<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec Site-to-Site between PA-200 and PFSense one direction route only in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/136384#M47630</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like palo works fine. Did you check pfsense logs, security policy and NAT rules (if any)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
    <pubDate>Sun, 08 Jan 2017 10:10:02 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-01-08T10:10:02Z</dc:date>
    <item>
      <title>IPSec Site-to-Site between PA-200 and PFSense one direction route only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/136365#M47628</link>
      <description>&lt;P&gt;Hi All!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I setup a IPSec site-to-site VPN between PA-200 and PfSense using this how to: &lt;A href="https://blog.kingj.net/2014/08/24/how-to/setting-up-a-policy-based-ipsec-vpn-between-a-palo-alto-pa-200-and-pfsense/" target="_blank"&gt;https://blog.kingj.net/2014/08/24/how-to/setting-up-a-policy-based-ipsec-vpn-between-a-palo-alto-pa-200-and-pfsense/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P1 and P2 is ok and I can access network from PA-200 to PfSense but from network PfSense side to PAN network side I can’t access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rodrigo&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jan 2017 22:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/136365#M47628</guid>
      <dc:creator>rodrigo.pires</dc:creator>
      <dc:date>2017-01-07T22:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Site-to-Site between PA-200 and PFSense one direction route only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/136384#M47630</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like palo works fine. Did you check pfsense logs, security policy and NAT rules (if any)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jan 2017 10:10:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/136384#M47630</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-08T10:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Site-to-Site between PA-200 and PFSense one direction route only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138835#M48036</link>
      <description>&lt;P&gt;Thank you for your quickly response.&lt;BR /&gt;&lt;BR /&gt;Sorry for delay, but I was sick in last weeks.&lt;BR /&gt;&lt;BR /&gt;Yes, I checked and I can't see any error.&lt;BR /&gt;&lt;BR /&gt;Before we put Palo Alto, we had 2 PfSense working very well, after when we changed 1 PfSense by Palo Alto the IPsec don't work anymore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 12:47:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138835#M48036</guid>
      <dc:creator>rodrigo.pires</dc:creator>
      <dc:date>2017-01-23T12:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Site-to-Site between PA-200 and PFSense one direction route only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138836#M48037</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do you have your security policy set up?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 12:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138836#M48037</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-23T12:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Site-to-Site between PA-200 and PFSense one direction route only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138878#M48042</link>
      <description>&lt;P&gt;To add to this without displaying any logs or security policies beforehand nobody is going to be able to point you in the right direction. It sounds like the Palo Alto is likely setup perfectly fine but you could be missing a rule on the PA-200 to allow PFSense back into the PA-200 network, or the PFSense could be stopping the traffic before it ever gets to the PA-200.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check over the security policies, double check your route entries on both sides and possibly post screenshots for both. If the tunnel is up perfectly fine then it really sounds like a routing or security rulebase issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 15:49:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138878#M48042</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-23T15:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Site-to-Site between PA-200 and PFSense one direction route only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138897#M48044</link>
      <description>&lt;P&gt;I just did it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SecPol.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7325i956CC3EB68BA23CD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SecPol.PNG" alt="SecPol.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 16:57:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138897#M48044</guid>
      <dc:creator>rodrigo.pires</dc:creator>
      <dc:date>2017-01-23T16:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Site-to-Site between PA-200 and PFSense one direction route only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138902#M48045</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where is your external VPN IP addresss assiged. Into which zone? How is&amp;nbsp;the traffic&amp;nbsp;flowing from &amp;nbsp;PFSense &amp;gt; Palo?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 17:17:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138902#M48045</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-23T17:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Site-to-Site between PA-200 and PFSense one direction route only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138919#M48046</link>
      <description>&lt;P&gt;One thing I would highly recommend is the following.&lt;/P&gt;&lt;P&gt;1) Temporarly override the interzone-default policy and enable log at session start and log at session end. Verify in the logs that you even have a rule allowing the traffic to come back.&lt;/P&gt;&lt;P&gt;2) Once you have the tunnel up what IP address are you assigning these users; they will need a rule to allow them to the specified zones that they need access to.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you have enabled the additional logging you should be able to tell if the traffic is at least being forwared from your PFSense correctly and if it's actually hitting the PA-200. If you aren't seeing the traffic then you need to look at the routing on the PFSense and make sure it's correct, along with any security policy that needs to be in place to allow the traffic. If it's hitting the PA-200 but it's being denied then you need to create a rule to actually allow the traffic to come back in.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The information that you are feeding kinda needs to be more detailed. Currently with the screenshot that you provided I'm unsure which rule(s) you believe are associated with your tunnel. Generally you would segregate your IPSec tunnels into a different security zone besides 'untrust' or 'trust' and we could at least identify them like that, since you are not doing that we can't tell what zone the IPSec traffic should really be identified under. &amp;nbsp;I'm also completely unaware of how your route table looks, what the config on the other end looks, or anything of the like. I'm not trying to put you off or come off like an ass, but you need to provide a little bit more information if you want help. Enabling the additional logging will give you a fair hint on where the issue actually is and we can go from there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 18:12:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138919#M48046</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-23T18:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Site-to-Site between PA-200 and PFSense one direction route only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138968#M48047</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;nice long email. Anyway as more info we got the easier and quicker we can help/advice. Same info needed on what you have already done.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 20:33:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-site-to-site-between-pa-200-and-pfsense-one-direction/m-p/138968#M48047</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-01-23T20:33:58Z</dc:date>
    </item>
  </channel>
</rss>

