<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKE phase-2 negotiation is failed as initiator, quick mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-is-failed-as-initiator-quick-mode/m-p/16132#M11779</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add to Jdelio's response, seems PA is initiator in your output. You should be checking on the responder side. Always the responder side will usually show what is failing. If you do not have access to responder IKE peer, then I would suggest to have remote side be the initiator of the tunnel and then check PA side logs to see what is failing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most common phase-2 failure is due to proxy-id mismatch. That would be first thing I would check. Also check IPSec crypto to ensure that proposals match on both sides.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Jan 2012 06:39:10 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2012-01-27T06:39:10Z</dc:date>
    <item>
      <title>IKE phase-2 negotiation is failed as initiator, quick mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-is-failed-as-initiator-quick-mode/m-p/16130#M11777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could someone clarify this error message?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IKE phase-2 negotiation is failed as initiator, quick mode. Failed SA:&amp;nbsp; 216.204.241.93[500]-216.203.80.108[500] message id:0x43D098BB. Due to&amp;nbsp; negotiation timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 14:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-is-failed-as-initiator-quick-mode/m-p/16130#M11777</guid>
      <dc:creator>LCMember1607</dc:creator>
      <dc:date>2012-01-26T14:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase-2 negotiation is failed as initiator, quick mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-is-failed-as-initiator-quick-mode/m-p/16131#M11778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This error means that Phase 2, IKE negotiation is timing out on UDP 500.&lt;/P&gt;&lt;P&gt;Now, there can be many causes, but here are a couple of things to check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Make sure that your UDP timeout is not dropping the connections before they can reply.. increasing your UDP timeout by 30 seconds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Make sure that your rules are not blocking your traffic. Check Monitor for dropped traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Check with your peer, see if they are getting any of the phase 2 communication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Past this, if you are not getting any where,&amp;nbsp; Please open up a support case by logging into support.paloaltonetworks.com or calling in at +1-866-898-9087&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 23:10:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-is-failed-as-initiator-quick-mode/m-p/16131#M11778</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-01-26T23:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase-2 negotiation is failed as initiator, quick mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-is-failed-as-initiator-quick-mode/m-p/16132#M11779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add to Jdelio's response, seems PA is initiator in your output. You should be checking on the responder side. Always the responder side will usually show what is failing. If you do not have access to responder IKE peer, then I would suggest to have remote side be the initiator of the tunnel and then check PA side logs to see what is failing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most common phase-2 failure is due to proxy-id mismatch. That would be first thing I would check. Also check IPSec crypto to ensure that proposals match on both sides.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jan 2012 06:39:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-is-failed-as-initiator-quick-mode/m-p/16132#M11779</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-01-27T06:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase-2 negotiation is failed as initiator, quick mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-is-failed-as-initiator-quick-mode/m-p/16133#M11780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Guys, Proxies it was.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jan 2012 14:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-is-failed-as-initiator-quick-mode/m-p/16133#M11780</guid>
      <dc:creator>LCMember1607</dc:creator>
      <dc:date>2012-01-27T14:40:10Z</dc:date>
    </item>
  </channel>
</rss>

