<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IKE phase 2 failing with an asa5505 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43230#M31709</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Message =&lt;/P&gt;&lt;P&gt;IKE phase-1 negotiation is succeeded as initiator, main mode. Established SA:&lt;/P&gt;&lt;P&gt;IKE phase-2 negotiation is started as initiator, quick mode. Initiated SA:&lt;/P&gt;&lt;P&gt;IKE protocol notification message received: INVALID-ID-INFORMATION (18). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Mar 2011 21:01:53 GMT</pubDate>
    <dc:creator>LCMember1607</dc:creator>
    <dc:date>2011-03-02T21:01:53Z</dc:date>
    <item>
      <title>IKE phase 2 failing with an asa5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43230#M31709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Message =&lt;/P&gt;&lt;P&gt;IKE phase-1 negotiation is succeeded as initiator, main mode. Established SA:&lt;/P&gt;&lt;P&gt;IKE phase-2 negotiation is started as initiator, quick mode. Initiated SA:&lt;/P&gt;&lt;P&gt;IKE protocol notification message received: INVALID-ID-INFORMATION (18). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 21:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43230#M31709</guid>
      <dc:creator>LCMember1607</dc:creator>
      <dc:date>2011-03-02T21:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 failing with an asa5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43231#M31710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Confirm we have the correct local and remote proxy Id's from the ASA configured on the PAN. &lt;BR /&gt;If we can get the tunnel to be initiated from the ASA the PAN system logs should give us more detail as to the configuration option we need to adjust.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Proxy id's are needed when building a tunnel to other devices that use policy based VPN, we use route based vpn's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*There would have to be a proxy id entry for each network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's an example of PAN to ISA config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1328"&gt;https://live.paloaltonetworks.com/docs/DOC-1328&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Renato&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 21:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43231#M31710</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-03-02T21:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 failing with an asa5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43232#M31711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, get the ASA5505 administrator to confirm he hasn't done soemthing "funky' with the tunnel name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's a "feature" in Cisco firewalls which require the tunnel ID ont he PIX/ASA to be the IP address of the remote end - just the IP address, *not* a name or anything else - or else phase 2 fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This one bit me in the backside badly in a past life.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 22:03:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43232#M31711</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-03-02T22:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 failing with an asa5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43233#M31712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have found in previous tests I need to set the exchange mode to aggressive mode.&lt;/P&gt;&lt;P&gt;Then, even though aggressive mode expects the IP address as the authentication, Cisco will send an FQDN instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command might give you some more info :&lt;/P&gt;&lt;P&gt;less mp-log ikemgr.log (see whole log)&lt;/P&gt;&lt;P&gt;tail mp-log ikemgr.log (go to end of log)&lt;/P&gt;&lt;P&gt;tail follow yes mp-log ikemgr.log (show log in real time)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are further CLI commands to check the VPN status in the VPN config/tech note docs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 22:31:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43233#M31712</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-03-02T22:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 failing with an asa5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43234#M31713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I set up the proxies and the tunnel is up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I think I may have a nat issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any NAT configs on hand for asa&amp;lt;-&amp;gt;pan?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Mar 2011 19:53:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43234#M31713</guid>
      <dc:creator>LCMember1607</dc:creator>
      <dc:date>2011-03-03T19:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 failing with an asa5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43235#M31714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Bill,&lt;/P&gt;&lt;P&gt;How did you set up the proxies? I got the same error between PAN4020 and ASA5510&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:lle@socccd.edu"&gt;lle@socccd.edu&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 16:20:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43235#M31714</guid>
      <dc:creator>leole</dc:creator>
      <dc:date>2011-09-28T16:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 failing with an asa5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43236#M31715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IPSec tunnel.&lt;/P&gt;&lt;P&gt;Show advanced options&lt;/P&gt;&lt;P&gt;select the correct IKE Gateway, under IPSec Crypto Profile add a Proxy ID with the Local ID&amp;nbsp; being either a subnet or device IP that you are allowing access to on the PAN side and a Remote ID being either a subnet or device IP on the ASA side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 16:37:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43236#M31715</guid>
      <dc:creator>LCMember1607</dc:creator>
      <dc:date>2011-09-28T16:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 failing with an asa5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43237#M31716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FYI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's limit of 10 Proxy per tunnel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Sep 2011 13:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43237#M31716</guid>
      <dc:creator>friento</dc:creator>
      <dc:date>2011-09-29T13:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: IKE phase 2 failing with an asa5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43238#M31717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you&amp;nbsp; Bill,&lt;/P&gt;&lt;P&gt;It works for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Sep 2011 17:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-2-failing-with-an-asa5505/m-p/43238#M31717</guid>
      <dc:creator>leole</dc:creator>
      <dc:date>2011-09-29T17:21:09Z</dc:date>
    </item>
  </channel>
</rss>

