<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vpn s2s with Mikrotik router - proxy id problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65097#M38920</link>
    <description>&lt;P&gt;uhh I figured it out (I hope)&lt;/P&gt;&lt;P&gt;Now tunnel is up ... but I havent any misconfiguration - in GUI everything was OK but ...&lt;/P&gt;&lt;P&gt;I started veryfication from CLI and I realised that from CLI polisy is broken (missed part about SA). I deleted it and created again - and - surprice !!! its working ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So lesson for me and You - use CLI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2015 12:09:09 GMT</pubDate>
    <dc:creator>_slv_</dc:creator>
    <dc:date>2015-09-25T12:09:09Z</dc:date>
    <item>
      <title>vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/64963#M38855</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;&lt;BR /&gt;I'm trying to connect PaloAlto PA200 PANOS 6.1.6 and Mikrotik RB951 6.32.2&lt;BR /&gt;&lt;BR /&gt;Phase 1 is estabilished properly but I cant get phase 2 working.&lt;BR /&gt;&lt;BR /&gt;Logs from Mikrotik says:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;DIV&gt;Sep/22/2015 20:09:34 ipsec,debug,packet HASH computed:&lt;BR /&gt;Sep/22/2015 20:09:34 ipsec,debug,packet f85f12d1 b77dc7a6 3690e85b ed9102d9 62f29649&lt;BR /&gt;Sep/22/2015 20:09:34 ipsec,debug,packet get a src address from ID payload 192.168.1.0[0] prefixlen=24 ul_proto=255&lt;BR /&gt;Sep/22/2015 20:09:34 ipsec,debug,packet get dst address from ID payload 192.168.2.0[0] prefixlen=24 ul_proto=255&lt;BR /&gt;Sep/22/2015 20:09:34 ipsec,debug no policy found: 192.168.1.0/24[0] 192.168.2.0/24[0] proto=any dir=in&lt;BR /&gt;Sep/22/2015 20:09:34 ipsec,debug failed to get proposal for responder.&lt;BR /&gt;Sep/22/2015 20:09:34 ipsec,error failed to pre-process ph2 packet.&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Logs from PaloAlto:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;DIV&gt;====&amp;gt; Initiated SA: x.y.z..157[500]-x.y.z..158[500] message id:0x6BB04309 &amp;lt;====&lt;BR /&gt;2015-09-22 20:09:53 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION FAILED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;BR /&gt;====&amp;gt; Failed SA: x.y.z..157[500]-x.y.z..158[500] message id:0x6BB04309 &amp;lt;==== Due to negotiation timeout.&lt;BR /&gt;2015-09-22 20:09:53 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;BR /&gt;====&amp;gt; Initiated SA: x.y.z..157[500]-x.y.z..158[500] message id:0x01365B68 &amp;lt;====&lt;BR /&gt;2015-09-22 20:10:23 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION FAILED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;BR /&gt;====&amp;gt; Failed SA: x.y.z..157[500]-x.y.z..158[500] message id:0x01365B68 &amp;lt;==== Due to negotiation timeout.&lt;BR /&gt;2015-09-22 20:10:23 [PROTO_NOTIFY]: phase-2 negotiation failed. delete stale phase-1 SA.&lt;BR /&gt;2015-09-22 20:10:23 [INFO]: ====&amp;gt; PHASE-1 SA DELETED &amp;lt;====&lt;BR /&gt;====&amp;gt; Deleted SA: x.y.z..157[500]-x.y.z..158[500] cookie:bb97b04a7db888f8:402f8a7370dc2e35 &amp;lt;====&lt;BR /&gt;2015-09-22 20:10:23 [INFO]: IPsec-SA request for x.y.z..158 queued since no phase1 found&lt;BR /&gt;2015-09-22 20:10:23 [PROTO_NOTIFY]: ====&amp;gt; PHASE-1 NEGOTIATION STARTED AS INITIATOR, MAIN MODE &amp;lt;====&lt;BR /&gt;====&amp;gt; Initiated SA: x.y.z..157[500]-x.y.z..158[500] cookie:5811ea271afc695f:0000000000000000 &amp;lt;====&lt;BR /&gt;2015-09-22 20:10:23 [INFO]: received Vendor ID: DPD&lt;BR /&gt;2015-09-22 20:10:23 [PROTO_NOTIFY]: ====&amp;gt; PHASE-1 NEGOTIATION SUCCEEDED AS INITIATOR, MAIN MODE &amp;lt;====&lt;BR /&gt;====&amp;gt; Established SA: x.y.z..157[500]-x.y.z..158[500] cookie:5811ea271afc695f:fe7fe1dface0fb0b lifetime 28800 Sec &amp;lt;====&lt;BR /&gt;2015-09-22 20:10:23 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;BR /&gt;====&amp;gt; Initiated SA: x.y.z..157[500]-x.y.z..158[500] message id:0xCE9673F6 &amp;lt;====&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;My config:&lt;BR /&gt;/ip ipsec proposal&lt;BR /&gt;set [ find default=yes ] auth-algorithms=md5,sha1 enc-algorithms=aes-128-cbc,aes-256-cbc,aes-128-ctr,aes-256-ctr lifetime=8h&lt;BR /&gt;/ip ipsec peer&lt;BR /&gt;add address=x.y.z..157/32 dpd-interval=disable-dpd enc-algorithm=aes-256 lifetime=8h nat-traversal=no secret="passw0rd"&lt;BR /&gt;/ip ipsec policy&lt;BR /&gt;set 0 disabled=yes dst-address=192.168.1.0/24 src-address=192.168.2.0/24&lt;BR /&gt;add dst-address=192.168.1.0/24 src-address=192.168.2.0/24 template=yes&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Does anyone sucessfully conected PA device with Mikrotik OS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2015 18:26:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/64963#M38855</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-09-22T18:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/64973#M38858</link>
