<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IKE phase 2 negotiation fail in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-fail/m-p/18113#M13194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having a hard time bringing up a VPN tunnel from my PA-5020 to a Cisco firewall.&amp;nbsp; I'm getting the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 10.13.247.43/32 type IPv4_address protocol 0 port 0, received remote id: 192.168.10.200/32 type IPv4_address protocol 0 port 0.'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My search indicates that it's a mismatch with the Cisco firewall ACL.&amp;nbsp; Would I be correct in assuming that their ACL references address protocol 0 port 0 instead of the specific ports we agreed upon during the design?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Aug 2014 22:27:55 GMT</pubDate>
    <dc:creator>przyboro</dc:creator>
    <dc:date>2014-08-12T22:27:55Z</dc:date>
    <item>
      <title>IKE phase 2 negotiation fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-fail/m-p/18113#M13194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having a hard time bringing up a VPN tunnel from my PA-5020 to a Cisco firewall.&amp;nbsp; I'm getting the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 10.13.247.43/32 type IPv4_address protocol 0 port 0, received remote id: 192.168.10.200/32 type IPv4_address protocol 0 port 0.'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My search indicates that it's a mismatch with the Cisco firewall ACL.&amp;nbsp; Would I be correct in assuming that their ACL references address protocol 0 port 0 instead of the specific ports we agreed upon during the design?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2014 22:27:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-fail/m-p/18113#M13194</guid>
      <dc:creator>przyboro</dc:creator>
      <dc:date>2014-08-12T22:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 negotiation fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-fail/m-p/18114#M13195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;przyboro&lt;/SPAN&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking, most of the customer refers only local and remote subnet. As per the logs, please ensure that PAN is configured with Local PROXY ID as &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;192.168.10.200/32&lt;/SPAN&gt; and remote PROXY ID as &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;10.13.247.43/32&lt;/SPAN&gt;. Please find below an example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14900" alt="proxy-ID.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14900_proxy-ID.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notes: If you have specified any port and protocol in Cisco ACL, then only, it is required to add on PAN firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Aug 2014 22:40:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-fail/m-p/18114#M13195</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-12T22:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 negotiation fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-fail/m-p/18115#M13196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for this information.&amp;nbsp; I will be testing this out shortly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Aug 2014 19:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-fail/m-p/18115#M13196</guid>
      <dc:creator>przyboro</dc:creator>
      <dc:date>2014-08-13T19:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 negotiation fail</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-fail/m-p/18116#M13197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the late reply.&amp;nbsp; Missing proxy-ID was the problem.&amp;nbsp; Fixed now.&amp;nbsp; Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2014 18:23:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-negotiation-fail/m-p/18116#M13197</guid>
      <dc:creator>przyboro</dc:creator>
      <dc:date>2014-08-22T18:23:22Z</dc:date>
    </item>
  </channel>
</rss>

