<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-2-Site IPSEC Tunnel won't come online in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3991#M2947</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys for the quick response. Give me a few minutes to gather that information and post it back.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Sep 2014 14:38:59 GMT</pubDate>
    <dc:creator>EDSAadmin</dc:creator>
    <dc:date>2014-09-24T14:38:59Z</dc:date>
    <item>
      <title>Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3988#M2944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i have three offices:&lt;/P&gt;&lt;P&gt;office 1: US - northeast&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.1&amp;nbsp; PAN-500HA&lt;/P&gt;&lt;P&gt;Office 2: US - southeast&amp;nbsp;&amp;nbsp; 2.2.2.2 PAN-3020HA&amp;nbsp; HQ site&lt;/P&gt;&lt;P&gt;Office 3: Shanghai China&amp;nbsp; 3.3.3.3 PAN-200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all three IPSEC tunnels were up and running.&amp;nbsp; My Office 3 moved locations and when they did that we obtained a new static IP from the executive office we moved into. We updated the firewalls with the new external interface IP, IPSEC tunnel info on the local and updated all peer sites. committed the changes. after the commit office 1 and office 3 tunnel came up no problem. but office 2 and office 3 will not come up. We have deleted the config on both office 2 and office 3&amp;nbsp; and reconfigured. we have reboot both firewalls, reboot the router in office 2, we have changed the preshared key on both sites. triple checked our routes are correct in each virtual router. Contacted both ISP to make sure they are not blocking any UDP 500, 4500 or ESP traffic. they both say all IP's ports and protocols are open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we are seeing in the logs is office 3 is initiating ike phase 1 traffic out, but the peer box is not seeing any traffic coming in from office 3 nor is it initiating anything out to it either.&amp;nbsp; In the ike gateway for each we have it currently set to:&lt;/P&gt;&lt;P&gt;Exchange mode: main&lt;/P&gt;&lt;P&gt;IKE Crypto Profile: set at default for troubleshooting purposes&lt;/P&gt;&lt;P&gt;Unchecked "Enable passive mode"&lt;/P&gt;&lt;P&gt;Checked "Enable NAT traversal"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an open ticket with support but they have been unable to figure&amp;nbsp; out the problem yet. It has been escalated but i am still waiting for a callback today to continue working on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone run into this and if so how did you get it working again?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HQ Site&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-5 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15735_pastedImage_5.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-12 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15742_pastedImage_12.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15732_pastedImage_3.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-13 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15743_pastedImage_13.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15729_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shanghai Site&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage image-9" src="https://live.paloaltonetworks.com/legacyfs/online/15739_pastedImage_9.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-10 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15740_pastedImage_10.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage image-8" src="https://live.paloaltonetworks.com/legacyfs/online/15738_pastedImage_8.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-11 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15741_pastedImage_11.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-14 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15744_pastedImage_14.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage image-6" src="https://live.paloaltonetworks.com/legacyfs/online/15736_pastedImage_6.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 14:15:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3988#M2944</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-24T14:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3989#M2945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi EDSAadmin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please run following on both Office2 and Office3 device :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Office 2 : show session all filter source 2.2.2.2 destination 3.3.3.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show session all filter source 3.3.3.3 destination 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Office 3 : show session all filter source 2.2.2.2 destination 3.3.3.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show session all filter source 3.3.3.3 destination 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also please run following on both devices :&lt;/P&gt;&lt;P&gt;Office 2&lt;/P&gt;&lt;P&gt;test vpn ike-sa gateway &amp;lt;office3_gateway&amp;gt;&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel &amp;lt;office3_tunnel&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show vpn ike-sa gateway &amp;lt;office3_gateway&amp;gt;&lt;/P&gt;&lt;P&gt;show vpn ipsec-sa tunnel &amp;lt;office3_tunnel&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Office 3&lt;/P&gt;&lt;P&gt;test vpn ike-sa gateway &amp;lt;office2_gateway&amp;gt;&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel &amp;lt;office2_tunnel&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show vpn ike-sa gateway &amp;lt;office3_gateway&amp;gt;&lt;/P&gt;&lt;P&gt;show vpn ipsec-sa tunnel &amp;lt;office3_tunnel&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also send the snapshot of system logs Monitor -&amp;gt; System from both devices. Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 14:27:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3989#M2945</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-09-24T14:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3990#M2946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="7065" data-username="EDSAadmin" href="https://live.paloaltonetworks.com/people/EDSAadmin" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;EDSAadmin,&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please verify on both end firewalls, that no session on the discard state. Please share below mentioned &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;commands&lt;/SPAN&gt; output.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;show&lt;/SPAN&gt; session all filter &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;state discard&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;show&lt;/SPAN&gt; session all filter &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;-port 500 destination-port 500&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;show&lt;/SPAN&gt; session all filter &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;-port 4500 destination-port 4500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply Test VPN command and &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;immidiately&lt;/SPAN&gt; verify the session information as mentioned below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;test&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vpn&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ike&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sa&lt;/SPAN&gt; gateway &amp;lt;office3_gateway&amp;gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;test&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vpn&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ipsec&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;sa&lt;/SPAN&gt; tunnel &amp;lt;office3_tunnel&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit; color: #3b3b3b;"&gt;&amp;gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;show&lt;/SPAN&gt; session all filter &lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit; color: #3b3b3b;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;source&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-weight: inherit; font-style: inherit; font-size: 10pt; font-family: inherit; color: #3b3b3b;"&gt; &amp;lt;External-IF-IP&amp;gt; destination &amp;lt;Remote-Gateway-IP&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 14:37:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3990#M2946</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-24T14:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3991#M2947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys for the quick response. Give me a few minutes to gather that information and post it back.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 14:38:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3991#M2947</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-24T14:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3992#M2948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Hello &lt;/SPAN&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-link-profile-small" data-containerid="-1" data-containertype="-1" data-objectid="7065" data-objecttype="3" href="https://live.paloaltonetworks.com/people/EDSAadmin" style="font-weight: inherit; font-style: inherit; font-family: inherit; color: #779308; text-decoration: underline;"&gt;EDSAadmin,&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Step-1: Could you please specify Local/peer identification &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;IP) on both side firewalls. &lt;/P&gt;&lt;P&gt;Ste-2: apply test VPN command from &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;CLI&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Step-3: Open an another CLI window and run&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt; &amp;gt; tail follow yes &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mp&lt;/SPAN&gt;-log ikemgr.log&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please attach a screenshot of the SYSTEM logs&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;subtype &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vpn&lt;/SPAN&gt;&lt;/SPAN&gt;) and &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ikemgr&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;logs from the PAN firewall&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 14:43:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3992#M2948</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-24T14:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3993#M2949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HQ site:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-5 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15750_pastedImage_5.