<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble setting up Proxy ID's for a S2S with a Checkpoint peer and continuous rekeys in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-setting-up-proxy-id-s-for-a-s2s-with-a-checkpoint-peer/m-p/598752#M119094</link>
    <description>&lt;P&gt;&lt;SPAN&gt;"TS remote: Proto:any, 172.20.2.160-172.20.2.175, Ports:any" refers that remote site is not using mask /24 but /28 instead.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But it is not consistent. Some Proxy IDs show "TS remote: Proto:any, 172.20.2.0-172.20.2.255, Ports:any" referring to /24 mask.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2024 12:53:28 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2024-09-25T12:53:28Z</dc:date>
    <item>
      <title>Trouble setting up Proxy ID's for a S2S with a Checkpoint peer and continuous rekeys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-setting-up-proxy-id-s-for-a-s2s-with-a-checkpoint-peer/m-p/598725#M119090</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm quite new to PA and not much firewall experience.&lt;/P&gt;
&lt;P&gt;We are having trouble with a S2S VPN with a partner who has a Checkpoint FW. The clients are on our side, the server is on their side.&lt;/P&gt;
&lt;P&gt;What I see in our logs are constant rekeys for the IKEV2 tunnel every 2-3 seconds:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT size="2"&gt;ipsec-key-expire&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;ikev2-send-p2-delete&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;ipsec-key-delete&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;ikev2-nego-child-start&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;ipsec-key-install&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;ikev2-nego-child-succ&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Proxy ID's are set up like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PID.jpg" style="width: 671px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62391i531465D3BC17F05F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PID.jpg" alt="PID.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I run this is CLI:&amp;nbsp;&lt;EM&gt;show vpn ike-sa detail gateway&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I get this output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Child SA 2035428:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Tunnel 2 TUNNEL_To_Partner:PID2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Type: ESP Resp&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;State: Mature&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Message ID: 000027BD&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Parent SN: 3948&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;SPI: BA19115F : CA352900 &amp;lt;= ESP: E485B975&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Algorithm: AES256/SHA256/DH14&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS local: Proto:any, 172.17.110.99-172.17.110.99, Ports:any&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS remote: Proto:any, 172.20.2.160-172.20.2.175, Ports:any&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Created: Sep.24 15:36:53, 12 minutes 19 seconds ago&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Expires: Sep.24 16:36:53, rekey in 37 minutes 34 seconds (2993 sec)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Child SA 2035924:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Tunnel 3 TUNNEL_To_Partner:PID3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Type: ESP Resp&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;State: Mature&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Message ID: 000028B7&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Parent SN: 3948&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;SPI: F25D7BD6 : D8D84325 &amp;lt;= ESP: 713CB68D&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Algorithm: AES256/SHA256/DH14&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS local: Proto:any, 172.17.112.0-172.17.112.255, Ports:any&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS remote: Proto:any, 172.20.2.160-172.20.2.175, Ports:any&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Created: Sep.24 15:46:46, 2 minutes 26 seconds ago&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Expires: Sep.24 16:46:46, rekey in 48 minutes 19 seconds (3045 sec)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Child SA 2036040:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Tunnel 1 TUNNEL_To_Partner:PID1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Type: ESP Resp&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;State: Expired&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Message ID: 000028F2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Parent SN: 3948&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;SPI: 845D756C : 33FE5E08&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Algorithm: AES256/SHA256/DH14&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS local: Proto:any, 10.150.0.0-10.150.7.255, Ports:any&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS remote: Proto:any, 172.20.2.0-172.20.2.255, Ports:any&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Created: Sep.24 15:49:08, 4 seconds ago&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Expires: Sep.24 16:49:08, rekey in 49 minutes 57 seconds (3001 sec)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Child SA 2036042:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Tunnel 1 TUNNEL_To_Partner:PID1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Type: ESP Resp&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;State: Mature&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Message ID: 000028F3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Parent SN: 3948&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;SPI: D04D11A8 : D1CE9B22&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Algorithm: AES256/SHA256/DH14&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS local: Proto:any, 10.150.0.0-10.150.7.255, Ports:any&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS remote: Proto:any, 172.20.2.160-172.20.2.175, Ports:any&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Created: Sep.24 15:49:10, 2 seconds ago&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Expires: Sep.24 16:49:10, rekey in 51 minutes 24 seconds (3086 sec)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Child SA 2036044:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Tunnel 1 TUNNEL_To_Partner:PID1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Type: ESP Resp&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;State: Mature&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Message ID: 000028F4&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Parent SN: 3948&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;SPI: 94F129BA : 272CD454&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Algorithm: AES256/SHA256/DH14&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS local: Proto:any, 10.150.0.0-10.150.7.255, Ports:any&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;TS remote: Proto:any, 172.20.2.0-172.20.2.255, Ports:any&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Created: Sep.24 15:49:12, 0 second ago&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;Expires: Sep.24 16:49:12, rekey in 48 minutes 27 seconds (2907 sec)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;So for PID1 I get multiple child SA's with sometimes different TS remote settings.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;Is this a problem on the peer checkpoint side? I don't have access to the config there.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 06:42:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-setting-up-proxy-id-s-for-a-s2s-with-a-checkpoint-peer/m-p/598725#M119090</guid>
      <dc:creator>Bart_Calmeyn</dc:creator>
      <dc:date>2024-09-25T06:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble setting up Proxy ID's for a S2S with a Checkpoint peer and continuous rekeys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trouble-setting-up-proxy-id-s-for-a-s2s-with-a-checkpoint-peer/m-p/598752#M119094</link>
      <description>&lt;P&gt;&lt;SPAN&gt;"TS remote: Proto:any, 172.20.2.160-172.20.2.175, Ports:any" refers that remote site is not using mask /24 but /28 instead.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But it is not consistent. Some Proxy IDs show "TS remote: Proto:any, 172.20.2.0-172.20.2.255, Ports:any" referring to /24 mask.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 12:53:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trouble-setting-up-proxy-id-s-for-a-s2s-with-a-checkpoint-peer/m-p/598752#M119094</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-09-25T12:53:28Z</dc:date>
    </item>
  </channel>
</rss>

