<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic third party VPN clients with PanOS 7.0.3 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/third-party-vpn-clients-with-panos-7-0-3/m-p/68965#M40109</link>
    <description>&lt;P&gt;I was curious if anybody else has seen this issue, or could perhaps try to duplicate it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem with third party VPN clients after upgrading from PanOS 6.1.6 to 7.0.3 on our PA-3020s.&amp;nbsp; Specifically, the built-in IPSec VPN client on Mac OSX (10.11/el capitan) and iOS (9.1).&amp;nbsp; They can connect, but a simple ping test shows packet loss near 50%.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been able to duplicate with 4 different clients and 2 different sites.&amp;nbsp; Strangely, I can NOT duplicate the problem when connecting to sites with PA-200s.&amp;nbsp; All sites are setup as an HA pair.&amp;nbsp; All firewalls are running 7.0.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was also not able to duplicate the issue with the ShrewSoft VPN client on Windows 7.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Global Protect client works fine on the OSX devies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Packet captures on the firewall don't indicate any issue.&amp;nbsp; All packets seem to traverse properly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem started right after the PanOS upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have an open support case with PaloAlto, but I wanted to see if anybody in the forums has seen this.&amp;nbsp; I noticed the other threads indicating problems with 7.0.x, but nothing related to this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;client (version) + site (model) = result&lt;BR /&gt;---&lt;BR /&gt;Mac OSX (10.11) + site_A (PA-3020) = problem&lt;BR /&gt;iOS (9.1) + site_A (PA-3020) = problem&lt;BR /&gt;Mac OSX (10.11) + site_B (PA-3020) = problem&lt;BR /&gt;iOS (9.1) + site_B (PA-3020) = problem&lt;BR /&gt;&lt;BR /&gt;Mac OSX (10.11) + site_C (PA-200) = ok&lt;BR /&gt;iOS (9.1) + site_C (PA-200) = ok&lt;BR /&gt;Mac OSX (10.11) + site_D (PA-200) = ok&lt;BR /&gt;iOS (9.1) + site_D (PA-200) = ok&lt;BR /&gt;&lt;BR /&gt;Windows 7 w/ Shrew Soft VPN Client (2.1.7) + site_A (PA-3020) = ok&lt;BR /&gt;Windows 7 w/ Shrew Soft VPN Client (2.1.7) + site_B (PA-3020) = ok&lt;BR /&gt;Windows 7 w/ Shrew Soft VPN Client (2.1.7) + site_C (PA-200) = ok&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2015 15:51:51 GMT</pubDate>
    <dc:creator>alowther_chatham</dc:creator>
    <dc:date>2015-12-03T15:51:51Z</dc:date>
    <item>
      <title>third party VPN clients with PanOS 7.0.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/third-party-vpn-clients-with-panos-7-0-3/m-p/68965#M40109</link>
      <description>&lt;P&gt;I was curious if anybody else has seen this issue, or could perhaps try to duplicate it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem with third party VPN clients after upgrading from PanOS 6.1.6 to 7.0.3 on our PA-3020s.&amp;nbsp; Specifically, the built-in IPSec VPN client on Mac OSX (10.11/el capitan) and iOS (9.1).&amp;nbsp; They can connect, but a simple ping test shows packet loss near 50%.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been able to duplicate with 4 different clients and 2 different sites.&amp;nbsp; Strangely, I can NOT duplicate the problem when connecting to sites with PA-200s.&amp;nbsp; All sites are setup as an HA pair.&amp;nbsp; All firewalls are running 7.0.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was also not able to duplicate the issue with the ShrewSoft VPN client on Windows 7.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Global Protect client works fine on the OSX devies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Packet captures on the firewall don't indicate any issue.&amp;nbsp; All packets seem to traverse properly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem started right after the PanOS upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have an open support case with PaloAlto, but I wanted to see if anybody in the forums has seen this.&amp;nbsp; I noticed the other threads indicating problems with 7.0.x, but nothing related to this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;client (version) + site (model) = result&lt;BR /&gt;---&lt;BR /&gt;Mac OSX (10.11) + site_A (PA-3020) = problem&lt;BR /&gt;iOS (9.1) + site_A (PA-3020) = problem&lt;BR /&gt;Mac OSX (10.11) + site_B (PA-3020) = problem&lt;BR /&gt;iOS (9.1) + site_B (PA-3020) = problem&lt;BR /&gt;&lt;BR /&gt;Mac OSX (10.11) + site_C (PA-200) = ok&lt;BR /&gt;iOS (9.1) + site_C (PA-200) = ok&lt;BR /&gt;Mac OSX (10.11) + site_D (PA-200) = ok&lt;BR /&gt;iOS (9.1) + site_D (PA-200) = ok&lt;BR /&gt;&lt;BR /&gt;Windows 7 w/ Shrew Soft VPN Client (2.1.7) + site_A (PA-3020) = ok&lt;BR /&gt;Windows 7 w/ Shrew Soft VPN Client (2.1.7) + site_B (PA-3020) = ok&lt;BR /&gt;Windows 7 w/ Shrew Soft VPN Client (2.1.7) + site_C (PA-200) = ok&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 15:51:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/third-party-vpn-clients-with-panos-7-0-3/m-p/68965#M40109</guid>
      <dc:creator>alowther_chatham</dc:creator>
      <dc:date>2015-12-03T15:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: third party VPN clients with PanOS 7.0.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/third-party-vpn-clients-with-panos-7-0-3/m-p/68967#M40111</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know if we have the same issue, I also experienced some other bug with GP and because of them I had to downgrad to 6.1.8. But thank you for the information, this would be another reason for not upgrading &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Do you configured your globalprotect gateways on loopback interfaces? if yes, then the problem might be the known issue 69458: Traffic for third-party IPSec clients is not routed correctly when using a loopback interface for a GlobalProtect gateway.&lt;/P&gt;
&lt;P&gt;Workaround: Use a physical interface instead of a loopback interface as the GlobalProtect gateway for third-party IPSec clients. Alternatively, configure the loopback interface that is used as the GlobalProtect gateway to be in the same zone as the physical ingress interface for third-party IPSec traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 16:08:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/third-party-vpn-clients-with-panos-7-0-3/m-p/68967#M40111</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2015-12-03T16:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: third party VPN clients with PanOS 7.0.3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/third-party-vpn-clients-with-panos-7-0-3/m-p/68972#M40115</link>
      <description>&lt;P&gt;Thanks for the tip.&amp;nbsp; The gateway is configured on a physical interface, so that bug wouldn't seem to apply.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 16:56:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/third-party-vpn-clients-with-panos-7-0-3/m-p/68972#M40115</guid>
      <dc:creator>alowther_chatham</dc:creator>
      <dc:date>2015-12-03T16:56:00Z</dc:date>
    </item>
  </channel>
</rss>

