<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN clients IPsec vendors in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150380#M49939</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53726"&gt;@Es_tecsupportsecurity&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've seen this in relation with PAN-OS 7.1 not accepting os = "any" &amp;nbsp;(lower case)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Verify if Any is upper or lower case in your config :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; configure&lt;BR /&gt;# show global-protect global-protect-gateway &amp;lt;Gateway Name&amp;gt; client-auth auth-any
auth-any {
&amp;nbsp; authentication-profile local;
&amp;nbsp; os &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Any&lt;/STRONG&gt;&lt;/FONT&gt;;
&amp;nbsp; authentication-message "Enter login credentials";&lt;/PRE&gt;
&lt;P&gt;If it is lower case you can fix it by forcing it to an&amp;nbsp;upper case:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; configure
# set global-protect global-protect-gateway &amp;lt;Gateway Name&amp;gt; client-auth auth-any os &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Any&lt;/STRONG&gt;&lt;/FONT&gt;
# commit
# exit&lt;/PRE&gt;
&lt;P&gt;If it's already correct then you might want to dig deeper.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps !&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2017 12:03:50 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2017-03-30T12:03:50Z</dc:date>
    <item>
      <title>VPN clients IPsec vendors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150371#M49938</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We realised after upgrading to 7.1.8 when we access to VPN GP using CISCO VPN CLIENT (IPsec) is not working. In previous version was working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the error ikemgrlog:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2017-03-30 13:11:52 [PROTO_ERR]: isakmp_inf.c:1362:isakmp_info_recv_d(): delete payload with invalid doi:0.&lt;BR /&gt;2017-03-30 13:11:52 [INFO]: isakmp_inf.c:1411:isakmp_info_recv_d(): IKE ISAKMP KEY_DELETE recvd: cookie:3b6f56f729ca40bf:3490ba81070b347c.&lt;BR /&gt;2017-03-30 13:11:52 [DEBUG]: isakmp_inf.c:1418:isakmp_info_recv_d(): PH1 state changed: 12 to 14 [PHASE1ST_EXPIRED] @isakmp_info_recv_d&lt;BR /&gt;2017-03-30 13:11:52 [DEBUG]: isakmp_inf.c:1473:isakmp_info_recv_d(): purged SAs.&lt;BR /&gt;2017-03-30 13:11:52 [INFO]: ikev1.c:2533:log_ph1expired(): ====&amp;gt; PHASE-1 SA LIFETIME EXPIRED &amp;lt;====&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any issue using another VPN clients (not GProtect) in 7.1??&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 11:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150371#M49938</guid>
      <dc:creator>Es_tecsupportsecurity</dc:creator>
      <dc:date>2017-03-30T11:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients IPsec vendors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150380#M49939</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53726"&gt;@Es_tecsupportsecurity&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've seen this in relation with PAN-OS 7.1 not accepting os = "any" &amp;nbsp;(lower case)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Verify if Any is upper or lower case in your config :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; configure&lt;BR /&gt;# show global-protect global-protect-gateway &amp;lt;Gateway Name&amp;gt; client-auth auth-any
auth-any {
&amp;nbsp; authentication-profile local;
&amp;nbsp; os &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Any&lt;/STRONG&gt;&lt;/FONT&gt;;
&amp;nbsp; authentication-message "Enter login credentials";&lt;/PRE&gt;
&lt;P&gt;If it is lower case you can fix it by forcing it to an&amp;nbsp;upper case:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt; configure
# set global-protect global-protect-gateway &amp;lt;Gateway Name&amp;gt; client-auth auth-any os &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Any&lt;/STRONG&gt;&lt;/FONT&gt;
# commit
# exit&lt;/PRE&gt;
&lt;P&gt;If it's already correct then you might want to dig deeper.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps !&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 12:03:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150380#M49939</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-03-30T12:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients IPsec vendors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150405#M49945</link>
      <description>&lt;P&gt;We tried changing to Upper case but it didnt worked. With upper case we can not access with either global protect or CiscoVPN ipsec client,&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 13:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150405#M49945</guid>
      <dc:creator>Es_tecsupportsecurity</dc:creator>
      <dc:date>2017-03-30T13:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients IPsec vendors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150426#M49951</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53726"&gt;@Es_tecsupportsecurity&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you confirm what the 'show' command output is in your case ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you upgrade from&amp;nbsp;an earlier 7.1 version or did you upgrade from 7.0 ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the release notes :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Fixed an issue on firewalls that were upgraded from a PAN‐OS 7.0 release to a PAN‐OS 7.1 release where GlobalProtect prevented third‐party IPSec (X‐Auth) clients from connecting to the GlobalProtect gateway. With this fix, you can now upgrade from a PAN‐OS 7.0 release to a PAN‐OS 7.1.2 or later release to prevent this issue. If your GlobalProtect firewall is already running a PAN‐OS 7.1.0 or 7.1.1 release, you must downgrade to a PAN‐OS 7.0 release before upgrading to a PAN‐OS 7.1.2 or later release to prevent this issue from occurring after the upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that the workaround I posted earlier should work for the issue described in the release notes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If all else fails I'd suggest that you reach out to support so they can do some in depth debugging.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 15:38:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150426#M49951</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-03-30T15:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients IPsec vendors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150529#M49967</link>
      <description>&lt;P&gt;You were right. We needed to write "Any" with uppercase by CLI. Its not working if you write it on WebUI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope PA solves this in new releases. Thaks a lot.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 06:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150529#M49967</guid>
      <dc:creator>Es_tecsupportsecurity</dc:creator>
      <dc:date>2017-03-31T06:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients IPsec vendors</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150534#M49969</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53726"&gt;@Es_tecsupportsecurity&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's awesome ! I'm glad it worked out !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 07:14:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-clients-ipsec-vendors/m-p/150534#M49969</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-03-31T07:14:18Z</dc:date>
    </item>
  </channel>
</rss>

