<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN s2s PA and Mikrotik in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-pa-and-mikrotik/m-p/41800#M30755</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have new tas - make VPN s2s between PA200 and Mikrotik router.&lt;/P&gt;&lt;P&gt;PA&amp;nbsp; (PA 200 on 6.1.4) has Advanced phase mode 1 optios set to AUTO and "anable passive mode" not checked&lt;/P&gt;&lt;P&gt;Mikrotik (751U-2HnD with latest 6.30 router OS) is in aggressive mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's quite simple task, few policy rules on PA and on Mikrotik side. Configuration similar to PA&amp;lt;&amp;gt;Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got strange resoults, everything seems to be OK.usually tunnel is working, hosts on both sides could ping each other, but ...&lt;/P&gt;&lt;P&gt;sometimes doesn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example 1:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="20330" alt="2015-07-13_215823.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20330_2015-07-13_215823.png" style="height: 317px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;I'm able to ping from A side to B, but not from B to A (packed rejected)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example 2&lt;/P&gt;&lt;P&gt;Side A pinging side B, ping from B to A doesnt working UNTIL I stopped ping from A to B&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="20331" alt="2015-07-13_215844.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20331_2015-07-13_215844.png" style="height: 315px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;example 3&lt;/P&gt;&lt;P&gt;Mikrotik shows Installes SAs:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="20332" alt="2015-07-13_215945.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/20332_2015-07-13_215945.png" style="height: 119px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it normal that on PA side Auth is none and Enc Algoritms is none?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone any idea whats going on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment (about 5min later than I created screenshots above) Ping from B to A started working - is it kind of mystery or what?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help me please&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Jul 2015 20:18:19 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2015-07-13T20:18:19Z</dc:date>
    <item>
      <title>VPN s2s PA and Mikrotik</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-pa-and-mikrotik/m-p/41800#M30755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have new tas - make VPN s2s between PA200 and Mikrotik router.&lt;/P&gt;&lt;P&gt;PA&amp;nbsp; (PA 200 on 6.1.4) has Advanced phase mode 1 optios set to AUTO and "anable passive mode" not checked&lt;/P&gt;&lt;P&gt;Mikrotik (751U-2HnD with latest 6.30 router OS) is in aggressive mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's quite simple task, few policy rules on PA and on Mikrotik side. Configuration similar to PA&amp;lt;&amp;gt;Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got strange resoults, everything seems to be OK.usually tunnel is working, hosts on both sides could ping each other, but ...&lt;/P&gt;&lt;P&gt;sometimes doesn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example 1:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="20330" alt="2015-07-13_215823.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20330_2015-07-13_215823.png" style="height: 317px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;I'm able to ping from A side to B, but not from B to A (packed rejected)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example 2&lt;/P&gt;&lt;P&gt;Side A pinging side B, ping from B to A doesnt working UNTIL I stopped ping from A to B&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="20331" alt="2015-07-13_215844.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20331_2015-07-13_215844.png" style="height: 315px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;example 3&lt;/P&gt;&lt;P&gt;Mikrotik shows Installes SAs:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="20332" alt="2015-07-13_215945.png" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/20332_2015-07-13_215945.png" style="height: 119px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it normal that on PA side Auth is none and Enc Algoritms is none?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone any idea whats going on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment (about 5min later than I created screenshots above) Ping from B to A started working - is it kind of mystery or what?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help me please&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jul 2015 20:18:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-pa-and-mikrotik/m-p/41800#M30755</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-07-13T20:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN s2s PA and Mikrotik</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-pa-and-mikrotik/m-p/41801#M30756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;In daily report I got:&lt;/P&gt;&lt;P&gt;Device SN Virtual System Rule Bytes Sessions&lt;/P&gt;&lt;P&gt;001606004XXX vsys1 VPN-s2s-local-networks 1021.08 M 129.84 k&lt;/P&gt;&lt;P&gt;It's mean that security rule that allowing traffic between A and B&amp;nbsp; transfered ~1GB and generates 130000 sessions. Thats pretty much sessions - why?&lt;/P&gt;&lt;P&gt;I used TotalCommander to upload and download 2,4GB ISO files, so I genereated more than 5GB traffic I think.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second problem, using ping from A to B gateway I got aroung 10-17% loss of ping packet - is it&amp;nbsp; normal?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jul 2015 06:13:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-pa-and-mikrotik/m-p/41801#M30756</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-07-14T06:13:30Z</dc:date>
    </item>
  </channel>
</rss>

