<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ipsec VPN traffic issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45927#M33753</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the far end of the VPN a Cisco device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ciscos do advertise their vendor in the IKE exchange, you can se this in the 'less mp-log ikemgr.log' output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2014-09-04 03:16:56 [INFO]: received Vendor ID: CISCO-UNITY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think is is due to this that ciscovpn is selected as the application within the Palo Alto firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Sep 2014 11:55:02 GMT</pubDate>
    <dc:creator>ajbool</dc:creator>
    <dc:date>2014-09-05T11:55:02Z</dc:date>
    <item>
      <title>Ipsec VPN traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45926#M33752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; why we are getting CISCOVPN traffic flow on VPN. please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="sa.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15332_sa.png" style="height: 270px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 11:40:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45926#M33752</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-09-05T11:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec VPN traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45927#M33753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the far end of the VPN a Cisco device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ciscos do advertise their vendor in the IKE exchange, you can se this in the 'less mp-log ikemgr.log' output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2014-09-04 03:16:56 [INFO]: received Vendor ID: CISCO-UNITY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think is is due to this that ciscovpn is selected as the application within the Palo Alto firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 11:55:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45927#M33753</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-09-05T11:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec VPN traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45928#M33754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ajbool, Yes, End side is the cisco device and i have more then 100 tunnels but most of cisco but i am facing this issue is only 3-4 tunnel.i have all ready create a application overwrite policy but till, i am facing this issue. Thanks Regards Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 12:14:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45928#M33754</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-09-05T12:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec VPN traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45929#M33755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find analysis of application "ciscovpn"&lt;/P&gt;&lt;P&gt;The Cisco VPN Client allows organizations to establish end-to-end, encrypted VPN tunnels for secure connectivity for mobile employees or teleworkers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on above analysis, there is a ciscovpn client which has generated remote access VPN request. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you confirm the same, via tracing source and destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;S&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;hah&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 13:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45929#M33755</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-05T13:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec VPN traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45930#M33756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If the IKE traffic is terminated on a Cisco device, it can contain a Cisco vendor ID field.&amp;nbsp; If &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Cisco vendor ID field&lt;/SPAN&gt; is seen in IKE packets by the &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;AppID&lt;/SPAN&gt; it will be identified as '&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ciscovpn&lt;/SPAN&gt;' application.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference DOC:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4340"&gt;ciscovpn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 14:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45930#M33756</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-05T14:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec VPN traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45931#M33757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Hulk Dud., You are right but question is that there are also other Cisco Tunnel but application identify as IPsec but few tunnel is identify as a CiscoVPN why??? Regards Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 15:50:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45931#M33757</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-09-05T15:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec VPN traffic issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45932#M33758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In both cases, could you please apply &amp;gt;show session id xxxx and share the output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2014 16:10:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-traffic-issue/m-p/45932#M33758</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-05T16:10:38Z</dc:date>
    </item>
  </channel>
</rss>

