<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OpenVPN behind PaloAlto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68544#M39955</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can't get OpenVPN to work. Our Juniper-SA works well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The setup is only working &lt;EM&gt;without&lt;/EM&gt; Firewall:&lt;/P&gt;
&lt;P&gt;Laptop (static IP 80.0.0.4) attachted to an switch and the OpenVPN server attached to the same switch (eth1, dmz)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our Policies:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1324i240BDE938F915B95/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="palo-config-policy3.png" title="palo-config-policy3.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Monitor:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1325i1A2DBC166FF70423/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="palo-config-monitor.png" title="palo-config-monitor.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;Konfig - OpenVPN server&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt; DMZ:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;iface eth1 inet static&lt;BR /&gt;address 80.0.0.5&lt;BR /&gt;netmask 255.255.255.248&lt;BR /&gt;gateway 80.0.0.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Local:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;iface eth0 inet static&lt;/P&gt;
&lt;P&gt;address 172.16.0.2&lt;BR /&gt;netmask 255.255.255.0&lt;BR /&gt;gateway 172.16.0.254&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know about this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://openvpn.net/index.php/open-source/faq/79-client/253-tls-error-tls-key-negotiation-failed-to-occur-within-60-seconds-check-your-network-connectivity.html" target="_blank"&gt;https://openvpn.net/index.php/open-source/faq/79-client/253-tls-error-tls-key-negotiation-failed-to-occur-within-60-seconds-check-your-network-connectivity.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But ist doesn't help &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone help me? Thanks a lot!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error OpenVPN Client:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Mon Nov 23 11:59:33 2015 NOTE: --user option is not implemented on Windows
Mon Nov 23 11:59:33 2015 NOTE: --group option is not implemented on Windows
Mon Nov 23 11:59:33 2015 OpenVPN 2.3.8 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on Aug 4 2015
Mon Nov 23 11:59:33 2015 library versions: OpenSSL 1.0.1p 9 Jul 2015, LZO 2.08
Mon Nov 23 11:59:33 2015 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Mon Nov 23 11:59:33 2015 Need hold release from management interface, waiting...
Mon Nov 23 11:59:34 2015 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Mon Nov 23 11:59:34 2015 MANAGEMENT: CMD 'state on'
Mon Nov 23 11:59:34 2015 MANAGEMENT: CMD 'log all on'
Mon Nov 23 11:59:34 2015 MANAGEMENT: CMD 'hold off'
Mon Nov 23 11:59:34 2015 MANAGEMENT: CMD 'hold release'
Mon Nov 23 11:59:34 2015 Socket Buffers: R=[8192-&amp;gt;8192] S=[8192-&amp;gt;8192]
Mon Nov 23 11:59:34 2015 UDPv4 link local: [undef]
Mon Nov 23 11:59:34 2015 UDPv4 link remote: [AF_INET]80.0.0.5:1194
Mon Nov 23 11:59:34 2015 MANAGEMENT: &amp;gt;STATE:1448276374,WAIT,,,
Mon Nov 23 12:00:34 2015 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Nov 23 12:00:34 2015 TLS Error: TLS handshake failed
Mon Nov 23 12:00:34 2015 SIGUSR1[soft,tls-error] received, process restarting
Mon Nov 23 12:00:34 2015 MANAGEMENT: &amp;gt;STATE:1448276434,RECONNECTING,tls-error,,
Mon Nov 23 12:00:34 2015 Restart pause, 2 second(s)
Mon Nov 23 12:00:36 2015 Socket Buffers: R=[8192-&amp;gt;8192] S=[8192-&amp;gt;8192]
Mon Nov 23 12:00:36 2015 UDPv4 link local: [undef]
Mon Nov 23 12:00:36 2015 UDPv4 link remote: [AF_INET]80.0.0.5:1194
Mon Nov 23 12:00:36 2015 MANAGEMENT: &amp;gt;STATE:1448276436,WAIT,,,
Mon Nov 23 12:01:36 2015 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Nov 23 12:01:36 2015 TLS Error: TLS handshake failed
Mon Nov 23 12:01:36 2015 SIGUSR1[soft,tls-error] received, process restarting
Mon Nov 23 12:01:36 2015 MANAGEMENT: &amp;gt;STATE:1448276496,RECONNECTING,tls-error,,
Mon Nov 23 12:01:36 2015 Restart pause, 2 second(s)
Mon Nov 23 12:01:38 2015 Socket Buffers: R=[8192-&amp;gt;8192] S=[8192-&amp;gt;8192]
Mon Nov 23 12:01:38 2015 UDPv4 link local: [undef]
Mon Nov 23 12:01:38 2015 UDPv4 link remote: [AF_INET]80.0.0.5:1194
Mon Nov 23 12:01:38 2015 MANAGEMENT: &amp;gt;STATE:1448276498,WAIT,,,&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2015 07:56:00 GMT</pubDate>
    <dc:creator>Morneweg</dc:creator>
    <dc:date>2015-12-01T07:56:00Z</dc:date>
    <item>
      <title>OpenVPN behind PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68544#M39955</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can't get OpenVPN to work. Our Juniper-SA works well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The setup is only working &lt;EM&gt;without&lt;/EM&gt; Firewall:&lt;/P&gt;
