<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec tunnel questions? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151354#M50124</link>
    <description>&lt;P&gt;The number one thing that you are going to see that is different is you will need to actually set the proxy ids for the other side to actually form up properly. I'm almost positive that sonicwall is going to need a proxyid setup so that it can actually form the tunnel properly.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2017 01:47:47 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-04-06T01:47:47Z</dc:date>
    <item>
      <title>IPsec tunnel questions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151300#M50115</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have several IPsec VPN tunnels for various remote firewalls connections.&amp;nbsp; One of them is changing their firewall hardware to something else next week. &amp;nbsp;Sonic firewall, I believe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been told that they are configuring the new replacement hardware with the same settings as before&amp;nbsp;including same peer IP address.&lt;/P&gt;&lt;P&gt;NOTE:&amp;nbsp; I will backup the current configuration of our PA 3020 before making any changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Could I make changes to our existing IPsec VPN settings (if necessary)&amp;nbsp;or must create new?&lt;/LI&gt;&lt;LI&gt;Would I have to make any changes at all?&amp;nbsp; Assuming that the IKE and IPsec Crypto profile setting match on new hardware.&amp;nbsp; Should just re-negotiate?&lt;/LI&gt;&lt;LI&gt;If things don't workout, I could always restore back to my save configuration, correct?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 21:26:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151300#M50115</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-04-05T21:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel questions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151325#M50117</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If everything is going to remain the same, e.g. IP, pass phrases, crypto settings, then you should not have to do anything. Since the only thing changing is the hardware on the customer side, you may have to tweak a setting or two, especially with routing, depending on what equipment they had before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Could I make changes to our existing IPsec VPN settings (if necessary)&amp;nbsp;or must create new?&lt;UL&gt;&lt;LI&gt;You can make changes&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Would I have to make any changes at all?&amp;nbsp; Assuming that the IKE and IPsec Crypto profile setting match on new hardware.&amp;nbsp; Should just re-negotiate?&lt;UL&gt;&lt;LI&gt;Sjhouldnt have to, but might require tweaking?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;If things don't workout, I could always restore back to my save configuration, correct?&lt;UL&gt;&lt;LI&gt;Yes you can always revert to a previous configuration&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 22:53:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151325#M50117</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-04-05T22:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel questions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151354#M50124</link>
      <description>&lt;P&gt;The number one thing that you are going to see that is different is you will need to actually set the proxy ids for the other side to actually form up properly. I'm almost positive that sonicwall is going to need a proxyid setup so that it can actually form the tunnel properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 01:47:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151354#M50124</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-04-06T01:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel questions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151477#M50159</link>
      <description>&lt;P&gt;Thank you!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like there is a type of pass phrase in the IKE gateway configuration.&amp;nbsp; Since this was configured before my time, I don't know what the value is.&amp;nbsp; Need to find out.&amp;nbsp; I guess I could change it and make sure to match it with the remote configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IKE.jpg" style="width: 598px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8663iC9D4C2E271DF1724/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="IKE.jpg" alt="IKE.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 14:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151477#M50159</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-04-06T14:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel questions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151483#M50162</link>
      <description>&lt;P&gt;If &amp;nbsp;the&amp;nbsp;PSK is unknown best way as you said to agree on the new one and share between other end&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 15:32:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/151483#M50162</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-06T15:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel questions?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/152371#M50403</link>
      <description>&lt;P&gt;I just wanted to add to this thread that I completed this task.&lt;/P&gt;&lt;P&gt;Our partner changed out their firewall hardware, setup their side IPSec settings to match our's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing I had to change on our existing IPSec tunnel settings was the Shared Password, and worked no problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did notice that the connection was green (but not communicating) before I changed the password.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 18:35:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-questions/m-p/152371#M50403</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-04-12T18:35:09Z</dc:date>
    </item>
  </channel>
</rss>

