<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN with a CISCO 880 series router Dynamic IP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-a-cisco-880-series-router-dynamic-ip/m-p/29935#M21869</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Following document should be able to help you set it up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4791"&gt;https://live.paloaltonetworks.com/docs/DOC-4791&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Jul 2013 10:41:11 GMT</pubDate>
    <dc:creator>Chatri</dc:creator>
    <dc:date>2013-07-25T10:41:11Z</dc:date>
    <item>
      <title>IPSEC VPN with a CISCO 880 series router Dynamic IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-a-cisco-880-series-router-dynamic-ip/m-p/29934#M21868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone setup a IPSEC VPN with a CISCO 880 series router Dynamic IP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jul 2013 10:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-a-cisco-880-series-router-dynamic-ip/m-p/29934#M21868</guid>
      <dc:creator>Shayan</dc:creator>
      <dc:date>2013-07-25T10:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN with a CISCO 880 series router Dynamic IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-a-cisco-880-series-router-dynamic-ip/m-p/29935#M21869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Following document should be able to help you set it up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4791"&gt;https://live.paloaltonetworks.com/docs/DOC-4791&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jul 2013 10:41:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-a-cisco-880-series-router-dynamic-ip/m-p/29935#M21869</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-07-25T10:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN with a CISCO 880 series router Dynamic IP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-a-cisco-880-series-router-dynamic-ip/m-p/29936#M21870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done the configuration and it seems like the session is also established. However, client computers cannot reach the servers on the other side. What i'm I missing here. Is it somthing to do with the cellular interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface: Dialer1 Cellular0&lt;/P&gt;&lt;P&gt;Profile: ISAKMP_PROF&lt;/P&gt;&lt;P&gt;Session status: UP-ACTIVE&lt;/P&gt;&lt;P&gt;Peer: &amp;lt;PaloAlto IP&amp;gt; port 500&lt;/P&gt;&lt;P&gt;&amp;nbsp; IKEv1 SA: local 10.249.207.85/500 remote &amp;lt;PaloAlto IP&amp;gt;/500 Active&lt;/P&gt;&lt;P&gt;&amp;nbsp; IPSEC FLOW: permit ip 10.20.1.0/255.255.255.0 10.3.0.0/255.255.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active SAs: 2, origin: crypto map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO Config.&lt;/P&gt;&lt;P&gt;Router#sh run&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 2934 bytes&lt;BR /&gt;!&lt;BR /&gt;! Last configuration change at 00:59:39 UTC Tue Jul 30 2013&lt;BR /&gt;version 15.1&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname Router&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no aaa new-model&lt;BR /&gt;!&lt;BR /&gt;crypto pki token default removal timeout 0&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip source-route&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip dhcp excluded-address 10.20.1.1 10.20.1.10&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool DHCP_POOL&lt;BR /&gt; network 10.20.1.0 255.255.255.0&lt;BR /&gt; default-router 10.20.1.1&lt;BR /&gt; dns-server 10.3.2.117 10.20.1.1&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip cef&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;chat-script gsm "" "AT!SCACT=1,4" TIMEOUT 60 "OK" CONNECT&lt;BR /&gt;license udi pid C887VAG+7-K9 sn FGL1710248X&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;controller VDSL 0&lt;BR /&gt;!