&lt;P&gt;Laptop (static IP 80.0.0.4) attachted to an switch and the OpenVPN server attached to the same switch (eth1, dmz)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our Policies:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1324i240BDE938F915B95/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="palo-config-policy3.png" title="palo-config-policy3.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Monitor:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1325i1A2DBC166FF70423/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="palo-config-monitor.png" title="palo-config-monitor.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;Konfig - OpenVPN server&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt; DMZ:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;iface eth1 inet static&lt;BR /&gt;address 80.0.0.5&lt;BR /&gt;netmask 255.255.255.248&lt;BR /&gt;gateway 80.0.0.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Local:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;iface eth0 inet static&lt;/P&gt;
&lt;P&gt;address 172.16.0.2&lt;BR /&gt;netmask 255.255.255.0&lt;BR /&gt;gateway 172.16.0.254&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know about this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://openvpn.net/index.php/open-source/faq/79-client/253-tls-error-tls-key-negotiation-failed-to-occur-within-60-seconds-check-your-network-connectivity.html" target="_blank"&gt;https://openvpn.net/index.php/open-source/faq/79-client/253-tls-error-tls-key-negotiation-failed-to-occur-within-60-seconds-check-your-network-connectivity.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But ist doesn't help &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone help me? Thanks a lot!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error OpenVPN Client:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Mon Nov 23 11:59:33 2015 NOTE: --user option is not implemented on Windows
Mon Nov 23 11:59:33 2015 NOTE: --group option is not implemented on Windows
Mon Nov 23 11:59:33 2015 OpenVPN 2.3.8 x86_64-w64-mingw32 [SSL (OpenSSL)] [LZO] [PKCS11] [IPv6] built on Aug 4 2015
Mon Nov 23 11:59:33 2015 library versions: OpenSSL 1.0.1p 9 Jul 2015, LZO 2.08
Mon Nov 23 11:59:33 2015 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:25340
Mon Nov 23 11:59:33 2015 Need hold release from management interface, waiting...
Mon Nov 23 11:59:34 2015 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:25340
Mon Nov 23 11:59:34 2015 MANAGEMENT: CMD 'state on'
Mon Nov 23 11:59:34 2015 MANAGEMENT: CMD 'log all on'
Mon Nov 23 11:59:34 2015 MANAGEMENT: CMD 'hold off'
Mon Nov 23 11:59:34 2015 MANAGEMENT: CMD 'hold release'
Mon Nov 23 11:59:34 2015 Socket Buffers: R=[8192-&amp;gt;8192] S=[8192-&amp;gt;8192]
Mon Nov 23 11:59:34 2015 UDPv4 link local: [undef]
Mon Nov 23 11:59:34 2015 UDPv4 link remote: [AF_INET]80.0.0.5:1194
Mon Nov 23 11:59:34 2015 MANAGEMENT: &amp;gt;STATE:1448276374,WAIT,,,
Mon Nov 23 12:00:34 2015 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Nov 23 12:00:34 2015 TLS Error: TLS handshake failed
Mon Nov 23 12:00:34 2015 SIGUSR1[soft,tls-error] received, process restarting
Mon Nov 23 12:00:34 2015 MANAGEMENT: &amp;gt;STATE:1448276434,RECONNECTING,tls-error,,
Mon Nov 23 12:00:34 2015 Restart pause, 2 second(s)
Mon Nov 23 12:00:36 2015 Socket Buffers: R=[8192-&amp;gt;8192] S=[8192-&amp;gt;8192]
Mon Nov 23 12:00:36 2015 UDPv4 link local: [undef]
Mon Nov 23 12:00:36 2015 UDPv4 link remote: [AF_INET]80.0.0.5:1194
Mon Nov 23 12:00:36 2015 MANAGEMENT: &amp;gt;STATE:1448276436,WAIT,,,
Mon Nov 23 12:01:36 2015 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
Mon Nov 23 12:01:36 2015 TLS Error: TLS handshake failed
Mon Nov 23 12:01:36 2015 SIGUSR1[soft,tls-error] received, process restarting
Mon Nov 23 12:01:36 2015 MANAGEMENT: &amp;gt;STATE:1448276496,RECONNECTING,tls-error,,
Mon Nov 23 12:01:36 2015 Restart pause, 2 second(s)
Mon Nov 23 12:01:38 2015 Socket Buffers: R=[8192-&amp;gt;8192] S=[8192-&amp;gt;8192]
Mon Nov 23 12:01:38 2015 UDPv4 link local: [undef]
Mon Nov 23 12:01:38 2015 UDPv4 link remote: [AF_INET]80.0.0.5:1194
Mon Nov 23 12:01:38 2015 MANAGEMENT: &amp;gt;STATE:1448276498,WAIT,,,&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 07:56:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68544#M39955</guid>
      <dc:creator>Morneweg</dc:creator>
      <dc:date>2015-12-01T07:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN behind PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68548#M39957</link>
      <description>&lt;P&gt;Should I create routes on the interfaces!? If so, is this OK?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1326i2CE38F9E13770FDF/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="palo-untrust.png" title="palo-untrust.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1327i7E390836C27A0977/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="palo-trust.png" title="palo-trust.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Chears!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 15:32:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68548#M39957</guid>
      <dc:creator>Morneweg</dc:creator>
      <dc:date>2015-11-24T15:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN behind PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68596#M39988</link>
