<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proxy IDs help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/69063#M40143</link>
    <description>&lt;P&gt;Hi Satish,&lt;/P&gt;
&lt;P&gt;I'm having a problem with Proxy-ID mismatch. This is between a PAN Firewall and a Cisco 3G router. For my local Proxy ID on the PAN, I have configured 10.5.0.0/16. However, when I look at the logs, it says 'received local id is X.X.X.X'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;where X.X.X.X is the public interface of the PAN. I can't figure out why.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, is a NAT-exempt rule required for my Local Proxy-ID?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Dec 2015 10:32:44 GMT</pubDate>
    <dc:creator>Bocsa</dc:creator>
    <dc:date>2015-12-07T10:32:44Z</dc:date>
    <item>
      <title>Proxy IDs help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3575#M2634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Palo Alto Firewall which wants to have IPsec Tunnel with a peer firewall which is a Checkpoint Firewall. Any of the firewalls can initiate VPN Traffic. &lt;/P&gt;&lt;P&gt;Can someone kindly let me know, what proxy IDs can be set on my Palo alto firewall for the following 2 cases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Case 1:&lt;/P&gt;&lt;P&gt;My internal networks for VPN (Palo Alto Firewall) : 172.16.10.0/24 , 10.31.0.0/16, 10.40.40.0/24&lt;/P&gt;&lt;P&gt;Networks behind the peer (Checkpoint Firewall) : Unknown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Case 2&lt;/P&gt;&lt;P&gt;My internal networks for VPN (Palo Alto Firewall) : 172.16.10.0/24 , 10.31.0.0/16, 10.40.40.0/24&lt;/P&gt;&lt;P&gt;Networks behind the peer (Checkpoint Firewall) : Exactly same i.e. 172.16.10.0/24 , 10.31.0.0/16, 10.40.40.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot !!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2014 07:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3575#M2634</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-11-13T07:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy IDs help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3576#M2635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PROXY ID's are required to define the SPI key's in the IPSec VPN. SPI is a key pair, used for encapsulation and decapsulation of ESP packet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CASE-1: Proxy ID's should be as mentioned below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="proxy-ID.JPG" class="image-0 jive-image" height="284" src="https://live.paloaltonetworks.com/legacyfs/online/16855_proxy-ID.JPG" style="height: 283.761290322581px; width: 486px;" width="486" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CASE-2: You have to follow the DOC&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; :&lt;/SPAN&gt; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1594"&gt;Configuring route based IPSec with overlapping networks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference Info&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;:&lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/message/17561"&gt;Re: IPsec VPN Tunnel with overlapping subnets.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2014 07:22:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3576#M2635</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-13T07:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy IDs help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3577#M2636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply! A few more questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Do I always have to mention 0.0.0.0/0 as remote proxy id or can i leave it blank?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Do I also have to add the IP Addresses of External Interfaces of Palo Alto and Peer Firewalls, in the Proxy IDs List ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Nov 2014 10:42:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3577#M2636</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-11-24T10:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy IDs help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3578#M2637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ans 1:- you cant do this.&lt;/P&gt;&lt;P&gt;2;-&amp;nbsp; yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Nov 2014 11:49:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3578#M2637</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-11-24T11:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy IDs help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3579#M2638</link>
      <description>&lt;P&gt;Hi Amit,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It may be help&amp;nbsp; you in configuration.....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6791" target="_self"&gt;How to Configure IPSec VPN&lt;/A&gt;&lt;/P&gt;
&lt;P class="f kv _SWb" style="color: #808080; font-family: arial, sans-serif; font-size: small;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="f kv _SWb" style="color: #808080; font-family: arial, sans-serif; font-size: small;"&gt;Thnx&lt;/P&gt;
&lt;P class="f kv _SWb" style="color: #808080; font-family: arial, sans-serif; font-size: small;"&gt;Satish&lt;/P&gt;
&lt;DIV class="action-menu ab_ctl" style="margin: 0 3px;"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 07 Dec 2015 17:50:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3579#M2638</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2015-12-07T17:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy IDs help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3580#M2639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your reply! Everything works now!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Nov 2014 11:20:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/3580#M2639</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-11-25T11:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy IDs help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/69063#M40143</link>
      <description>&lt;P&gt;Hi Satish,&lt;/P&gt;
&lt;P&gt;I'm having a problem with Proxy-ID mismatch. This is between a PAN Firewall and a Cisco 3G router. For my local Proxy ID on the PAN, I have configured 10.5.0.0/16. However, when I look at the logs, it says 'received local id is X.X.X.X'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;where X.X.X.X is the public interface of the PAN. I can't figure out why.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, is a NAT-exempt rule required for my Local Proxy-ID?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 10:32:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/69063#M40143</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2015-12-07T10:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy IDs help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/69254#M40233</link>
      <description>&lt;P&gt;&lt;SPAN&gt;'received local id is X.X.X.X'&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I believe this is telling you that the Cisco is sending the proxy-id with your public ip address. &amp;nbsp;You will need to check the configuration on that side to remove this setting and put in the ACL on the Cisco tunnel that you need.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 11:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/proxy-ids-help/m-p/69254#M40233</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-12-09T11:11:50Z</dc:date>
    </item>
  </channel>
</rss>

