<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-To-Site VPN to VMWare VShield Edge? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-to-vmware-vshield-edge/m-p/78664#M42994</link>
    <description>&lt;P&gt;Halo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Article below will help you to troubleshoot:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 May 2016 15:10:56 GMT</pubDate>
    <dc:creator>Transporter</dc:creator>
    <dc:date>2016-05-25T15:10:56Z</dc:date>
    <item>
      <title>Site-To-Site VPN to VMWare VShield Edge?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-to-vmware-vshield-edge/m-p/78661#M42993</link>
      <description>&lt;P&gt;Greetings all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're in pre-deployment for our firewall and I'm attempting to get an Site-To-Site VPN tunnel set up to our VShield Edge setup in the cloud. &amp;nbsp;I have a tunnel established but we can't seem to get anything across it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Troubleshooting so far:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Verified on the Traffic Monitor I can see my pings going from my inside trusted zone to our Site-To-Site VPN zone and that they're getting aged-out session ends.&lt;/LI&gt;
&lt;LI&gt;"show vpn flow" is showing encap bytes increasing with no change in decap bytes which should mean I'm sending but I'm not receiving from the other side&lt;/LI&gt;
&lt;LI&gt;I have an Interzone allow for any application with both my inside trusted zone and Site-to-Site zone added to the source and destinations&lt;/LI&gt;
&lt;LI&gt;I created a NAT rule to set No-NAT for anything coming from my inside trusted zone to the host on the other side I'm trying to ping&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We have a connection from our existing Cisco ASA to the VShield Edge setup that works and we're able to ping and pass traffic. &amp;nbsp;That setup has Reverse Route Injection configured. &amp;nbsp;The VShield Edge has no static routes configured (for the ASA VPN either) and it's interface is rather limited... apparently we don't have the Advanced Networking license.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone have any ideas or have any experience with this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 14:21:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-to-vmware-vshield-edge/m-p/78661#M42993</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2016-05-25T14:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Site-To-Site VPN to VMWare VShield Edge?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-to-vmware-vshield-edge/m-p/78664#M42994</link>
      <description>&lt;P&gt;Halo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Article below will help you to troubleshoot:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 15:10:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-to-vmware-vshield-edge/m-p/78664#M42994</guid>
      <dc:creator>Transporter</dc:creator>
      <dc:date>2016-05-25T15:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Site-To-Site VPN to VMWare VShield Edge?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-to-vmware-vshield-edge/m-p/78763#M43026</link>
      <description>&lt;P&gt;The issue ended up being with the Tunnel Monitor I had set up. &amp;nbsp;One of the PA techs got me a link to this article:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Tunnel-Monitoring-for-VPN-between-PA-and-ASA/ta-p/68358" target="_self"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Tunnel-Monitoring-for-VPN-between-PA-and-ASA/ta-p/68358&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hadn't realized the monitoring packets are sent out every SA and not only the one that the target host falls in. &amp;nbsp;If any of those don't receive a response back (I'm assuming a "Host not reachable" would even suffice) due to a packet drop, then the tunnel monitor fails and starts trying to re-key constantly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If tunnel monitors could be configured per SA or an SA selected to use for the one tunnel monitor then this could still work the way I was thinking but, the current software only has the one tunnel monitor that sends packets to the destination IP over every SA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our solution is going to be just to use the Dead Peer Detection with the IKE Gateway since the tunnel doesn't require any extrodinary measures to make sure it is up 100% of the time.&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2016 21:23:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-to-vmware-vshield-edge/m-p/78763#M43026</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2016-05-27T21:23:22Z</dc:date>
    </item>
  </channel>
</rss>

