<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site to Site VPN from PA 200 to Juniper 5GT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-pa-200-to-juniper-5gt/m-p/50520#M37194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have a guide on how to set site to site vpn between PA200 and Juniper 5GT?. I tried a luck but now enable&amp;nbsp; to establish a connection. In Juniper the tunnel i created the status is ready.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A little help please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Jun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 21 Jul 2013 14:10:49 GMT</pubDate>
    <dc:creator>JunNOC</dc:creator>
    <dc:date>2013-07-21T14:10:49Z</dc:date>
    <item>
      <title>Site to Site VPN from PA 200 to Juniper 5GT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-pa-200-to-juniper-5gt/m-p/50520#M37194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have a guide on how to set site to site vpn between PA200 and Juniper 5GT?. I tried a luck but now enable&amp;nbsp; to establish a connection. In Juniper the tunnel i created the status is ready.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A little help please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Jun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Jul 2013 14:10:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-pa-200-to-juniper-5gt/m-p/50520#M37194</guid>
      <dc:creator>JunNOC</dc:creator>
      <dc:date>2013-07-21T14:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN from PA 200 to Juniper 5GT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-pa-200-to-juniper-5gt/m-p/50521#M37195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 8px 0; color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;IPSEC on PAN-OS firewalls is Route Based .&lt;/P&gt;&lt;P style="margin: 8px 0; color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;For the ease of config and co-relation , configure Route-Based on the Juniper-5GT (Screen-OS ) firewall.&lt;/P&gt;&lt;P style="margin: 8px 0; color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;SPAN style="line-height: 1.5em;"&gt;P&lt;/SPAN&gt;&lt;SPAN style="line-height: 1.5em;"&gt;roxy-IDs can be left blank (not-configured) at both ends as both Screen-OS&amp;nbsp; and PA firewall &lt;SPAN style="color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;in route-based mode &lt;/SPAN&gt;use defaults (local&amp;nbsp; 0.0.0.0/0 remote :&amp;nbsp; 0.0.0.0/0 , service any)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 8px 0; color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Use security level of standard for both&amp;nbsp; for the proposals on&amp;nbsp; 5GT.&lt;/P&gt;&lt;P style="margin: 8px 0; color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Config Guides :&lt;/P&gt;&lt;P style="margin: 8px 0; color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;PA-200&amp;nbsp; &lt;A __default_attr="1163" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="margin: 8px 0; color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Juniper 5GT- &lt;A class="active_link" href="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB8533" title="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB8533"&gt;Juniper Networks - [ScreenOS] Juniper Firewall LAN-to-LAN Route Based VPN articles - Knowledge Base&lt;/A&gt;&lt;/P&gt;&lt;P style="margin: 8px 0; color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Addtional Ref :&lt;/P&gt;&lt;P style="margin: 8px 0; color: #5f5f5f; font-family: arial, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;A href="https://live.paloaltonetworks.com/message/25784"&gt;Re: Juniper ScreenOS VPN to PANOS&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Jul 2013 15:51:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-pa-200-to-juniper-5gt/m-p/50521#M37195</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-21T15:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN from PA 200 to Juniper 5GT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-pa-200-to-juniper-5gt/m-p/50522#M37196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nadir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for help and i managed to up the link between the two sites half-way. Looking on my PA200 side the Ipesec Tunnel are up for both Phase 1 and Phase 2. But on my 5GT Juniper side the link status of the Tunnel is Down but its Active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can not ping any internal ip addresses&amp;nbsp; from each from Firewall. But for the public IP addresses&amp;nbsp; for each firewall&amp;nbsp; i am able to reach them thru ping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have few attachment and hope it can guide you to give some advices that i miss out. I am not so sure if this is something to do on the PA200 policy.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="5GTJuniperVPNStatus.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7359_5GTJuniperVPNStatus.png" width="450" /&gt;&lt;IMG alt="PA200 IPSec Tunnel Status.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7360_PA200 IPSec Tunnel Status.PNG" width="450" /&gt;&lt;IMG alt="packet.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7361_packet.PNG" width="450" /&gt;&lt;IMG alt="show vpn flow.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7362_show vpn flow.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Jun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 04:34:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-pa-200-to-juniper-5gt/m-p/50522#M37196</guid>
      <dc:creator>JunNOC</dc:creator>
      <dc:date>2013-07-22T04:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN from PA 200 to Juniper 5GT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-pa-200-to-juniper-5gt/m-p/50523#M37197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On PA-200's end&amp;nbsp; Make sure&lt;/P&gt;&lt;P&gt;1&amp;gt;You have configured a static route with tunnel.2 as an Interface and next-hop = None&lt;/P&gt;&lt;P&gt;2&amp;gt;Security rules (bidirectional if needed) between tunnel-zone and Inside zone.&lt;/P&gt;&lt;P&gt;# decap bytes are incrementing while encap=0 which suggests that PA firewall is receiving traffic for tunnel from Juniper's End but not sending any traffic for the tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Juniper Link Down -Could be related to Tunnel Monitoring.&lt;/P&gt;&lt;P&gt;Try to allow&amp;nbsp; PING on the Tunnel Interface (PA-200) using Interface-Managment profile .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 14:11:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-from-pa-200-to-juniper-5gt/m-p/50523#M37197</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-22T14:11:30Z</dc:date>
    </item>
  </channel>
</rss>