      <description>&lt;P&gt;I have not but here are somethings to look for:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure all the settings are identical, ciphers, timeouts both time and data, etc. Also make sure you are only using IKE version1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-VPN-Connectivity-Issues/ta-p/59187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-VPN-Connectivity-Issues/ta-p/59187&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2015 20:52:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/64973#M38858</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-09-22T20:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/64983#M38864</link>
      <description>&lt;P&gt;Hi Otakar&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this doc - new info is that in log I have&lt;/P&gt;&lt;PRE&gt; IKEv1 phase-2 negotiation request received when phase-1 SA is not act
ive or expired&lt;/PRE&gt;&lt;P&gt;What does it mean? I have green bubble in IKE section also I see connected peers in Mikrotik.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2015 06:34:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/64983#M38864</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-09-23T06:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65006#M38881</link>
      <description>&lt;P&gt;Try clearing the tunnel and reestablishing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the PAN cli clear vpn ike-sa gateway &amp;lt;name of gateway&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also on the same on the other end. I had an issue with an ASA that was not bringing up a tunnel and it turned out that it was holding onto an old tunnel. Once i cleared it, everything came back up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know I would love to have a list and possible solutions to error messages, perhaps PAN is working on this for us? I only have an internal Cisco doc that some tech put together with common errors and why they are occuring.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2015 14:48:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65006#M38881</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-09-23T14:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65050#M38903</link>
      <description>&lt;P&gt;We have many Mikrotik to PA VPN tunnels up. In fact we have some very complex VPN scenarios implemented between PA and Mikrotik (PA at central office, Mikrotiks at remote location, 2 ISPs on both sides, 4 VPN tunnels with automatic switchover for all combinations).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case I would say there is some setting missing on Mikrotik for phase 2:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Sep/22/2015 20:09:34 ipsec,debug no policy found: 192.168.1.0/24[0] 192.168.2.0/24[0] proto=any dir=in&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;I'm not a Mikrotik expert but I'd say you don't have correct encryption domains (Proxy IDs) set on Mikrotik.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2015 09:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65050#M38903</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-09-24T09:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65096#M38919</link>
      <description>&lt;P&gt;Hi santonic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could You share some configuration of Microtik?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have few question:&lt;/P&gt;&lt;P&gt;- is DPD 5/5&amp;nbsp; OK?&lt;/P&gt;&lt;P&gt;- are You using tunnel monitoring?&lt;/P&gt;&lt;P&gt;- are You use in policy &amp;gt; action &amp;gt; level reguire or unique? according to manual should be unique but it not working for me&lt;/P&gt;&lt;P&gt;- I'm using RB951 - when passing 30Mb/s CPU of RB is 100%, I tryed with md5/sha1 aes/3des but I not get any change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mikrotic has one LAN 192.168.2.0/24, PA has few LANs: 192.168.1.0/24 and 192.168.x.0/24, Internet trafffic from Mikrotik must go by VPN tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Mikrotik config (ipsec part)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Route:
