<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Proxy ID nightmare in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69071#M40151</link>
    <description>&lt;P&gt;GRE is not supported on PA.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Dec 2015 15:14:48 GMT</pubDate>
    <dc:creator>pankaku</dc:creator>
    <dc:date>2015-12-07T15:14:48Z</dc:date>
    <item>
      <title>VPN Proxy ID nightmare</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69064#M40144</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I can't seem to resolve proxy-id mismatch on a Route-based VPN i have configured between the PAN Firewall and a Cisco 3G router.&lt;/P&gt;
&lt;P&gt;On the PAN side, I have configured 10.5.0.0/16 as my local proxy-id and 0.0.0.0 as proxy-id of remote side. I still get a mismatch error as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: X.X.X.X/32 type IPv4_address protocol 47 port 0, received remote id: Y.Y.Y.Y/32 type IPv4_address protocol 47 port 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;where X is outside interface address of the Palo and Y is the interface address of the peer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have also tried to configure Proxy ID of 0.0.0.0/0 for both local and remote on the Palo. No luck&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please can anyone assist?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 11:01:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69064#M40144</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2015-12-07T11:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxy ID nightmare</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69066#M40146</link>
      <description>&lt;P&gt;The proxy ID have to match on both side. It should match means there local become our remote and there remote becomes our local. I think the configured proxy ID on the CISCO is local x.x.x.x/32 remote y.y.y.y/32&lt;/P&gt;
&lt;P&gt;So on the PA sside you have to configure local y.y.y.y/32 and remote x.x.x.x/32&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some thing like this will be on the cisco side&lt;/P&gt;
&lt;P&gt;access-list extended PA_Proxy permit x.x.x.x 0.0.0.0 y.y.y.y 0.0.0.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So there local will become our remote and vice versa.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 12:30:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69066#M40146</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-12-07T12:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxy ID nightmare</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69069#M40149</link>
      <description>&lt;P&gt;I had the same problem. After some debugging and magic touch I saw a GRE packet come out of the tunnel &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or in other words; check if Cisco is trying to establish GRE tunnel instead of IPsec tunnel. If it is, reconfigure&amp;nbsp;Cisco to start&amp;nbsp;IPsec tunnel as GRE is not supported on PA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 14:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69069#M40149</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-12-07T14:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxy ID nightmare</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69070#M40150</link>
      <description>&lt;P&gt;Ok, I&amp;nbsp;read your post again: Cisco is definitelly configured to start GRE tunnel instead of IPsec (hint: &lt;SPAN&gt; protocol 47&lt;/SPAN&gt;)&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 14:38:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69070#M40150</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-12-07T14:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxy ID nightmare</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69071#M40151</link>
      <description>&lt;P&gt;GRE is not supported on PA.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 15:14:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69071#M40151</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-12-07T15:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxy ID nightmare</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69073#M40152</link>
      <description>&lt;P&gt;hi Pakumar,&lt;/P&gt;
&lt;P&gt;I don't have any access-list on the Cisco side because I'm using a tunnel-based VPN on the Cisco side as well. I only have a static route&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 15:24:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69073#M40152</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2015-12-07T15:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxy ID nightmare</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69076#M40153</link>
      <description>&lt;P&gt;Could you please paste some config of cisco device.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 15:54:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69076#M40153</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-12-07T15:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxy ID nightmare</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69082#M40154</link>
      <description>&lt;P&gt;That worked....Thanks a whole lot.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 16:31:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxy-id-nightmare/m-p/69082#M40154</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2015-12-07T16:31:23Z</dc:date>
    </item>
  </channel>
</rss>

