<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues with ipsec traffic from PA3020 to Cisco 871. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-ipsec-traffic-from-pa3020-to-cisco-871/m-p/150063#M49876</link>
    <description>&lt;P&gt;If ping is working but TCP sessions aren't it could be asymmetric routing issue. Check routing and ingress/egress interfaces in logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And i'd suggest using different security zone for VPN traffic.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Mar 2017 06:08:08 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2017-03-29T06:08:08Z</dc:date>
    <item>
      <title>Issues with ipsec traffic from PA3020 to Cisco 871.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-ipsec-traffic-from-pa3020-to-cisco-871/m-p/150048#M49874</link>
      <description>&lt;P&gt;I have a working tunnel between Netscreen and Cisco 871. I tried to move this from Netscreen to PA3020.&lt;/P&gt;&lt;P&gt;The tunnel comes up. PA3020-local network-192.168.2.0/24 and remote-192.168.235.0/24.&lt;/P&gt;&lt;P&gt;Traffic from 2.0(palo side) to 235.0(cisco side) network is fine. But from 235.0(cisco side) to 2.0(palo side) we have issues&lt;/P&gt;&lt;P&gt;Only thing which works is ping. rdp,mail,port80 nothing works. The tunnel is part of trust with 2.0 in trust as well. All trust intrazone is allowed and I can see logs allowing. all interface mtu is 1500. Tried adjusting mtu to different setting 1350,1418 but still doesnt work. Reverted the tunnel to netscreen and works fine. On netscreen its policy based and no tunnel is involved so&lt;/P&gt;&lt;P&gt;cant check mtu.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 04:56:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-ipsec-traffic-from-pa3020-to-cisco-871/m-p/150048#M49874</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2017-03-29T04:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ipsec traffic from PA3020 to Cisco 871.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-ipsec-traffic-from-pa3020-to-cisco-871/m-p/150063#M49876</link>
      <description>&lt;P&gt;If ping is working but TCP sessions aren't it could be asymmetric routing issue. Check routing and ingress/egress interfaces in logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And i'd suggest using different security zone for VPN traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 06:08:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-ipsec-traffic-from-pa3020-to-cisco-871/m-p/150063#M49876</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-29T06:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ipsec traffic from PA3020 to Cisco 871.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-ipsec-traffic-from-pa3020-to-cisco-871/m-p/150092#M49887</link>
      <description>&lt;P&gt;I have migrated tunnel which is working in the same setup. Its not a routing but mtu or mss adjust setup.&lt;/P&gt;&lt;P&gt;On netscreen I have set flow tcp-mss does that mean i will need to enable adjust mss on external interface.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 09:52:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-ipsec-traffic-from-pa3020-to-cisco-871/m-p/150092#M49887</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2017-03-29T09:52:59Z</dc:date>
    </item>
  </channel>
</rss>

