<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Systems VPN Adapter in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40425#M29680</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Iancom,&lt;/P&gt;&lt;P&gt;If you hear back can you leave a post, as I am having the same issue!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Aug 2012 15:43:19 GMT</pubDate>
    <dc:creator>u14441</dc:creator>
    <dc:date>2012-08-14T15:43:19Z</dc:date>
    <item>
      <title>Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40412#M29667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see there is now support for Cisco Systems VPN Adaper however I am trying to figure out what exactly is supported am I now able to connect to the firewall via cisco IPSEC VPN from the Cisco VPN Client software or is this support for something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ask as we have engineers that connect to many sites and global rotect is not geared this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 06:40:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40412#M29667</guid>
      <dc:creator>bcsgroup</dc:creator>
      <dc:date>2012-01-26T06:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40413#M29668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried looking through the more recent Release Notes, and I was not able to find much on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mind me asking where you saw that referenced? I have a partial answer, but want to wait your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 19:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40413#M29668</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-01-26T19:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40414#M29669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the portal when I click Client Configuration I can add a third party adapter. So was not sure what that was in referance to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have more info on it that would be great. I am still trying to get my head around global protect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 20:12:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40414#M29669</guid>
      <dc:creator>bcsgroup</dc:creator>
      <dc:date>2012-01-26T20:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40415#M29670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We use Cisco VPN Client 5.0 to connect to PA's.&amp;nbsp; The Portal must be configured with the Cisco VPN Adapter being allowed, and the Gateway needs to use tunnel mode with XAuth (Group Name/Secret).&amp;nbsp; Have you attempted connection with these settings?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 21:09:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40415#M29670</guid>
      <dc:creator>bmorrison</dc:creator>
      <dc:date>2012-01-26T21:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40416#M29671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks BCSGROUP,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible that Cisco IPSEC clients with the XAUTH feature could work, but it is not tested or supported at this time for Windows, Linux or Mac-OS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other thing that I heard/read was that the routes for the desntination network may not show up, and as long as you are manually adding in the routes, then you might be OK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 21:51:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40416#M29671</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-01-26T21:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40417#M29672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any chance I can get some info on how this is done do you just create a portal with these settings or do you have to do the full global protect config?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jan 2012 03:30:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40417#M29672</guid>
      <dc:creator>bcsgroup</dc:creator>
      <dc:date>2012-01-27T03:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40418#M29673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@bcsgroup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;although not officially supported, the Cisco VPN Client does work.&amp;nbsp; It does not append the mask/gateway to your client, but you should still have no issues connecting to devices within your local network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You must configure the Portal/Gateway under Network&amp;gt;GlobalProtect and use a tunnel interface placed inside the appropriate security zone.&amp;nbsp; Remember to create/use your certificates appropriately and have them configured for use on the Gateway(certificate) and Portal(CA, and certificate).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Portal:&lt;/P&gt;&lt;P&gt;Create a profile using your local interface (external) and local IP that you wish to use for VPN connectivity.&amp;nbsp; Choose the standard certificate that is signed by the CA used in your Client Configuration, and choose your authentication methods.&amp;nbsp; Under Client Configuration setup a profile using your external IP/mask for connectivity with Priority 1 and choose your Root CA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Gateway:&lt;/P&gt;&lt;P&gt;Ensure that you have tunnel mode chosen and checked Enable IPSec, check Enable X-Auth Support (verify group name and group password), and check Skip Auth on IKE Rekey.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Choose your external Tunnel Gateway Interface and Address used for the VPN/Portal, and under Client configuration make sure you have your DNS, VPN IP-Pool, and Access Route configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;under Policies&amp;gt;Security:&lt;/P&gt;&lt;P&gt;Ensure that you have a rule above any blocking statements that allow ipsec, ike, ssl, web-browsing, and ciscovpn applications to your VPN Gateway IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Using Cisco VPN Client:&lt;/P&gt;&lt;P&gt;setup the connection profile with the Gateway IP, group name, and group password.&amp;nbsp; Connect and enter your credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any issues, enter the log responses here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jan 2012 13:37:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40418#M29673</guid>
      <dc:creator>bmorrison</dc:creator>