Flags: X - disabled, A - active, D - dynamic, 
C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, 
B - blackhole, U - unreachable, P - prohibit 
 #      DST-ADDRESS        PREF-SRC        GATEWAY            DISTANCE
 0 A S  0.0.0.0/0                          x.y.z.129             1
 1 ADC  x.y.z.128/26   x.y.z.158   WAN                       0
 2 A S  192.168.1.0/24                     WAN                       1
 3 ADC  192.168.2.0/24     192.168.2.1     LAN bridge                0

Policy:
  1     src-address=192.168.2.0/24 src-port=any dst-address=192.168.1.0/24 
       dst-port=any protocol=all action=encrypt level=require 
       ipsec-protocols=esp tunnel=yes sa-src-address=x.y.z.158 
       sa-dst-address=x.y.z.157 proposal=proposal2 priority=0 

 2     src-address=192.168.2.0/24 src-port=any dst-address=0.0.0.0/0 dst-port=any 
       protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes 
       sa-src-address=x.y.z.158 sa-dst-address=x.y.z.157 
       proposal=proposal2 priority=0 

Peer:
 0    address=x.y.z.157/32 local-address=:: passive=no port=500 
      auth-method=pre-shared-key secret="xxxxxx" generate-policy=no 
      policy-template-group=group1 exchange-mode=main mode-config=request-only 
      send-initial-contact=no nat-traversal=no proposal-check=obey 
      hash-algorithm=sha1 enc-algorithm=aes-256 dh-group=modp1024 lifetime=8h 
      lifebytes=0 dpd-interval=5s dpd-maximum-failures=5&lt;/PRE&gt;&lt;P&gt;And - maybe stupid qustion - how to verify is it working properly? I'm new in ipsec VPN and I worry about problems. What I should verify? now everything is OK (in my opinion) but now devices are in LAN and I get about 5% loss of pings packet.&lt;/P&gt;&lt;P&gt;I'm worry how it will act in real scenario...&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 11:56:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65096#M38919</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-09-25T11:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65097#M38920</link>
      <description>&lt;P&gt;uhh I figured it out (I hope)&lt;/P&gt;&lt;P&gt;Now tunnel is up ... but I havent any misconfiguration - in GUI everything was OK but ...&lt;/P&gt;&lt;P&gt;I started veryfication from CLI and I realised that from CLI polisy is broken (missed part about SA). I deleted it and created again - and - surprice !!! its working ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So lesson for me and You - use CLI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 12:09:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65097#M38920</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-09-25T12:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65102#M38921</link>
      <description>&lt;P&gt;Glad you got it working.&lt;/P&gt;&lt;P&gt;DPD doesn't matter when establishing IPSEC for the first time. Also don't use tunnel monitor before establishing VPN for the first time.&lt;/P&gt;&lt;P&gt;Yeah, CLI "test vpn" is very useful. It's also in WebUI from 7.0.0 but I haven't tried it yet.&lt;/P&gt;&lt;P&gt;The ultimate test for VPN is always to send some traffic through it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 13:24:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65102#M38921</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-09-25T13:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65105#M38923</link>
      <description>&lt;P&gt;I observed another strange behaviour ...&lt;/P&gt;&lt;P&gt;My workstation has IP 192.168.1.35 and its connected to PAN device&lt;/P&gt;&lt;P&gt;Laptop with 192.168.2.200 is connected to Mikrotik&lt;/P&gt;&lt;P&gt;If is lunched ping from laptop to 192.168.1.1 and I try to start pinging from my workstation to laptop IP after few packet I get&lt;/P&gt;&lt;PRE&gt;Badanie 192.168.2.200 z 32 bajtami danych:
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=2ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=2ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=2ms TTL=126
Upłynął limit czasu żądania.
