<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN with fqdn denying ike 500 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42553#M31245</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes fortigate initiates the vpn connection but the weird thing is that i don't see any logs under Monitor -&amp;gt; System. I can see only under Monitor -&amp;gt; traffic where the firewall denies the specific packet (ike 500).&lt;/P&gt;&lt;P&gt;When switching the ha pair from active to passive, I can see normal logs and the vpn is working until the public ip address changes in the fortigate...&lt;/P&gt;&lt;P&gt;I think it has to do with the fortigate and the way it initiates the vpn connection..??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Dec 2011 09:45:35 GMT</pubDate>
    <dc:creator>cskodras</dc:creator>
    <dc:date>2011-12-30T09:45:35Z</dc:date>
    <item>
      <title>VPN with fqdn denying ike 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42549#M31241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to setup a ipsec vpn with a fortigate which has dynamic ip as gateway.&lt;/P&gt;&lt;P&gt;I have a security policy which allows all packets from the dynamic ip (fqdn) but if i type the command 'show log traffic src in x.x.x.x' i can see that i have an incoming request which Palo Alto denies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The weird thing is that this allow rule contains all other vpn gateways which are with static ip addresses and the only difference is that this one is defined with fqdn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Dec 2011 15:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42549#M31241</guid>
      <dc:creator>cskodras</dc:creator>
      <dc:date>2011-12-22T15:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with fqdn denying ike 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42550#M31242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dynamic like constantly changing or dynamic like a DHCP lease?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the FQDN job runs every 30 minutes or after a commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it's not constantly asking for the IP of the FQDN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Dec 2011 17:46:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42550#M31242</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2011-12-22T17:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with fqdn denying ike 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42551#M31243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's just a dsl connection with dynamic ip and ttl value 86400.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could see from console that the fqdn was correctly resolving to the new ip addresss.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another weird behavior: I forced the active unit to suspend mode and when the passive unit returned to active, the vpn worked! Then I switched again the units and it was working. The two configurations were synchronized correctly and there was no configuration change at all...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This morning all ipsec vpns are working except this one with the dynamic ip.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Dec 2011 08:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42551#M31243</guid>
      <dc:creator>cskodras</dc:creator>
      <dc:date>2011-12-23T08:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with fqdn denying ike 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42552#M31244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming that the fortigate is initiating the VPN you should get very useful debugging messages in the Palo Alto Device's system logs regarding the reason for the VPN initiation failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried that route for debugging the issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Dec 2011 00:45:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42552#M31244</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-12-30T00:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with fqdn denying ike 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42553#M31245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes fortigate initiates the vpn connection but the weird thing is that i don't see any logs under Monitor -&amp;gt; System. I can see only under Monitor -&amp;gt; traffic where the firewall denies the specific packet (ike 500).&lt;/P&gt;&lt;P&gt;When switching the ha pair from active to passive, I can see normal logs and the vpn is working until the public ip address changes in the fortigate...&lt;/P&gt;&lt;P&gt;I think it has to do with the fortigate and the way it initiates the vpn connection..??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Dec 2011 09:45:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42553#M31245</guid>
      <dc:creator>cskodras</dc:creator>
      <dc:date>2011-12-30T09:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with fqdn denying ike 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42554#M31246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this continues to be a problem you should open a ticket with support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SK &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Dec 2011 18:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-fqdn-denying-ike-500/m-p/42554#M31246</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-12-30T18:27:46Z</dc:date>
    </item>
  </channel>
</rss>