      <description>&lt;P&gt;It's easier if you have both interfaces in the same virtual router so you don't have to create routes. If the external (internet) interface and the internal (Open vpn server) interface are on different virtual routers you need to create inter-VR routing only a route in the "untrust" would be needed as the the return route (default route in trust VR) is already in place.&lt;/P&gt;
&lt;P&gt;I recommend you to enable ping for the test and validate you can reach the server (it has 2 default routes which can cause problems).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Gerardo,&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 00:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68596#M39988</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2015-11-25T00:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN behind PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68684#M40019</link>
      <description>&lt;P&gt;Hi! I Have changed the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OpenVPN Server (client and server config:&lt;/P&gt;
&lt;P&gt;tcp 443 (udp 1194 old config)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I can see this log entries:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1365iF0F1DC49834921FC/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="palo-monitor-incomplete.png" title="palo-monitor-incomplete.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;routes only vr-untrust:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1366i1CC726062A7AB56D/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="palo-untrust-only.png" title="palo-untrust-only.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interfaces:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1367iD8BACDA7681FB9CB/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="palo-interfaces.png" title="palo-interfaces.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but it doesn't work &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 09:21:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68684#M40019</guid>
      <dc:creator>Morneweg</dc:creator>
      <dc:date>2015-11-26T09:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN behind PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68699#M40022</link>
      <description>&lt;P&gt;I have created an Application Override:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Tips-amp-Tricks-How-to-Create-an-Application-Override/ta-p/65513&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is wrong? it doesn't work &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1372i2AC4144CD33AF600/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="1over01.png" title="1over01.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1373i07B2051B255569F8/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="2over01.png" title="2over01.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1374iF2E794C7D240DBB9/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="over01.png" title="over01.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1375i3CC3BCA0781EB9DF/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="over02.png" title="over02.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1376iAD6BC52D96947659/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="over03.png" title="over03.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1377i1B40BABF78A05A5C/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="over04.png" title="over04.png" border="0" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 10:31:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68699#M40022</guid>
      <dc:creator>Morneweg</dc:creator>
      <dc:date>2015-11-26T10:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN behind PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68730#M40034</link>
      <description>&lt;P&gt;I have test a few confguration settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have installed an ftp-server in the dmz with the ip-address: 80.0.0.5 and have set the rule to application "ftp" - &lt;EM&gt;THIS WORKS FINE!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;But PaloAlto blocks OpenVPN Traffic &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Update Status (application defintions):&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1380iDEAE0C0799E6E376/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="04update-status.png" title="04update-status.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Policy Rules:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1381i677364DEBA56FC20/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="01policy.png" title="01policy.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Monitor:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1382i2752A7E903AF3FBD/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="02monitor.png" title="02monitor.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Capture (PaloAlto &amp;gt; Monitor &amp;gt; last action (deny in the screenshot above)&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1383iEAF442352FCE28AF/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="03capture-palo.png" title="03capture-palo.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OpenVPN Server TCPDump:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1384iE0F7FB82FEE4E55F/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="05tcpdump.png" title="05tcpdump.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks four your support!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2015 11:12:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68730#M40034</guid>
