<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco AnyConnect over IKEv2 killed by PAN-OS 8.0 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141313#M48383</link>
    <description>&lt;P&gt;PAN-OS says "aged-out". Cisco AnyConnect doesn't even notice that it's been disconnected.&lt;/P&gt;&lt;P&gt;Everything worked fine in 7.1.7 and earlier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw, it's a PA-200.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Feb 2017 16:51:37 GMT</pubDate>
    <dc:creator>GI-1</dc:creator>
    <dc:date>2017-02-06T16:51:37Z</dc:date>
    <item>
      <title>Cisco AnyConnect over IKEv2 killed by PAN-OS 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141210#M48363</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been running PAN-OS 8.0 since release, and immediately got problems with Cisco AnyConnect over IKEv2. Even if the session is very much alive, PAN-OS 8.0 kills it of after a random amount of time, usually a couple of hours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I change the AnyConnect policy to use SSL instead, everything runs fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-OS 8.0 recognizes AnyConnect over IKEv2 as&amp;nbsp;ipsec-esp-udp. Changing the default timeout to e.g. 86400 seconds changes nothing.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 08:17:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141210#M48363</guid>
      <dc:creator>GI-1</dc:creator>
      <dc:date>2017-02-06T08:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect over IKEv2 killed by PAN-OS 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141237#M48369</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;does the session indicate why it was terminated (idle, rst, ...) ?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 09:17:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141237#M48369</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-02-06T09:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect over IKEv2 killed by PAN-OS 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141313#M48383</link>
      <description>&lt;P&gt;PAN-OS says "aged-out". Cisco AnyConnect doesn't even notice that it's been disconnected.&lt;/P&gt;&lt;P&gt;Everything worked fine in 7.1.7 and earlier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw, it's a PA-200.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 16:51:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141313#M48383</guid>
      <dc:creator>GI-1</dc:creator>
      <dc:date>2017-02-06T16:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect over IKEv2 killed by PAN-OS 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141315#M48384</link>
      <description>&lt;P&gt;Do you see anything in the Threat logs; it kind of sounds like some security policy is preventing the traffic from passing, hence your age-out response.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 17:13:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141315#M48384</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-02-06T17:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect over IKEv2 killed by PAN-OS 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141533#M48418</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, there's no entries in the threat log with the IP to the AnyConnect server.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2017 12:22:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141533#M48418</guid>
      <dc:creator>GI-1</dc:creator>
      <dc:date>2017-02-07T12:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect over IKEv2 killed by PAN-OS 8.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141831#M48449</link>
      <description>&lt;P&gt;I see now that the apps and threats content release 658 did something to ipsec-esp-udp. I guess that's the culprit, and not necessarily 8.0.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 08:13:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cisco-anyconnect-over-ikev2-killed-by-pan-os-8-0/m-p/141831#M48449</guid>
      <dc:creator>GI-1</dc:creator>
      <dc:date>2017-02-08T08:13:45Z</dc:date>
    </item>
  </channel>
</rss>

