<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Validation of the PAN VPN, SSID, and PEAP-TEAP Protocols in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/validation-of-the-pan-vpn-ssid-and-peap-teap-protocols/m-p/1257522#M126656</link>
    <description>&lt;P&gt;Hi Team&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got a question :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;During a previous session with end user, it was determined that, following the migration from PEAP to TEAP on the metropolitan area’s wireless network, 802.1X authentications fail to complete correctly when traversing the site-to-site VPN between a branch and the corporate headquarters.&lt;BR /&gt;From a technical standpoint, the following was observed:&lt;BR /&gt;• The authentication process starts correctly, but the session is not completed and times out in Cisco ISE.&lt;BR /&gt;• The access points are able to send requests to the NAC; however, a complete response is not received.&lt;BR /&gt;• At the corporate headquarters (without going through the VPN), behavior is normal.&lt;BR /&gt;Based on the above, and considering that:&lt;BR /&gt;• TEAP introduces greater encapsulation and larger packet sizes compared to PEAP&lt;BR /&gt;• The IPsec VPN adds additional overhead&lt;BR /&gt;The primary hypothesis is a possible fragmentation or MTU issue in the VPN tunnel, which would be preventing the EAP exchange from completing correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;by any chance that you have a case similar to this one in order for me to solve the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is my action plan&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Agreed-Upon Testing Plan&lt;BR /&gt;To validate this hypothesis, it was agreed to conduct controlled tests during a low-impact window, including the following activities:&lt;BR /&gt;1. Validation of the actual MTU on the path&lt;BR /&gt;o Connectivity tests with the DF flag to identify the maximum size without fragmentation.&lt;BR /&gt;2. Controlled adjustment of the MTU in the VPN tunnel&lt;BR /&gt;o Reduce the MTU to a reference value (e.g., 1360) for testing.&lt;BR /&gt;3. Conduct authentication tests&lt;BR /&gt;o Verify whether the TEAP process completes successfully after the adjustment.&lt;BR /&gt;4. Monitor and capture traffic&lt;BR /&gt;o Review behavior at the firewall and NAC levels to confirm whether symptoms of fragmentation or truncated sessions disappear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any kind of help would be highly cherished&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jun 2026 14:04:40 GMT</pubDate>
    <dc:creator>F.Pinar</dc:creator>
    <dc:date>2026-06-26T14:04:40Z</dc:date>
    <item>
      <title>Validation of the PAN VPN, SSID, and PEAP-TEAP Protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/validation-of-the-pan-vpn-ssid-and-peap-teap-protocols/m-p/1257522#M126656</link>
      <description>&lt;P&gt;Hi Team&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got a question :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;During a previous session with end user, it was determined that, following the migration from PEAP to TEAP on the metropolitan area’s wireless network, 802.1X authentications fail to complete correctly when traversing the site-to-site VPN between a branch and the corporate headquarters.&lt;BR /&gt;From a technical standpoint, the following was observed:&lt;BR /&gt;• The authentication process starts correctly, but the session is not completed and times out in Cisco ISE.&lt;BR /&gt;• The access points are able to send requests to the NAC; however, a complete response is not received.&lt;BR /&gt;• At the corporate headquarters (without going through the VPN), behavior is normal.&lt;BR /&gt;Based on the above, and considering that:&lt;BR /&gt;• TEAP introduces greater encapsulation and larger packet sizes compared to PEAP&lt;BR /&gt;• The IPsec VPN adds additional overhead&lt;BR /&gt;The primary hypothesis is a possible fragmentation or MTU issue in the VPN tunnel, which would be preventing the EAP exchange from completing correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;by any chance that you have a case similar to this one in order for me to solve the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is my action plan&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Agreed-Upon Testing Plan&lt;BR /&gt;To validate this hypothesis, it was agreed to conduct controlled tests during a low-impact window, including the following activities:&lt;BR /&gt;1. Validation of the actual MTU on the path&lt;BR /&gt;o Connectivity tests with the DF flag to identify the maximum size without fragmentation.&lt;BR /&gt;2. Controlled adjustment of the MTU in the VPN tunnel&lt;BR /&gt;o Reduce the MTU to a reference value (e.g., 1360) for testing.&lt;BR /&gt;3. Conduct authentication tests&lt;BR /&gt;o Verify whether the TEAP process completes successfully after the adjustment.&lt;BR /&gt;4. Monitor and capture traffic&lt;BR /&gt;o Review behavior at the firewall and NAC levels to confirm whether symptoms of fragmentation or truncated sessions disappear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any kind of help would be highly cherished&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2026 14:04:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/validation-of-the-pan-vpn-ssid-and-peap-teap-protocols/m-p/1257522#M126656</guid>
      <dc:creator>F.Pinar</dc:creator>
      <dc:date>2026-06-26T14:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Validation of the PAN VPN, SSID, and PEAP-TEAP Protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/validation-of-the-pan-vpn-ssid-and-peap-teap-protocols/m-p/1257527#M126657</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;While I have not had that same issue. Your path seems logical to ensure it either is or is not MTU. Depending on the packets, might have to go lower than what you have proposed.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2026 16:04:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/validation-of-the-pan-vpn-ssid-and-peap-teap-protocols/m-p/1257527#M126657</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2026-06-26T16:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Validation of the PAN VPN, SSID, and PEAP-TEAP Protocols</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/validation-of-the-pan-vpn-ssid-and-peap-teap-protocols/m-p/1257529#M126658</link>
      <description>&lt;P&gt;I realized that there is an internal misconfiguration error the firewall is working as expected.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2026 17:53:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/validation-of-the-pan-vpn-ssid-and-peap-teap-protocols/m-p/1257529#M126658</guid>
      <dc:creator>F.Pinar</dc:creator>
      <dc:date>2026-06-26T17:53:44Z</dc:date>
    </item>
  </channel>
</rss>

