<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKE Phase 1 Timeout in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156414#M51343</link>
    <description>&lt;P&gt;i am having the same issue since two days !!!&lt;/P&gt;</description>
    <pubDate>Fri, 12 May 2017 14:49:36 GMT</pubDate>
    <dc:creator>Ammar</dc:creator>
    <dc:date>2017-05-12T14:49:36Z</dc:date>
    <item>
      <title>IKE Phase 1 Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156267#M51299</link>
      <description>&lt;P&gt;IKE is failing to negoriate phase 1. &amp;nbsp;I get this timeout and then a delete. Any thoughts on the possible cause? I'm thinking&lt;/P&gt;&lt;P&gt;the&amp;nbsp;peer is perhaps not permitting the traffic from this device perhaps at a security device in front of their tunneling firewall (ASA). ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May 11th 2017, 10:39:04.000 &amp;lt;14&amp;gt;May 11 10:39:04 172.19.5.38 prdfw100-pri.internal.foodahoo.com 1,2017/05/11 10:39:04,002201003116,SYSTEM,vpn,0,2017/05/11 10:39:04,,ike-nego-p1-fail,IKE-CostaRice-Scooby-GATEWAY,0,0,general,informational,"IKE phase-1 negotiation is failed as responder, main mode. Failed SA: 10.10.179.237.54[500]-100.100.102.52[500] cookie:1e341d416839:075a2865154b8d40. Due to timeout.",4906344,0x8000000000000000&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 19:36:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156267#M51299</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-05-11T19:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Phase 1 Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156281#M51302</link>
      <description>&lt;P&gt;You are a responder, so IKE P1 traffic is initiated by the&amp;nbsp;other side. When you responding back to the&amp;nbsp;peer, traffic is matching already created session. Are you able to post the following commands output? :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; debug ike global on debug&lt;/P&gt;&lt;P&gt;&amp;gt; tail lines 50 mp-log ikemgr.log&lt;/P&gt;&lt;P&gt;&amp;gt; debug ike global on normal&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 21:10:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156281#M51302</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-11T21:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Phase 1 Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156289#M51303</link>
      <description>&lt;P&gt;I need to schedule another window for the setup. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you saying that it sounds like a three way handshake has occured such that my replies are getting back to the peer?&lt;/P&gt;&lt;P&gt;I'll definitely do the debug next go-around.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 20:52:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156289#M51303</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-05-11T20:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Phase 1 Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156293#M51304</link>
      <description>&lt;P&gt;&lt;SPAN&gt;IKE phase 1 (main mode/aggressive mode) is UDP src and dst&amp;nbsp;port 500, so no 3-way handshake.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;Failed SA: &lt;FONT color="#FF0000"&gt;10.10.179.237.54&lt;/FONT&gt;[500]-100.100.102.52[500]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What is your correct peer ip? &amp;nbsp;Are you behind the NAT?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 21:08:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156293#M51304</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-11T21:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Phase 1 Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156414#M51343</link>
      <description>&lt;P&gt;i am having the same issue since two days !!!&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 14:49:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156414#M51343</guid>
      <dc:creator>Ammar</dc:creator>
      <dc:date>2017-05-12T14:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Phase 1 Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156430#M51355</link>
      <description>&lt;P&gt;The peers are actually public IP's non-natted at each end. I do see that from the current ASA that I can ping the peer and from the PAN I can not. That could just be a red herring or perhaps there is a permission missing. Thanks for reminding me that the UDP 500 is what's coming in my direction initially so it's not a sign of a three way handshake.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 16:33:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156430#M51355</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-05-12T16:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Phase 1 Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156472#M51370</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/54718"&gt;@palomed&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is likely not setup correctly because of the whole '&lt;SPAN&gt;10.10.179.237.54' issue. It looks like one of your devices is passing it's private address instead of it's public; your tunnel is likely setup with the peer being the public address and not '10.10.179.237.54'. If I would take a guess I would assume that the&amp;nbsp;10.10.179.237.54 address is your ASA correct?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 19:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156472#M51370</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-12T19:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Phase 1 Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156475#M51373</link>
      <description>&lt;P&gt;I'm just masking our address space by putting 10.x into one of the peers.&amp;nbsp;It's actually a valid public IP.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 19:53:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156475#M51373</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-05-12T19:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: IKE Phase 1 Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156492#M51382</link>
      <description>&lt;P&gt;Correct. Ping simply could be disabled on the&amp;nbsp;ASA external interface. Please provide more logs from the&amp;nbsp;responder side (in our case it is Palo) and then we can go from there.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 21:38:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-phase-1-timeout/m-p/156492#M51382</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-12T21:38:32Z</dc:date>
    </item>
  </channel>
</rss>

