<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question regarding site to site VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-site-to-site-vpn/m-p/39217#M28765</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you may be able to help. I am a little confused regarding the site-to-site VPN tunnel configuration (remote end will be a Cisco PIX).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get the following error when attempting to commit using PANOS 4.0&lt;/P&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="1" dir="ltr" width="611"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="2" valign="middle"&gt;&lt;STRONG style="font-family: Times New Roman; "&gt;&lt;P&gt;Details&lt;/P&gt;&lt;STRONG&gt;&lt;P&gt;·&lt;/P&gt;&lt;STRONG&gt;&lt;P&gt;·&lt;/P&gt;&lt;STRONG&gt;&lt;P&gt;·&lt;/P&gt;&lt;/STRONG&gt;Commit failed&lt;/STRONG&gt; (Module: device) &lt;/STRONG&gt;Error: tunnel configuration error &lt;/STRONG&gt;:&lt;BR /&gt;&lt;STRONG&gt;·&lt;/STRONG&gt; Error: tunnel VPN-tunnel-BVB: invalid peer IP address&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The local gateway IP is 199.55.55.1. The remote network is 172.31.31.0/24. Why I am getting the above ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Configuration.&lt;/P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;P&gt;Define the IKE crypto profile (step 1)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;network profiles&amp;gt;IKE Crypto&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;P&gt;Name: name of profile&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-Crypto-BVB&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;DH group: Diff-Hellman group&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; Group 2&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Encryption: Encryption&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; aes-256&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Authentication: Authentication&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; sha256&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Lifetime: VPN keepalive 1 day/24 hours/1440 minutes/86400 seconds :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; hours 24&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the IPSEC crypto profile (step 2)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;network profiles&amp;gt;IPSEC Crypto&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;P&gt;Name: name of profile&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-IPSECCrypto-BVB&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;IPSEC protocol: ESP/AH&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; ESP&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Encryption: Encryption&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; aes-256&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;DH group: Diff-Hellman group&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; Group 2&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Lifetime: VPN keepalive 1 day/24 hours/1440 minutes/86400 seconds :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; hours 24&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Authentication: Authentication&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; sha256&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Lifesize: VPN capacity bytes/kb/mb :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; KB 4500&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the IKE gateway (step 3)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;network profiles&amp;gt;IKE gateways&lt;/P&gt;&lt;P&gt;Name: name of gateway&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-GW-BVB&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; 199.55.55.1/32 (ip address of Palo-Alto ae3.400 outside interface)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; 172.31.31.1/32 (test address of the PIX)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the IPSEC tunnel (step 4)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;IPSEC tunnels&lt;/P&gt;&lt;P&gt;Name: Name of tunnel&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-tunnel-BVB&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; tunnel.1&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; auto-key&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-GW-BVB (from step 3)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the remote network (step 5)&lt;/P&gt;&lt;P&gt;Objects&amp;gt;addresses&lt;/P&gt;&lt;P&gt;Name: VPN-net-BVB&lt;/P&gt;&lt;P&gt;SHARED&lt;/P&gt;&lt;P&gt;Description: VPN BVB destination network&lt;/P&gt;&lt;P&gt;IP netmask: 172.31.31.0/24&lt;/P&gt;&lt;P&gt;Define the remote peer (step 6)&lt;/P&gt;&lt;P&gt;Objects&amp;gt;addresses&lt;/P&gt;&lt;P&gt;Name: VPN-peer-BVB&lt;/P&gt;&lt;P&gt;SHARED&lt;/P&gt;&lt;P&gt;Description: VPN BVB destination peer&lt;/P&gt;&lt;P&gt;IP netmask: 172.31.31.1/32&lt;/P&gt;&lt;P&gt;Define the static route for LDMZ to external (step 7)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;Virtual routers&lt;/P&gt;&lt;P&gt;Name: Name of router&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; RTVTLOUT&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; test network behind test PIX)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; RTVTOUT&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the static route for external to internet (step &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;Virtual routers&lt;/P&gt;&lt;P&gt;Name: Name of router&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; RTVTOUT&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; test network behind test PIX)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Policies&amp;gt;security (step 9)&lt;/P&gt;&lt;P&gt;Virtual system: FWOUTLDMZ&lt;/P&gt;&lt;P&gt;Name: VPN-rule1-BVB&lt;/P&gt;&lt;P&gt;Desc: Test rule for BVB configuration&lt;/P&gt;&lt;P&gt;Source: source zone&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;LDMZ&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Destination: destination zone&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;LOUT&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Address　: VPN-net-BVB (from step 5)&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Statics routes: ADD&lt;/P&gt;&lt;P&gt;Name: VPN-route-BVB&lt;/P&gt;&lt;P&gt;Destination: 172.31.31.0/24&lt;/P&gt;&lt;P&gt;Interface: tunnel.1&lt;/P&gt;&lt;P&gt;Next hop: ip address &amp;gt; 172.31.31.1/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Statics routes: ADD&lt;/P&gt;&lt;P&gt;Name: VPN-route2-BVB&lt;/P&gt;&lt;P&gt;Destination: 172.31.31.0/24&lt;/P&gt;&lt;P&gt;Interface: ae3.400&lt;/P&gt;&lt;P&gt;Next hop: Next VR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tunnel interface: ascending unique number of tunnel interface&lt;/P&gt;&lt;P&gt;Type: automatic of manual key&lt;/P&gt;&lt;P&gt;IKE gateway: Name of gateway&lt;/P&gt;&lt;P&gt;IPSEC crypto profile: VPN-IPSECCrypto-BVB (from step 2)&lt;/P&gt;&lt;P&gt;Click Ok&lt;/P&gt;&lt;P&gt;Virtual router: RTVOUT01&lt;/P&gt;&lt;P&gt;Virtual system: FWOUTDMZ&lt;/P&gt;&lt;P&gt;Security zone: LOUT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Local ip: the local ip address of the VPN tunnel&lt;/P&gt;&lt;P&gt;Peer ip: the remote peer ip address of the VPN tunnel&lt;/P&gt;&lt;P&gt;Presharedkey: vpntestkey&lt;/P&gt;&lt;P&gt;CLICK SHOW ADVANCED PHASE 1 OPTIONS&lt;/P&gt;&lt;P&gt;Exchange mode: aggressive&lt;/P&gt;&lt;P&gt;IKE crypto profile: VPN-Crypto-BVB (from step 1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Feb 2012 09:50:33 GMT</pubDate>
    <dc:creator>sfisher899</dc:creator>
    <dc:date>2012-02-21T09:50:33Z</dc:date>
    <item>
      <title>Question regarding site to site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-site-to-site-vpn/m-p/39217#M28765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you may be able to help. I am a little confused regarding the site-to-site VPN tunnel configuration (remote end will be a Cisco PIX).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get the following error when attempting to commit using PANOS 4.0&lt;/P&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="1" dir="ltr" width="611"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="2" valign="middle"&gt;&lt;STRONG style="font-family: Times New Roman; "&gt;&lt;P&gt;Details&lt;/P&gt;&lt;STRONG&gt;&lt;P&gt;·&lt;/P&gt;&lt;STRONG&gt;&lt;P&gt;·&lt;/P&gt;&lt;STRONG&gt;&lt;P&gt;·&lt;/P&gt;&lt;/STRONG&gt;Commit failed&lt;/STRONG&gt; (Module: device) &lt;/STRONG&gt;Error: tunnel configuration error &lt;/STRONG&gt;:&lt;BR /&gt;&lt;STRONG&gt;·&lt;/STRONG&gt; Error: tunnel VPN-tunnel-BVB: invalid peer IP address&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The local gateway IP is 199.55.55.1. The remote network is 172.31.31.0/24. Why I am getting the above ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Configuration.&lt;/P&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;P&gt;Define the IKE crypto profile (step 1)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;network profiles&amp;gt;IKE Crypto&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;P&gt;Name: name of profile&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-Crypto-BVB&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;DH group: Diff-Hellman group&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; Group 2&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Encryption: Encryption&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; aes-256&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Authentication: Authentication&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; sha256&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Lifetime: VPN keepalive 1 day/24 hours/1440 minutes/86400 seconds :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; hours 24&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the IPSEC crypto profile (step 2)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;network profiles&amp;gt;IPSEC Crypto&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;P&gt;Name: name of profile&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-IPSECCrypto-BVB&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;IPSEC protocol: ESP/AH&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; ESP&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Encryption: Encryption&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; aes-256&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;DH group: Diff-Hellman group&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; Group 2&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Lifetime: VPN keepalive 1 day/24 hours/1440 minutes/86400 seconds :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; hours 24&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Authentication: Authentication&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; sha256&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Lifesize: VPN capacity bytes/kb/mb :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; KB 4500&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the IKE gateway (step 3)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;network profiles&amp;gt;IKE gateways&lt;/P&gt;&lt;P&gt;Name: name of gateway&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-GW-BVB&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; 199.55.55.1/32 (ip