<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Paloalto and Checkpoint dynamic address vpn in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1732#M1282</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a project,that Paloalto and checkpoint vpn.Paloalto is static address ,checkpoint is pppoe ,dynamic address.who had do this , can you give me some document ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Mar 2014 09:52:40 GMT</pubDate>
    <dc:creator>ChuanhouLei</dc:creator>
    <dc:date>2014-03-07T09:52:40Z</dc:date>
    <item>
      <title>Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1732#M1282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a project,that Paloalto and checkpoint vpn.Paloalto is static address ,checkpoint is pppoe ,dynamic address.who had do this , can you give me some document ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 09:52:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1732#M1282</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-03-07T09:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1733#M1283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an example of IPSec VPN between PAN and CISCO, where Palo Alto FW is having a static IP address and other side is having a dynamic IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4791"&gt;VPN Tunnel Down Between Palo Alto Networks Firewall Static IP Address and Cisco VTI on Dynamic IP Address&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to configure the IPSec tunnel in aggressive mode, and the dynamic-side (checkpoint) should be the initiator always. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;PAN should be enable for passive mode-responder). In aggressive mode, the peer will be identified by its hostname/email-address/common IP address etc. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Dynamic-vpn.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/12027_Dynamic-vpn.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 17:10:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1733#M1283</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-07T17:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1734#M1284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;The cisco router can use this command "self-identity user-fqdn " ,is it must to set ?&lt;/P&gt;&lt;P&gt;the checkpoint utm-1 edge can't set this .I use hostname but doesn't work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2014 03:54:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1734#M1284</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-03-14T03:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1735#M1285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can select as "IP address" and put the local and remote interface IP address. This is just to verify the identity, hence you can put any IP address. Only keep in mind, the Local address here will the remote address for peer and vice versa. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2014 04:21:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1735#M1285</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-14T04:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1736#M1286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is my configuration . what's wrong with this ? When I change it to "static",and input peer ip ,it's ok.&lt;/P&gt;&lt;P&gt;The peer device is checkpoint utm-1 edge ,&amp;nbsp; The UTM-1 Edge does not support Aggressive mode in Phase 1. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="phase1_1.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/12141_phase1_1.JPG.jpg" style="width: 620px; height: 399px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="phaes1_2.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/12142_phaes1_2.JPG.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="log.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/12146_log.JPG.jpg" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Mar 2014 09:54:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1736#M1286</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-03-15T09:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1737#M1287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are You sure that cp-test (as a FQDN)&amp;nbsp; is a really FQDN address and resolvable by PA and Chekpoint?&lt;/P&gt;&lt;P&gt;Try to ping that address from CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Mar 2014 10:24:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1737#M1287</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-03-15T10:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1738#M1288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;I can't resolve the hostname(cp-test) via dns.&lt;/P&gt;&lt;P&gt;is there have some method without dns?the peer is dynamic address&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Mar 2014 10:33:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1738#M1288</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-03-15T10:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1739#M1289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hulk give You document, please follow it but use public IP (not 192.168.x.x) and some kind of service like DynDNS to map dynamic IP to constant FQDN address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Mar 2014 10:44:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1739#M1289</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-03-15T10:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1740#M1290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;192.168 is my test ip. if the paloalto and checkpoint use static ip address,i can do that, and vpn connect is ok.but now the checkpoint use dynamic ip address ,i can't do it.the checkpoint edge firewall not support aggressive mode vpn,fqdn need dynamic dns support.&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Mar 2014 14:00:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1740#M1290</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-03-15T14:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1741#M1291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As per my understanding, once you will select Peer type: dynamic, the firewall will prepare a negotiation in Aggressive mode. As you said before, t&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;he UTM-1 Edge does not support Aggressive mode, it could be a problem here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Could you please check "ikemgr.log" for detail information. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Mar 2014 17:37:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1741#M1291</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-15T17:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: Paloalto and Checkpoint dynamic address vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1742#M1292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;2014-03-17 19:24:39 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;P&gt;2014-03-17 19:24:41 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;P&gt;2014-03-17 19:24:43 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;P&gt;2014-03-17 19:24:46 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;P&gt;2014-03-17 19:24:48 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;P&gt;2014-03-17 19:24:51 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;P&gt;2014-03-17 19:24:56 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;P&gt;2014-03-17 19:24:59 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;P&gt;2014-03-17 19:25:03 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;P&gt;2014-03-17 19:25:07 [PROTO_ERR]: Couldn't find configuration for IKE phase-1 request for peer IP 192.168.30.250[500].&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Mar 2014 11:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-and-checkpoint-dynamic-address-vpn/m-p/1742#M1292</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-03-17T11:49:14Z</dc:date>
    </item>
  </channel>
</rss>