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shanghai&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage image-6" src="https://live.paloaltonetworks.com/legacyfs/online/15751_pastedImage_6.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HQ&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage image-7" src="https://live.paloaltonetworks.com/legacyfs/online/15752_pastedImage_7.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shanghai&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage image-8" src="https://live.paloaltonetworks.com/legacyfs/online/15753_pastedImage_8.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 15:10:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3993#M2949</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-24T15:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3994#M2950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi EDSAadmin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On your 1st snapshot from HQ, I would expect to see session from External to External. Instead it is showing internal to external. Could you please check your routing to verify if that is expected. Should 67.151.x.x belong to Internal zone. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 15:17:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3994#M2950</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-09-24T15:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3995#M2951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;TABLE border="1" class="jiveBorder" style="border: 1px solid #000000; width: 100%;"&gt;&lt;TBODY&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;I exported the system logs, but i don't see a way to attach them to my posts.&amp;nbsp; Am i just blind or is that not an option on this community?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 15:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3995#M2951</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-24T15:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3996#M2952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15756_pastedImage_2.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface 1/2 is in my external&amp;nbsp; zone which is 67.151.xxx.xxx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 15:23:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3996#M2952</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-24T15:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3997#M2953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for those output. I think we need to address why 67.151.x.x is showing up as internal zone. Could you please send us the output of show routing route. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 15:42:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3997#M2953</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-09-24T15:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3998#M2954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HQ Site&lt;/P&gt;&lt;P&gt;show session all filter state discard&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15757_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15758_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15759_pastedImage_2.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shanghai&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15760_pastedImage_3.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 15:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3998#M2954</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-24T15:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3999#M2955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG __jive_id="15761" alt="" class="image-4 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15761_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have multiple ISP's for redundancy. With that we use PBF rule so our default route is our backup circuit the 50.58. and then we use the PBF to send all traffic down our primary 67.151.......&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if that would be causing it to show up as an internal zone. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 15:50:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/3999#M2955</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-24T15:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4000#M2956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Step-1: Could you please specify Local/peer identification &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;IP) on both side firewalls.&amp;nbsp; - see previous screenshots&lt;/P&gt;&lt;P&gt;Ste-2: apply test VPN command from &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;CLI&lt;/SPAN&gt;. did that&lt;/P&gt;&lt;P&gt;Step-3: Open an another CLI window and run&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt; &amp;gt; tail follow yes &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mp&lt;/SPAN&gt;-log ikemgr.log &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I ran the tail command and there is a lot of output.&amp;nbsp; Do you want a screenshot of this, or some other method.&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt; &lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please attach a screenshot of the SYSTEM logs&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;(&lt;/SPAN&gt;subtype &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vpn&lt;/SPAN&gt;&lt;/SPAN&gt;) and &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ikemgr&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;logs from the PAN firewall&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;HQ Site&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;IMG alt="" class="image-0 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15762_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shanghai System Monitor&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/15763_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 16:05:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4000#M2956</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-24T16:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4001#M2957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please update your PAN support case number here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 19:47:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4001#M2957</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-24T19:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4002#M2958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the case number: 00252881&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i added this discussion thread to the case notes as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone got any ideas based on the information posted so far? Please let me know if you need more screenshots, logs, etc. i still owe you the tail output hulk.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Sep 2014 21:33:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4002#M2958</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-24T21:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4003#M2959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to see, the case has been closed today. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Sep 2014 22:02:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4003#M2959</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-25T22:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4004#M2960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We found the problem. On our HQ firewall we have a clean up rule set.&amp;nbsp; When we put that in initially it caused all of our tunnels to go down since it was dropping the ike phase 1 traffic. We put a VPN tunnel policy in place, with source zone external&amp;nbsp; and all four site external IP's and destination zone with all four external IP's one for each site allowing any app, and any service. Stupid me i forgot we had to set that up and that policy had the old IP address in it. once we updated the policy with the new IP and commited the tunnel came up no problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 13:25:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4004#M2960</guid>
      <dc:creator>EDSAadmin</dc:creator>
      <dc:date>2014-09-26T13:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site IPSEC Tunnel won't come online</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4005#M2961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;good to hear that is solved.implicity deny should be written always carefully.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2014 15:36:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-ipsec-tunnel-won-t-come-online/m-p/4005#M2961</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-09-26T15:36:24Z</dc:date>
    </item>
  </channel>
</rss>