address of Palo-Alto ae3.400 outside interface)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; 172.31.31.1/32 (test address of the PIX)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the IPSEC tunnel (step 4)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;IPSEC tunnels&lt;/P&gt;&lt;P&gt;Name: Name of tunnel&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-tunnel-BVB&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; tunnel.1&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; auto-key&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; VPN-GW-BVB (from step 3)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the remote network (step 5)&lt;/P&gt;&lt;P&gt;Objects&amp;gt;addresses&lt;/P&gt;&lt;P&gt;Name: VPN-net-BVB&lt;/P&gt;&lt;P&gt;SHARED&lt;/P&gt;&lt;P&gt;Description: VPN BVB destination network&lt;/P&gt;&lt;P&gt;IP netmask: 172.31.31.0/24&lt;/P&gt;&lt;P&gt;Define the remote peer (step 6)&lt;/P&gt;&lt;P&gt;Objects&amp;gt;addresses&lt;/P&gt;&lt;P&gt;Name: VPN-peer-BVB&lt;/P&gt;&lt;P&gt;SHARED&lt;/P&gt;&lt;P&gt;Description: VPN BVB destination peer&lt;/P&gt;&lt;P&gt;IP netmask: 172.31.31.1/32&lt;/P&gt;&lt;P&gt;Define the static route for LDMZ to external (step 7)&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;Virtual routers&lt;/P&gt;&lt;P&gt;Name: Name of router&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; RTVTLOUT&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; test network behind test PIX)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; RTVTOUT&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Define the static route for external to internet (step &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;&lt;/P&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;Network&amp;gt;Virtual routers&lt;/P&gt;&lt;P&gt;Name: Name of router&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;DIR&gt;&lt;DIR&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; RTVTOUT&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt; test network behind test PIX)&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Policies&amp;gt;security (step 9)&lt;/P&gt;&lt;P&gt;Virtual system: FWOUTLDMZ&lt;/P&gt;&lt;P&gt;Name: VPN-rule1-BVB&lt;/P&gt;&lt;P&gt;Desc: Test rule for BVB configuration&lt;/P&gt;&lt;P&gt;Source: source zone&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;LDMZ&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Destination: destination zone&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; font-family: Wingdings; "&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;LOUT&lt;/SPAN&gt;&lt;SPAN style="font-size: 12pt; font-family: Calibri; "&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Address　: VPN-net-BVB (from step 5)&lt;/P&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Statics routes: ADD&lt;/P&gt;&lt;P&gt;Name: VPN-route-BVB&lt;/P&gt;&lt;P&gt;Destination: 172.31.31.0/24&lt;/P&gt;&lt;P&gt;Interface: tunnel.1&lt;/P&gt;&lt;P&gt;Next hop: ip address &amp;gt; 172.31.31.1/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Statics routes: ADD&lt;/P&gt;&lt;P&gt;Name: VPN-route2-BVB&lt;/P&gt;&lt;P&gt;Destination: 172.31.31.0/24&lt;/P&gt;&lt;P&gt;Interface: ae3.400&lt;/P&gt;&lt;P&gt;Next hop: Next VR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tunnel interface: ascending unique number of tunnel interface&lt;/P&gt;&lt;P&gt;Type: automatic of manual key&lt;/P&gt;&lt;P&gt;IKE gateway: Name of gateway&lt;/P&gt;&lt;P&gt;IPSEC crypto profile: VPN-IPSECCrypto-BVB (from step 2)&lt;/P&gt;&lt;P&gt;Click Ok&lt;/P&gt;&lt;P&gt;Virtual router: RTVOUT01&lt;/P&gt;&lt;P&gt;Virtual system: FWOUTDMZ&lt;/P&gt;&lt;P&gt;Security zone: LOUT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Local ip: the local ip address of the VPN tunnel&lt;/P&gt;&lt;P&gt;Peer ip: the remote peer ip address of the VPN tunnel&lt;/P&gt;&lt;P&gt;Presharedkey: vpntestkey&lt;/P&gt;&lt;P&gt;CLICK SHOW ADVANCED PHASE 1 OPTIONS&lt;/P&gt;&lt;P&gt;Exchange mode: aggressive&lt;/P&gt;&lt;P&gt;IKE crypto profile: VPN-Crypto-BVB (from step 1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2012 09:50:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-site-to-site-vpn/m-p/39217#M28765</guid>
      <dc:creator>sfisher899</dc:creator>
      <dc:date>2012-02-21T09:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding site to site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-site-to-site-vpn/m-p/39218#M28766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's a bit tough to read your configuration in this format.&amp;nbsp; Could you please paste in the CLI output?&amp;nbsp; I think the issue is that you're using 172.31.31.0/24 as an IP address.&amp;nbsp; .0 isn't a legal address so the commit is failing.&amp;nbsp; I'll be able to confirm if you can paste in the IKE gateway configuration and the IPSec tunnel configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick Campagna&lt;/P&gt;&lt;P&gt;Product Management&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Feb 2012 16:38:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-site-to-site-vpn/m-p/39218#M28766</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2012-02-22T16:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Question regarding site to site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-site-to-site-vpn/m-p/39219#M28767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Were you able to resolve this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2012 16:32:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/question-regarding-site-to-site-vpn/m-p/39219#M28767</guid>
      <dc:creator>ncampagna</dc:creator>
      <dc:date>2012-06-21T16:32:07Z</dc:date>
    </item>
  </channel>
</rss>