&lt;BR /&gt;controller Cellular 0&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto keyring KEYR1&lt;BR /&gt;&amp;nbsp; pre-shared-key address &amp;lt;PaloAlto IP&amp;gt; key &amp;lt;Password&amp;gt;&lt;BR /&gt;!&lt;BR /&gt;crypto isakmp policy 1&lt;BR /&gt; encr 3des&lt;BR /&gt; hash md5&lt;BR /&gt; authentication pre-share&lt;BR /&gt; group 2&lt;BR /&gt;crypto isakmp key &amp;lt;Password&amp;gt; address &amp;lt;PaloAlto IP&amp;gt; no-xauth&lt;BR /&gt;crypto isakmp profile ISAKMP_PROF&lt;BR /&gt;&amp;nbsp;&amp;nbsp; keyring KEYR1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; self-identity user-fqdn &amp;lt;email address&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; match identity address &amp;lt;PaloAlto IP&amp;gt; 255.255.255.255&lt;BR /&gt;&amp;nbsp;&amp;nbsp; initiate mode aggressive&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto ipsec transform-set PaloAlto esp-3des esp-sha-hmac&lt;BR /&gt;!&lt;BR /&gt;crypto map PaloAlto 10 ipsec-isakmp&lt;BR /&gt; set peer &amp;lt;PaloAlto IP&amp;gt;&lt;BR /&gt; set security-association lifetime seconds 86400&lt;BR /&gt; set transform-set PaloAlto&lt;BR /&gt; set pfs group2&lt;BR /&gt; set isakmp-profile ISAKMP_PROF&lt;BR /&gt; match address IPSEC&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0&lt;BR /&gt; no ip address&lt;BR /&gt; shutdown&lt;BR /&gt;!&lt;BR /&gt;interface ATM0&lt;BR /&gt; no ip address&lt;BR /&gt; shutdown&lt;BR /&gt; no atm ilmi-keepalive&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet1&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet2&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet3&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Cellular0&lt;BR /&gt; no ip address&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip virtual-reassembly in&lt;BR /&gt; encapsulation slip&lt;BR /&gt; load-interval 60&lt;BR /&gt; dialer in-band&lt;BR /&gt; dialer pool-member 1&lt;BR /&gt; dialer-group 1&lt;BR /&gt; async mode interactive&lt;BR /&gt; crypto map PaloAlto&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; ip address 10.20.1.1 255.255.255.0&lt;BR /&gt; ip virtual-reassembly in&lt;BR /&gt; no ip route-cache cef&lt;BR /&gt;!&lt;BR /&gt;interface Dialer0&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Dialer1&lt;BR /&gt; ip address negotiated&lt;BR /&gt; no ip redirects&lt;BR /&gt; no ip unreachables&lt;BR /&gt; no ip proxy-arp&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip virtual-reassembly in&lt;BR /&gt; encapsulation slip&lt;BR /&gt; dialer pool 1&lt;BR /&gt; dialer idle-timeout 0&lt;BR /&gt; dialer string gsm&lt;BR /&gt; dialer persistent&lt;BR /&gt; dialer-group 1&lt;BR /&gt; crypto map PaloAlto&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;no ip http server&lt;BR /&gt;no ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip nat inside source list NAT interface Dialer1 overload&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 Dialer1&lt;BR /&gt;!&lt;BR /&gt;ip access-list extended IPSEC&lt;BR /&gt; permit ip 10.20.1.0 0.0.0.255 10.3.0.0 0.0.255.255&lt;BR /&gt;ip access-list extended NAT&lt;BR /&gt; deny&amp;nbsp;&amp;nbsp; ip 10.20.1.0 0.0.0.255 10.3.0.0 0.0.255.255&lt;BR /&gt; permit ip 10.20.1.0 0.0.0.255 any&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; no modem enable&lt;BR /&gt;line aux 0&lt;BR /&gt;line 3&lt;BR /&gt; exec-timeout 0 0&lt;BR /&gt; script dialer gsm&lt;BR /&gt; modem InOut&lt;BR /&gt; no exec&lt;BR /&gt; transport input all&lt;BR /&gt; rxspeed 21600000&lt;BR /&gt; txspeed 5760000&lt;BR /&gt;line vty 0 4&lt;BR /&gt; login&lt;BR /&gt; transport input all&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;Router#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jul 2013 01:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-a-cisco-880-series-router-dynamic-ip/m-p/29936#M21870</guid>
      <dc:creator>Shayan</dc:creator>
      <dc:date>2013-07-30T01:14:21Z</dc:date>
    </item>
  </channel>
</rss>