Upłynął limit czasu żądania.
Upłynął limit czasu żądania.
Upłynął limit czasu żądania.
Upłynął limit czasu żądania.&lt;/PRE&gt;&lt;P&gt;but ... when I stoped ping from laptop&amp;nbsp; imiditellly ping from my workstation starting pinging OK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone idea whats going on? how to troubleshoot this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tryed to copy big files in both direction and everything is OK ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reagrds&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 13:31:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65105#M38923</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-09-25T13:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65107#M38924</link>
      <description>&lt;P&gt;Check logs if your VPN is going up and down. Pings would get lost while TCP connections would survive in such case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 13:40:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65107#M38924</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-09-25T13:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65120#M38931</link>
      <description>&lt;P&gt;I observed another strange behaviour ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sit down - take a deep breath .... and read&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My workstation has IP 192.168.1.35 and its connected to PAN device&lt;/P&gt;&lt;P&gt;Laptop with 192.168.2.200 is connected to Mikrotik&lt;/P&gt;&lt;P&gt;If is lunched ping from laptop to 192.168.1.1 and I try to start pinging from my workstation to laptop IP after few packet I get&lt;/P&gt;&lt;PRE&gt;Badanie 192.168.2.200 z 32 bajtami danych:
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=2ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=1ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=2ms TTL=126
Odpowiedź z 192.168.2.200: bajtów=32 czas=2ms TTL=126
Upłynął limit czasu żądania.
Upłynął limit czasu żądania.
Upłynął limit czasu żądania.
Upłynął limit czasu żądania.
Upłynął limit czasu żądania.&lt;/PRE&gt;&lt;P&gt;but ... when I stoped ping from laptop&amp;nbsp; imiditellly ping from my workstation starting pinging OK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone idea whats going on? how to troubleshoot this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tryed to copy big files in both direction and everything is OK ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reagrds&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 17:11:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65120#M38931</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-09-25T17:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65121#M38932</link>
      <description>&lt;P&gt;Do the traffic logs show anything?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 18:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65121#M38932</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-09-25T18:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65133#M38937</link>
      <description>&lt;P&gt;Of course Yes. some details - maybe it will be useful lto find some odds&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/468i2766FA384F93AF35/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="2015-09-26_115601.png" title="2015-09-26_115601.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;details of "1"&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/469iE9E2DDC8AA6B3186/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="2015-09-26_115652.png" title="2015-09-26_115652.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;details of "2"&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/470iD38CB234EBFAF7DB/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="2015-09-26_115718.png" title="2015-09-26_115718.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;the same from CLI&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/471iA478817B04A6C2E8/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="2015-09-26_114954.png" title="2015-09-26_114954.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;Is it normal to have such many session during one "ping" session?&lt;/P&gt;&lt;P&gt;Why the session aged out so quicky?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2015 10:04:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65133#M38937</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-09-26T10:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65136#M38940</link>
      <description>&lt;P&gt;heh I GOT it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;problem with ping was related to firwall rule on Mikrotik. This rule make limitations - afer diabling - ping working perfectly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2015 12:58:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65136#M38940</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-09-26T12:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65201#M38959</link>
      <description>&lt;P&gt;Glad to hear you got it working properly! If you have a basic writeup perhaps consider posting it for other users to reference?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2015 16:12:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/65201#M38959</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-09-28T16:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: vpn s2s with Mikrotik router - proxy id problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/66403#M39186</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After few weeks of testings in real networks (not in my lab) I have to say - it doesnt wroking stable ... I have to leave it now as it is. I will back to it&amp;nbsp; later.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 08:08:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-s2s-with-mikrotik-router-proxy-id-problem/m-p/66403#M39186</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2015-10-12T08:08:48Z</dc:date>
    </item>
  </channel>
</rss>

