<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP] in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/1230184#M124406</link>
    <description>&lt;P&gt;Hi, Have you tried with ikev2?&lt;/P&gt;</description>
    <pubDate>Tue, 27 May 2025 14:21:49 GMT</pubDate>
    <dc:creator>JosipMartinic</dc:creator>
    <dc:date>2025-05-27T14:21:49Z</dc:date>
    <item>
      <title>Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344255#M86135</link>
      <description>&lt;P&gt;Does anyone have experience setting up an site-to-site IP Sec tunnel between a PAN firewall with a static IP address and a CradlePoint with a dynamic IP address? &amp;nbsp;I am trying to determine if there's a way to setup the IP Sec tunnel between the 2 endpoints without having to pay a 3rd party for DDNS service.&lt;/P&gt;&lt;P&gt;I tried setting the firewall peering to Dynamic, and the IKE Phase 1 exchange modes to Aggressive, but no luck.&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 03:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344255#M86135</guid>
      <dc:creator>acrxsupport-old</dc:creator>
      <dc:date>2020-08-18T03:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344272#M86138</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118857"&gt;@acrxsupport-old&lt;/a&gt;&amp;nbsp; What option have you selected under local/peer identification type? You need to select proper settings here. Also what do you see under system logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 05:58:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344272#M86138</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-08-18T05:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344332#M86157</link>
      <description>&lt;P&gt;as long as one side is static, this shouldn't be too difficult&lt;/P&gt;&lt;P&gt;the PA will need to be set as 'passive' as it won't be able to connect out to the dynamic peer (without ddns) and you'll need to use set peer identification to some fictitious FQDN or email (or the local IP of the remote peer, if said peer lives behind a NAT device)&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 09:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344332#M86157</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-08-18T09:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344343#M86158</link>
      <description>&lt;P&gt;Thanks for the responses&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;I've got Local and Remote Identities set on both, and it isn't coming up.&lt;/P&gt;&lt;P&gt;If I enable Passive Mode on the PAN, it hasn't actually responding to the IKE Phase 1 - even if I use a Static peer address instead of Dynamic. &amp;nbsp;The system logs unfortunately also don't have anything showing up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-08-18_06-43-25.png" style="width: 449px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27414iD1CCFFC0FDC3890B/image-dimensions/449x285/is-moderation-mode/true?v=v2" width="449" height="285" role="button" title="2020-08-18_06-43-25.png" alt="2020-08-18_06-43-25.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="acrxsupport-old_0-1597748127515.png" style="width: 405px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27417iB791C40FD531A219/image-dimensions/405x434/is-moderation-mode/true?v=v2" width="405" height="434" role="button" title="acrxsupport-old_0-1597748127515.png" alt="acrxsupport-old_0-1597748127515.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-08-18_06-43-47.png" style="width: 447px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27415iD656D72EF9B1D893/image-dimensions/447x335/is-moderation-mode/true?v=v2" width="447" height="335" role="button" title="2020-08-18_06-43-47.png" alt="2020-08-18_06-43-47.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-08-18_06-44-21.png" style="width: 438px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27416iA740B9EF300A57CA/image-dimensions/438x293/is-moderation-mode/true?v=v2" width="438" height="293" role="button" title="2020-08-18_06-44-21.png" alt="2020-08-18_06-44-21.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 11:00:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344343#M86158</guid>
      <dc:creator>acrxsupport-old</dc:creator>
      <dc:date>2020-08-18T11:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344344#M86159</link>
      <description>&lt;P&gt;I realized that I flipped the peering in the PAN IKE screenshot, this is corrected, but the results are the same.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 11:07:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344344#M86159</guid>
      <dc:creator>acrxsupport-old</dc:creator>
      <dc:date>2020-08-18T11:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344351#M86165</link>
      <description>&lt;P&gt;try these for more detailed debug logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; debug ike gateway &amp;lt;gw&amp;gt; on debug&lt;/P&gt;&lt;P&gt;&amp;gt; tail follow yes mp-log ikemgr.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed your local ip is 172.16x.x but you did not enable NAT-T, could you try turning that on?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2020 14:31:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344351#M86165</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-08-18T14:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344859#M86249</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;thanks for your patience. This was very helpful for troubleshooting. &amp;nbsp;It is working now with Responder Mode and NAT-T enabled, and using the matching identities.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 20:54:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344859#M86249</guid>
      <dc:creator>acrxsupport-old</dc:creator>
      <dc:date>2020-08-20T20:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344860#M86250</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118857"&gt;@acrxsupport-old&lt;/a&gt;&amp;nbsp; that's great!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 20:59:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/344860#M86250</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-08-20T20:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/530823#M109510</link>
      <description>&lt;P&gt;When using 'user FQDN (email address)' identity, is it a real email that the system checks? Or is it just a text string?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2023 05:30:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/530823#M109510</guid>
      <dc:creator>JimMcGrady</dc:creator>
      <dc:date>2023-02-13T05:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site IP Sec - PAN 220 [Static IP] to  CradlePoint [Dynamic IP]</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/1230184#M124406</link>
      <description>&lt;P&gt;Hi, Have you tried with ikev2?&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 14:21:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-ip-sec-pan-220-static-ip-to-cradlepoint-dynamic-ip/m-p/1230184#M124406</guid>
      <dc:creator>JosipMartinic</dc:creator>
      <dc:date>2025-05-27T14:21:49Z</dc:date>
    </item>
  </channel>
</rss>

