<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How VPN test commands work in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-vpn-test-commands-work/m-p/152761#M50487</link>
    <description>&lt;P&gt;What happens behind the scenes when you run..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test vpn ike-sa gateway &amp;lt;name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel &amp;lt;name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a debug which will show you the test packets sent/received?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 16 Apr 2017 22:42:46 GMT</pubDate>
    <dc:creator>palomed</dc:creator>
    <dc:date>2017-04-16T22:42:46Z</dc:date>
    <item>
      <title>How VPN test commands work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-vpn-test-commands-work/m-p/152761#M50487</link>
      <description>&lt;P&gt;What happens behind the scenes when you run..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test vpn ike-sa gateway &amp;lt;name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel &amp;lt;name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a debug which will show you the test packets sent/received?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2017 22:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-vpn-test-commands-work/m-p/152761#M50487</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-04-16T22:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: How VPN test commands work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-vpn-test-commands-work/m-p/152772#M50488</link>
      <description>&lt;P&gt;test vpn ike-sa gateway &amp;lt;name&amp;gt;&lt;/P&gt;&lt;P&gt;Will negotiate VPN Phase 1 with VPN Peer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel &amp;lt;name&amp;gt;&lt;/P&gt;&lt;P&gt;Will negotiate VPN Phase 1 and if this is successful then Phase 2 with VPN Peer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you troubleshoot VPN and try to initiate traffic from workstation they you have to have routing and firewall rules correct.&lt;/P&gt;&lt;P&gt;Using those commands help you to verify if underlying VPN is set correctly without checking routing or security policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you use those commands then your firewall is initiator. If VPN config does not match then responder does not tell you what is wrong so not much troubleshooting you can do at initiator side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If Palo is responder then you can take packet capture to troubleshoot Phase 1 settings and ike pcap to troubleshoot Phase 2.&lt;/P&gt;&lt;P&gt;&lt;A title="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187" href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 03:08:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-vpn-test-commands-work/m-p/152772#M50488</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-04-17T03:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: How VPN test commands work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-vpn-test-commands-work/m-p/152808#M50493</link>
      <description>&lt;P&gt;In addition to the&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;comment,&amp;nbsp;VPN &amp;nbsp;the only effective way to troubleshoot is to check the logs from the responder side. Responder side will say why VPN is failing and record everything into the&amp;nbsp;log file but it will not send this info to the initiator. This is per design. Similar we can compare when we submitting our credentials to the other side. We only see a message "your username or password is incorrect". But another side has all records exactly&amp;nbsp;why.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 10:22:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-vpn-test-commands-work/m-p/152808#M50493</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-04-17T10:22:44Z</dc:date>
    </item>
  </channel>
</rss>

