<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71182#M40713</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First - Palo has no IPSec license so not needed.&lt;/P&gt;
&lt;P&gt;Second - Palo supports standards based IPSec so you can do vpn with pretty much every other box out there.&lt;/P&gt;
&lt;P&gt;If you configure "passive mode" on IKE gateway and ask other end to connect to you then you see exactly what does not match in Monitor &amp;gt; System log&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2016 14:48:28 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2016-01-19T14:48:28Z</dc:date>
    <item>
      <title>IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71179#M40711</link>
      <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First - Do you need a IPSEC license for a PAN-VM?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Second - Can I follow the PAN guide for - "IPSEC interoperaability between Palo Alto Firewalls and CISCO ASA"? The reason I ask is the guide show conifguration between a PAN-5060 and a ASA 5505.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Third - Has anyone done this configuration? and are there things to watch for?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dana&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 14:13:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71179#M40711</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-19T14:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71181#M40712</link>
      <description>&lt;P&gt;Hi There&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;no license is needed to be able to support IPSEC on any firewall platform&lt;/P&gt;
&lt;P&gt;all&amp;nbsp;firewalls share the same functionality, the only difference is capacity based on the platform (amount of sessions and throughput basically) so that guide will apply to the PA-VM as well&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 14:46:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71181#M40712</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-01-19T14:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71182#M40713</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First - Palo has no IPSec license so not needed.&lt;/P&gt;
&lt;P&gt;Second - Palo supports standards based IPSec so you can do vpn with pretty much every other box out there.&lt;/P&gt;
&lt;P&gt;If you configure "passive mode" on IKE gateway and ask other end to connect to you then you see exactly what does not match in Monitor &amp;gt; System log&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 14:48:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71182#M40713</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-01-19T14:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71195#M40718</link>
      <description>&lt;P&gt;Thanks, I try it and get back to you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dana&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 15:50:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71195#M40718</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-19T15:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71197#M40720</link>
      <description>&lt;P&gt;Hi Burtond,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As others have mentioned, NO license is required for setting up IPSEC VPN on Palo alto firewalls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding setting up a VPN with Cisco, I would advise you to keep in mind that the "proxy-IDs" match (vice-versa) exactly as on Cisco since Cisco doesnt like 0/0 proxy IDs. This is a common gotcha when dealing with IPSEC between Cisco and other vendors (which support 0/0 proxy IDs)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2016 15:58:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71197#M40720</guid>
      <dc:creator>syadav</dc:creator>
      <dc:date>2016-01-19T15:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71273#M40740</link>
      <description>&lt;P&gt;Phase 1 and phase 2 life time should be checked.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2016 17:32:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71273#M40740</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-01-20T17:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71719#M40903</link>
      <description>&lt;P&gt;Thanks for updates... I will pass them on....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PAN document doesn't show how to config IKE 2 for certificates.... does anyone have a document showing it? or has anyone done this?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are getting "peer not matching error" on CISCO&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dana&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 19:28:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71719#M40903</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-27T19:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71721#M40904</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;While I have not used certificates, I have built many tunnels between Cisco and a PAN, same on all version i have worked on so far. As stated before, make sure phase 1 and 2 are identical, also check the 'interesting' traffic, 'Proxy ID's' on the PAN and they must match the 'Crypto map' on the Cisco side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 19:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71721#M40904</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-01-27T19:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71722#M40905</link>