      <dc:creator>Morneweg</dc:creator>
      <dc:date>2015-11-27T11:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN behind PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68838#M40070</link>
      <description>&lt;P&gt;I'm sending you different info to play with.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://serverfault.com/questions/709860/fix-tls-error-tls-handshake-failed-on-openvpn-client" target="_blank"&gt;http://serverfault.com/questions/709860/fix-tls-error-tls-handshake-failed-on-openvpn-client&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check the detailed info for the session that says "insufficiant", to see if you have traffic in both directions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do a pcap on the fw, to see what happens. Is there a NAT problem?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You did an app override, for port 443, while all logs you are showing are port 1194. Perhaps you should one for port 1194 as well, plus adding the custom apps to the policy as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When doing a google search on "TLS handshake failed", there are many posts. Here's one of them:&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;A href="https://openvpn.net/index.php/open-source/faq/79-client/253-tls-error-tls-key-negotiation-failed-to-occur-within-60-seconds-check-your-network-connectivity.html" target="_blank"&gt;https://openvpn.net/index.php/open-source/faq/79-client/253-tls-error-tls-key-negotiation-failed-to-occur-within-60-seconds-check-your-network-connectivity.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To better understand the messages the Monitor are giving you, read here:&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Insufficient data in the application field&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Insufficient data means not enough data to identify the application. So for example, if the three-way TCP handshake completed and there was one data packet after the handshake but that one data packet was not enough to match any of our signatures, then user will see insufficient data in the application field of the traffic log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Meaning... The FW doesn't see enogh packets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From this site:&amp;nbsp;&lt;A href="https://openvpn.net/index.php/open-source/documentation/howto.html" target="_blank"&gt;https://openvpn.net/index.php/open-source/documentation/howto.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Troubleshooting&lt;/H3&gt;
&lt;P&gt;If the ping failed or the OpenVPN client initialization failed to complete, here is a checklist of common symptoms and their solutions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You get the error message: &lt;STRONG&gt;TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)&lt;/STRONG&gt;. This error indicates that the client was unable to establish a network connection with the server.
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Solutions&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Make sure the client is using the correct hostname/IP address and port number which will allow it to reach the OpenVPN server.&lt;/LI&gt;
&lt;LI&gt;If the OpenVPN server machine is a single-NIC box inside a protected LAN, make sure you are using a correct port forward rule on the server's gateway firewall. For example, suppose your OpenVPN box is at 192.168.4.4 inside the firewall, listening for client connections on UDP port 1194. The NAT gateway servicing the 192.168.4.x subnet should have a port forward rule that says &lt;STRONG&gt;forward UDP port 1194 from my public IP address to 192.168.4.4&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Open up the server's firewall to allow incoming connections to UDP port 1194 (or whatever TCP/UDP port you have configured in the server config file).&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Good luck.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 09:09:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68838#M40070</guid>
      <dc:creator>gtomte</dc:creator>
      <dc:date>2015-12-01T09:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: OpenVPN behind PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68839#M40071</link>
      <description>&lt;P&gt;I see you use profiles. Anything in the threat logs? Have you tried a policy without profiles?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2015 09:12:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/openvpn-behind-paloalto/m-p/68839#M40071</guid>
      <dc:creator>gtomte</dc:creator>
      <dc:date>2015-12-01T09:12:12Z</dc:date>
    </item>
  </channel>
</rss>

