<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ipsec vpn issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-issue/m-p/5803#M4244</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Javith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPSec tunnel is basically for user traffic coming from local Private subnet (10.10.10.x) to the remote private subnet (10.100.100&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;x). So, are you able to ping from source 10.10.10.x to destination 10.100.100&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;x..?&amp;nbsp;&amp;nbsp; Also, if you want to initiate from your external interface IP, then it should be mentioned on the proxy ID's (appropriate local and remote IP's).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Jul 2014 19:32:59 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-07-09T19:32:59Z</dc:date>
    <item>
      <title>ipsec vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-issue/m-p/5802#M4243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I configured ipsec vpn with palo alto to checkpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pinging isp:&lt;/P&gt;&lt;P&gt;local/external ip(182.x.x.x) to peer ip(102.x.x.x) ping successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pinging local network to peer ip:&lt;/P&gt;&lt;P&gt;local pc(10.10.10.x) to peer ip(102.x.x.x) ping unsuccessful..tracert confirm drops on internet..ike not established(verified by &lt;SPAN style="color: #3b3b3b; font-family: 'courier new', courier;"&gt;show vpn ike-sa gateway&lt;/SPAN&gt;)..following vpn troubleshooting doc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping 10.100.100.x(remote ip) from fw cli&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping remote pc (10.100.100.x) and pinging peer ip from firewall cli successful..but prblm is it doesn't take external ip(182.x.x.x) route..it takes another route(customer says vpn is connected to other fw too)&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;so fw takes that routes and successfully pings remote ip&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;then i put this command:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;ping source 182.x.x.x host 102.x..x.x&amp;nbsp; -&amp;gt;successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;ping source 182.x.x.x host 10.100.100.x-&amp;gt;unsuccessful..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; font-size: 10pt;"&gt;after going to system logs-&amp;gt;it shows ike phase 1 aborted msg and sometimes both phase 1 and phase 2 &lt;/SPAN&gt;succeeded logs..but ipsec tunnel is not showing up.&lt;SPAN style="line-height: 1.5em; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Can i tell customer to disconnect same vpn connection which is using another route to reach remote ip successfully(directly connected i think) ??&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Please suggest..&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jul 2014 18:41:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-issue/m-p/5802#M4243</guid>
      <dc:creator>Javith</dc:creator>
      <dc:date>2014-07-09T18:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: ipsec vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-issue/m-p/5803#M4244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Javith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPSec tunnel is basically for user traffic coming from local Private subnet (10.10.10.x) to the remote private subnet (10.100.100&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;x). So, are you able to ping from source 10.10.10.x to destination 10.100.100&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;.&lt;/SPAN&gt;x..?&amp;nbsp;&amp;nbsp; Also, if you want to initiate from your external interface IP, then it should be mentioned on the proxy ID's (appropriate local and remote IP's).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jul 2014 19:32:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-issue/m-p/5803#M4244</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-09T19:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: ipsec vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-issue/m-p/5804#M4245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you check the phase 1 and phase 2 status and see if the tunnel is up and not passing traffic or not coming up at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This document shows how to confirm the status.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3671"&gt;How to Troubleshoot VPN Connectivity Issues&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jul 2014 15:14:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-issue/m-p/5804#M4245</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-07-10T15:14:05Z</dc:date>
    </item>
  </channel>
</rss>