      <description>&lt;P&gt;Also I got this from a Cisco TAC engineer a long time ago....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG id="yui_3_16_0_1_1453923161358_11186"&gt;ADAPTIVE SECURITY APPLIANCE ISAKMP STATES:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG id="yui_3_16_0_1_1453923161358_11182"&gt;MM_WAIT_MSG2:&lt;/STRONG&gt; Initial DH public key sent to responder. Awaiting initial contact reply from other side. If stuck here it usually means the other end is not responding. This could be due to no route to the far end, the far end does not have ISAKMP enabled on the outside, the far end is down or DES isn't accepted as the encryption algorithm of the ISAKMP policy.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG id="yui_3_16_0_1_1453923161358_11178"&gt;MM_WAIT_MSG3:&lt;/STRONG&gt; Both peers have agreed on the ISAKMP policies. Awaiting exchange of keyring information. Hang up’s here may be due to mismatch device vendors, a router with a firewall in the way, or even ASA version mismatches.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG id="yui_3_16_0_1_1453923161358_11177"&gt;MM_WAIT_MSG4:&lt;/STRONG&gt; In this step the pre-share key hashes are exchanged. They are not compared or checked, only sent. If one side sends a key and does not receive a key back, this is where the tunnel will fail. I have seen the tunnel fail at this step due to the remote side having the wrong Peer IP address. Hang up’s here may also be due to mismatch device vendors, a router with a firewall in the way, or even ASA version mismatches.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG id="yui_3_16_0_1_1453923161358_11126"&gt;MM_WAIT_MSG5:&lt;/STRONG&gt; This step is where the devices exchange pre-shared keys. If the pre-shared keys do not match it will stay at this MSG. I have also seen the tunnel stop here when NAT Traversal was on when it needed to be turned off.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG id="yui_3_16_0_1_1453923161358_11176"&gt;MM_WAIT_MSG6:&lt;/STRONG&gt; This step is where the devices exchange pre-shared keys. If the pre-shared keys do not match it will stay at this MSG. I have also seen the tunnel stop here when NAT Traversal was on when it needed to be turned off. However, if the state goes to MSG6 then the ISAKMP gets reset that means phase 1 finished but phase 2 failed. Check that IPSEC settings match in phase 2 to get the tunnel to MM_ACTIVE.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG&gt;AM_ACTIVE / MM_ACTIVE:&lt;/STRONG&gt; The ISAKMP negotiations are complete. Phase 1 has successfully completed.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG&gt;MM_NO_STATE:&lt;/STRONG&gt; ISAKMP SA has been created but nothing else has happened yet.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG&gt;MM_SA_SETUP:&lt;/STRONG&gt; The peers have agreed on parameters for the ISAKMP SA.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG&gt;MM_KEY_EXCH:&lt;/STRONG&gt; The peers have exchanged Diffie-Hellman public keys and have generated a shared secret. The I SAKMP SA remains unauthenticated.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG&gt;MM_KEY_AUTH:&lt;/STRONG&gt; The ISAKMP SA has been authenticated. If the router initiated this exchange, this state transitions immediately to QM_IDLE and a Quick mode exchange begins.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG&gt;AG_NO_STATE:&lt;/STRONG&gt; The ISAKMP SA has been created but nothing else has happened yet.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG&gt;AG_INIT_EXCH:&lt;/STRONG&gt; The peers have done the first exchange in Aggressive mode but the SA is not authenticated.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG&gt;AG_AUTH:&lt;/STRONG&gt; The ISAKMP SA has been authenticated. If the router initiated this exchange, this state transitions immediately to QM_IDLE and a Quick mode exchange begins.&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="yiv0568087386MsoNormal"&gt;&lt;STRONG&gt;QM_IDLE:&lt;/STRONG&gt; The ISAKMP negotiations are complete. Phase 1 successfully completed. It remains authenticated with its peer and may be used for subsequent Quick mode exchanges.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 19:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71722#M40905</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-01-27T19:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71764#M40921</link>
      <description>&lt;P&gt;Thanks I'll look these over and pass them on.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 13:15:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71764#M40921</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-28T13:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71769#M40926</link>
      <description>&lt;P&gt;It was the Crypto Map and Proxy ID config.... all is working, not with certificates yet but, tunnel is up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dana&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 14:35:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/71769#M40926</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-28T14:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC interoperability - PAN-VM-200 to CISCO ASA 5505</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/101404#M44501</link>
      <description>&lt;P&gt;Hiya, Have you managed to get certificates working between ASA and Palo Alto? We are getting the following error messages. Thanks, Paul&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2016-08-08 12:44:02 [PROTO_ERR]: RSA_verify failed: 4112512720:error:04091064:rsa routines:INT_RSA_VERIFY:algorithm mismatch:rsa_sign.c:269:&lt;/P&gt;&lt;P&gt;2016-08-08 12:44:02 [PROTO_ERR]: Invalid SIG.&lt;/P&gt;&lt;P&gt;2016-08-08 12:44:02 [PROTO_ERR]: 30779:y.y.y.y[500] - x.x.x.x[500]:0x8a44598:authentication failure&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 13:22:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-interoperability-pan-vm-200-to-cisco-asa-5505/m-p/101404#M44501</guid>
      <dc:creator>woolp4</dc:creator>
      <dc:date>2016-08-08T13:22:31Z</dc:date>
    </item>
  </channel>
</rss>