      <dc:date>2012-01-27T13:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40419#M29674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I also configured PA to work with CISCO VPN Client and it works OK.&amp;nbsp; The only problem is that the connection get expired after one hour and the client must reconnect. I can not find the setting to change this expiration time. Do you have any idea how to chang this life time ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2012 11:41:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40419#M29674</guid>
      <dc:creator>BLepenik</dc:creator>
      <dc:date>2012-04-19T11:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40420#M29675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have managed to configure the Cisco VPN client to work along-side our PA firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Much better client than Global Protect as it behaves like it should and works with corporate proxy settings as expected!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2012 10:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40420#M29675</guid>
      <dc:creator>singersit</dc:creator>
      <dc:date>2012-04-23T10:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40421#M29676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;lancom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which PAN-OS version? This bug was fixed in 4.0.8.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;33542 – SSL VPN user to IP mappings are being lost after about an hour in an HA configuration when the mappings do not contain information. Issue due to idle timeout and maximum ttl not matching the expiration ttl of the SSL VPN connections.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2012 14:09:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40421#M29676</guid>
      <dc:creator>wscmtts</dc:creator>
      <dc:date>2012-04-23T14:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40422#M29677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/people/wscmtts" id="jive-53285,548,138,958,251,901"&gt;wscmtts&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PANOS 4.1.2 and this is not the same problem. I configured Gateway with IPSec and X_Auth support. As client I use CISCO VPN client 5 which support only IPSec VPN connections. When I open "More Users Info" window to see active connection a have a LIfetime of connection set to 3660 sec. When I configured gateway I set login lifetime parameter to 24 hours. I also get an System log message that IPSec key has expired. I just do not know where I can change this parameter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2012 15:43:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40422#M29677</guid>
      <dc:creator>BLepenik</dc:creator>
      <dc:date>2012-04-23T15:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40423#M29678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello lancom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you find a solution to the lifetime timer (3660 sec).&lt;/P&gt;&lt;P&gt;I run into the same issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hedi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2012 06:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40423#M29678</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-07-26T06:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40424#M29679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I still have an open case on this matter. We find out that it is the same problem with iPad nativ client which is supported by Palo Alto.&lt;/P&gt;&lt;P&gt;So i'm waiting for a response from support team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2012 07:22:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40424#M29679</guid>
      <dc:creator>BLepenik</dc:creator>
      <dc:date>2012-07-26T07:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40425#M29680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Iancom,&lt;/P&gt;&lt;P&gt;If you hear back can you leave a post, as I am having the same issue!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 15:43:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40425#M29680</guid>
      <dc:creator>u14441</dc:creator>
      <dc:date>2012-08-14T15:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40426#M29681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;does your case close and get a workaroud?&lt;/P&gt;&lt;P&gt;could you please share a solution?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 10:57:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40426#M29681</guid>
      <dc:creator>enkim</dc:creator>
      <dc:date>2012-10-08T10:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40427#M29682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bump. Same problem here, PA-2050, version 4.1.9. I have tried all the suggestions in the forum, but connections from Android and Linux devices timeout after about an hour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the logs, I see this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPSec key installed. Installed SA: 65.183.159.2[4500]-24.218.166.37[4500] SPI:0x8CB61A86/0x73498191 lifetime 3300 Sec lifesize unlimited&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;followed by (surprise, surprise!) about 3300 seconds later.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;TABLE border="0" cellspacing="0" frame="VOID" rules="NONE"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD height="17" width="1255"&gt;IKE phase-1 SA is expired SA: 65.183.159.2[4500]-24.218.166.37[4500] cookie:ffe6e33d5c27a2f5:6253cd787672d842.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is really a shame, because the connection works flawlessly, but in our environment timing out and having to manually reconnect isn't going to fly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2012 15:48:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40427#M29682</guid>
      <dc:creator>steve.chupack</dc:creator>
      <dc:date>2012-10-18T15:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Systems VPN Adapter</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40428#M29683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried everything you mentioned and I can connect using iOS with no problem. For the life of me, I can't get the Cisco VPN client to even connect, no response from peer. The one confusing me is the security policy rule you mentioned. Would it be from untrust to untrust as far as the zones since the interface IP is in the untrust zone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Aug 2013 00:28:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-systems-vpn-adapter/m-p/40428#M29683</guid>
      <dc:creator>BeyondTrust</dc:creator>
      <dc:date>2013-08-23T00:28:32Z</dc:date>
    </item>
  </channel>
</rss>

