<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Having trouble configuring IPSec tunnel (PA-500) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-configuring-ipsec-tunnel-pa-500/m-p/43595#M31992</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a VPS system to which we need to grant access to our private office network.&amp;nbsp; The VPS is in a cloud service so there is no networking gear that we can use for the vpn end point.&amp;nbsp; Our office network is behind a PA-500 firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VPS is a CentOS linux system that I've configured to use racoon.&amp;nbsp; I've tested this in my staging network with a pfsense firewall and was able to get it up and functional within about 30 minutes of work.&amp;nbsp; Traffic flowed across the vpn in both directions perfectly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On our office network with the PA-500, I am able to establish the tunnel, so both phases of IKE are successful, but no traffic is passed.&amp;nbsp; When I check the routing with the fib-lookup subcommand, it's going out to this vps host over the untrusted interface rather than the tunnel.1 interface but if I add a static route, then both IKE phases fail because it's trying to send the ike packets through the tunnel as well, which hasn't yet been established.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been through the "How to set up IPSec VPNs" pdf but since this configuration involves a single host with only a public interface as one endpoint, there is less of a match to the examples.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone set up a configuration like this that can point me to my next step?&amp;nbsp; It seems to me that I should need to add in a policy of some time, but I've tried several and haven't made any progress beyond IKE phase 2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Feb 2012 21:43:10 GMT</pubDate>
    <dc:creator>safecloud</dc:creator>
    <dc:date>2012-02-15T21:43:10Z</dc:date>
    <item>
      <title>Having trouble configuring IPSec tunnel (PA-500)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-configuring-ipsec-tunnel-pa-500/m-p/43595#M31992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a VPS system to which we need to grant access to our private office network.&amp;nbsp; The VPS is in a cloud service so there is no networking gear that we can use for the vpn end point.&amp;nbsp; Our office network is behind a PA-500 firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VPS is a CentOS linux system that I've configured to use racoon.&amp;nbsp; I've tested this in my staging network with a pfsense firewall and was able to get it up and functional within about 30 minutes of work.&amp;nbsp; Traffic flowed across the vpn in both directions perfectly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On our office network with the PA-500, I am able to establish the tunnel, so both phases of IKE are successful, but no traffic is passed.&amp;nbsp; When I check the routing with the fib-lookup subcommand, it's going out to this vps host over the untrusted interface rather than the tunnel.1 interface but if I add a static route, then both IKE phases fail because it's trying to send the ike packets through the tunnel as well, which hasn't yet been established.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been through the "How to set up IPSec VPNs" pdf but since this configuration involves a single host with only a public interface as one endpoint, there is less of a match to the examples.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone set up a configuration like this that can point me to my next step?&amp;nbsp; It seems to me that I should need to add in a policy of some time, but I've tried several and haven't made any progress beyond IKE phase 2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Feb 2012 21:43:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-configuring-ipsec-tunnel-pa-500/m-p/43595#M31992</guid>
      <dc:creator>safecloud</dc:creator>
      <dc:date>2012-02-15T21:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble configuring IPSec tunnel (PA-500)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-configuring-ipsec-tunnel-pa-500/m-p/43596#M31993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you have routing issue.&lt;/P&gt;&lt;P&gt;Check the following :&lt;/P&gt;&lt;P&gt;1) Default route pointing to your WAN router.&lt;/P&gt;&lt;P&gt;2) Route to 'remote network (LAN Side)' pointing to the tunnel interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also add a route to your tunnel endpoint IP address (with the next hop pointing to your WAN router).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hedi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2012 10:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-configuring-ipsec-tunnel-pa-500/m-p/43596#M31993</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-02-16T10:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble configuring IPSec tunnel (PA-500)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-configuring-ipsec-tunnel-pa-500/m-p/43597#M31994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hedi, thanks for your reply, but I'm not completely certain that I understand your suggestions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; We do have a default route in the PAN device to the WAN router.&amp;nbsp; Of course, if we did not we wouldn't have internet access, so perhaps you are referring to something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; I have tried setting up a static route to the remote network via the tunnel interface, but there isn't actually a remote network at all.&amp;nbsp; It's a single host and a single IP at that endpoint of the tunnel.&amp;nbsp; Whenever I try setting a static route through tunnel.1 for the remote endpoint, it prevents the IKE from succeeding, since the IKE packets are also routed through the tunnel.1 which isn't up yet.&amp;nbsp; Am I misunderstanding what you are suggesting?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)&amp;nbsp; I have tried adding a next hop to that static route of our wan router and it doesn't seem to make any difference.&amp;nbsp; It still prevents IKE from finishing.&amp;nbsp; I've also tried next hop of the PAN device's trust interface with the same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps I'm just misunderstanding something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 01:56:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-configuring-ipsec-tunnel-pa-500/m-p/43597#M31994</guid>
      <dc:creator>safecloud</dc:creator>
      <dc:date>2012-03-01T01:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble configuring IPSec tunnel (PA-500)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-configuring-ipsec-tunnel-pa-500/m-p/43598#M31995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's clarify a little bit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You have a default route pointing to the WAN router : OK&lt;/P&gt;&lt;P&gt;2) You say "﻿ but there isn't actually a remote network at all.&amp;nbsp; It's a single host and a single IP at that endpoint of the tunnel.".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my point of view, this kind of configuration never work because you try to encrypt IP traffic to the same IP address of the tunnel endpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you deal with routing ?&lt;/P&gt;&lt;P&gt;Sorry I have no idea&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hedi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2012 07:50:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/having-trouble-configuring-ipsec-tunnel-pa-500/m-p/43598#M31995</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2012-03-02T07:50:55Z</dc:date>
    </item>
  </channel>
</rss>

