<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TMG 2010 ipsec vpn in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tmg-2010-ipsec-vpn/m-p/22583#M16496</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can you try to set the proxy ID as a single host?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Do you get the same error on the TMG side when the PA-500 initiates the tunnel?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It may be worthwhile to gather packet captures and compare the proxy-ID that is being sent/received to see if there is difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Mar 2012 21:55:30 GMT</pubDate>
    <dc:creator>sspringer</dc:creator>
    <dc:date>2012-03-22T21:55:30Z</dc:date>
    <item>
      <title>TMG 2010 ipsec vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tmg-2010-ipsec-vpn/m-p/22582#M16495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to set up a site to site vpn with TMG 2010 (SP2) on the other point and is failing at phase 2.&lt;/P&gt;&lt;P&gt;The systems logs in PA-500 shows 'Invalid ID information (18)'. This is subnet mismatch between the two end points but I am sure that it's correct as i have doublechecked everything.&lt;/P&gt;&lt;P&gt;In remote networks of TMG I enter 192.168.1.0 - 192.168.1.255 (as you define it only by ip range) and in proxy id of PA i type 192.168.1.0/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone succesfully setup an IPSec VPN with PA and TMG?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2012 13:09:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tmg-2010-ipsec-vpn/m-p/22582#M16495</guid>
      <dc:creator>cskodras</dc:creator>
      <dc:date>2012-03-14T13:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: TMG 2010 ipsec vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tmg-2010-ipsec-vpn/m-p/22583#M16496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can you try to set the proxy ID as a single host?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Do you get the same error on the TMG side when the PA-500 initiates the tunnel?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It may be worthwhile to gather packet captures and compare the proxy-ID that is being sent/received to see if there is difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2012 21:55:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tmg-2010-ipsec-vpn/m-p/22583#M16496</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-03-22T21:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: TMG 2010 ipsec vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tmg-2010-ipsec-vpn/m-p/22584#M16497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello CSKodras ,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I hade the same problem last week.&lt;/P&gt;&lt;P&gt;PAN Firewall allow proxy id`s just with IP/SUBNET&lt;/P&gt;&lt;P&gt;SO you need to change in your TMG to IP/SUBNET and you phase 2 will function,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CHANGE TMG to IP/SUBNET 192.168.0.1/24 in your TMG ,&amp;nbsp; site-to-site VPN will function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Phase 2 IPSEC VPN , PAN and TMG switch yours networks and needs to be the same or Phase 2 will mismatch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 23:43:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tmg-2010-ipsec-vpn/m-p/22584#M16497</guid>
      <dc:creator>Thiago</dc:creator>
      <dc:date>2012-03-23T23:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: TMG 2010 ipsec vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tmg-2010-ipsec-vpn/m-p/22585#M16498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN&gt;gruposeguranca,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for the info. It worked to me as well.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2012 08:05:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tmg-2010-ipsec-vpn/m-p/22585#M16498</guid>
      <dc:creator>cskodras</dc:creator>
      <dc:date>2012-03-26T08:05:16Z</dc:date>
    </item>
  </channel>
</rss>

