<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Faild Starting Phase1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/faild-starting-phase1/m-p/2848#M2109</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you filed this as a bug to the support?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen some threads aswell in this forum regarding VPN issues which seems to be fixed when you recreate the VPN settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the issues I think was when the order of where the VPN settings are placed within the running-config file was changed between two releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible for you to do a diff between the faulting config and the config which now works? Im thinking of if some naming standards has been changed which wasnt pickedup by the conversation scripts (which I assume exists when you go from one version into another?).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 May 2013 04:34:22 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-05-08T04:34:22Z</dc:date>
    <item>
      <title>Faild Starting Phase1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/faild-starting-phase1/m-p/2846#M2107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Group I am really ready to pull the hair out of my head.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For 3 months or so, I have had a VPN between my PA-200 to a PA-500 at my remote office. All was working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last night I come back into the office to find the VPN down, and not sure why. I am looking at my PA-200 which has exact configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see via my pcaps that I am attempting to transmit my IPSEC traffic via agressive mode from my PA-200 to my destination PA-500 FW. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my PA-500, I look in the system logs, and am seeing countless of messages "failed starting phase1"&lt;/P&gt;&lt;P&gt;Ok, I re-did my entire configuration on the PA-500, deleted old config, commit, created new config, and then commit.&lt;/P&gt;&lt;P&gt;Still getting failed starting phase1 I need to understand WHY is happening. &lt;/P&gt;&lt;P&gt;I do not have any insight or log to determine why it is failing to start. My PA-200 has dynamic IP, so I know my local PA-200 which be initiating the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at my traffic logs, and filtering on the public IP of my PA-200, I am not seeing any matching traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No changes to my policy, but now, I am starting to open my firewall open in hopes to catch some sort of inbound traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could use some insight on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 01:30:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/faild-starting-phase1/m-p/2846#M2107</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-05-08T01:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Faild Starting Phase1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/faild-starting-phase1/m-p/2847#M2108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I have no idea, but because I am playing in a lab, I just deleted all my rules and started over. The VPN tunnel is now back up with a smaller subset the exact rules. This is the 5th time I have seen a perfectly working VPN configuration just stop working and by putting in a different policy, it just magically works. I think there is something to be investigated in this 5.0.2 to 5.0.4 software......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 02:23:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/faild-starting-phase1/m-p/2847#M2108</guid>
      <dc:creator>scantwell</dc:creator>
      <dc:date>2013-05-08T02:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Faild Starting Phase1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/faild-starting-phase1/m-p/2848#M2109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you filed this as a bug to the support?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen some threads aswell in this forum regarding VPN issues which seems to be fixed when you recreate the VPN settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the issues I think was when the order of where the VPN settings are placed within the running-config file was changed between two releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible for you to do a diff between the faulting config and the config which now works? Im thinking of if some naming standards has been changed which wasnt pickedup by the conversation scripts (which I assume exists when you go from one version into another?).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 04:34:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/faild-starting-phase1/m-p/2848#M2109</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-05-08T04:34:22Z</dc:date>
    </item>
  </channel>
</rss>

