for next processing:&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: encryption(3des)&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: with key:&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: decrypted payload by IV:&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: decrypted payload, but not trimed.&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: padding len=209&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: decrypted.&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: begin.&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: seen nptype=5(id)&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [DEBG]: { 3: }: succeed.&lt;BR /&gt;2023-11-30 14:30:40.004 +0400 [PERR]: { 3: }: 5.41.58.98[500] - 215.70.10.151[500]:(nil) few isakmp message received.&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: processing isakmp packet&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: ===&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: 92 bytes message received from 215.70.10.151&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: chk packet 50089829:20 size 92, rcp 2, NF rc -1&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: begin decryption.&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: encryption(3des)&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: IV was saved for next processing:&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: encryption(3des)&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: with key:&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: decrypted payload by IV:&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: decrypted payload, but not trimed.&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: padding len=209&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: decrypted.&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: begin.&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: seen nptype=5(id)&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [DEBG]: { 3: }: succeed.&lt;BR /&gt;2023-11-30 14:30:41.594 +0400 [PERR]: { 3: }: 5.41.58.98[500] - 215.70.10.151[500]:(nil) few isakmp message received.&lt;BR /&gt;2023-11-30 14:30:42.000 +0400 [DEBG]: { 3: }: 180 bytes from 5.41.58.98[500] to 215.70.10.151[500]&lt;BR /&gt;2023-11-30 14:30:42.000 +0400 [DEBG]: 5.41.58.98[500] - 215.70.10.151[500]:(nil) 1 times of 180 bytes message will be sent over socket 1024&lt;BR /&gt;2023-11-30 14:30:42.000 +0400 [DEBG]: { 3: }: resend phase1 packet 440c0aafbf89757a:29c7baa57f364bfa, retry 2&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: processing isakmp packet&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: ===&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: 92 bytes message received from 215.70.10.151&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: chk packet 50089829:20 size 92, rcp 2, NF rc -1&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: { 3: }: begin decryption.&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: { 3: }: encryption(3des)&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: { 3: }: IV was saved for next processing:&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: { 3: }: encryption(3des)&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: { 3: }: with key:&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: { 3: }: decrypted payload by IV:&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: { 3: }: decrypted payload, but not trimed.&lt;BR /&gt;2023-11-30 14:30:42.004 +0400 [DEBG]: { 3: }: padding len=209&lt;BR /&gt;2023-11-30 14:30:42.005 +0400 [DEBG]: { 3: }: decrypted.&lt;BR /&gt;2023-11-30 14:30:42.005 +0400 [DEBG]: { 3: }: begin.&lt;BR /&gt;2023-11-30 14:30:42.005 +0400 [DEBG]: { 3: }: seen nptype=5(id)&lt;BR /&gt;2023-11-30 14:30:42.005 +0400 [DEBG]: { 3: }: succeed.&lt;BR /&gt;2023-11-30 14:30:42.005 +0400 [PERR]: { 3: }: 5.41.58.98[500] - 215.70.10.151[500]:(nil) few isakmp message received.&lt;BR /&gt;2023-11-30 14:30:43.000 +0400 [PNTF]: { 3: }: ====&amp;gt; PHASE-1 NEGOTIATION FAILED AS RESPONDER, MAIN MODE &amp;lt;====&lt;BR /&gt;====&amp;gt; Failed SA: 5.41.58.98[500]-215.70.10.151[500] cookie:3f32b1eb6993ebe3:12554596cd819655 &amp;lt;==== Due to timeout.&lt;BR /&gt;2023-11-30 14:30:43.000 +0400 [INFO]: { 3: }: ====&amp;gt; PHASE-1 SA DELETED &amp;lt;====&lt;BR /&gt;====&amp;gt; Deleted SA: 5.41.58.98[500]-215.70.10.151[500] cookie:3f32b1eb6993ebe3:12554596cd819655 &amp;lt;====&lt;BR /&gt;2023-11-30 14:30:43.000 +0400 [DEBG]: IV freed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 04:18:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-1-tunnel-not-connecting/m-p/568140#M114691</guid>
      <dc:creator>ImtiyazKhot</dc:creator>
      <dc:date>2023-12-03T04:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Phase 1 tunnel not connecting</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-1-tunnel-not-connecting/m-p/568220#M114697</link>
      <description>&lt;P&gt;looks like an issue with either the local/peer ID, or maybe the preshared secret (or security policy)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is either of these devices behind a NAT gateway? if thats the case you'll need to enable NAT traversal and configure local and peer IDs for the device behind NAT&lt;/P&gt;
&lt;P&gt;else try to reset your PSK&lt;/P&gt;
&lt;P&gt;(also double check if both are set to the same IKE version&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also check if ipsec is allowed via security policy on both sides&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 14:43:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-1-tunnel-not-connecting/m-p/568220#M114697</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-12-04T14:43:38Z</dc:date>
    </item>
  </channel>
</rss>

