<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Adding a Proxy ID member to IPSec Tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-proxy-id-member-to-ipsec-tunnel/m-p/159214#M52069</link>
    <description>&lt;P&gt;I added a single host to an existing tunnel. Does the phase 1 portion of the tunnel need to be restarted to take effect? After I added the new proxy-id 39 - if I run show vpn flow - I see that portion of the tunnel is in "init" phase while all others are active.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried tunning "test vpn ipsec-sa .." for that specific phase 2 instance but it's still just in init. Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;277 &amp;nbsp; IPSEC-YoyoPhx-Yaba-TUNNEL:YoYab-39init &amp;nbsp; &amp;nbsp; &amp;nbsp; off &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;13.17.36.54 &amp;nbsp;7.13.102.52 &amp;nbsp; tunnel.22&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2017 15:49:37 GMT</pubDate>
    <dc:creator>palomed</dc:creator>
    <dc:date>2017-06-02T15:49:37Z</dc:date>
    <item>
      <title>Adding a Proxy ID member to IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-proxy-id-member-to-ipsec-tunnel/m-p/159214#M52069</link>
      <description>&lt;P&gt;I added a single host to an existing tunnel. Does the phase 1 portion of the tunnel need to be restarted to take effect? After I added the new proxy-id 39 - if I run show vpn flow - I see that portion of the tunnel is in "init" phase while all others are active.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried tunning "test vpn ipsec-sa .." for that specific phase 2 instance but it's still just in init. Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;277 &amp;nbsp; IPSEC-YoyoPhx-Yaba-TUNNEL:YoYab-39init &amp;nbsp; &amp;nbsp; &amp;nbsp; off &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;13.17.36.54 &amp;nbsp;7.13.102.52 &amp;nbsp; tunnel.22&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 15:49:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-proxy-id-member-to-ipsec-tunnel/m-p/159214#M52069</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-06-02T15:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a Proxy ID member to IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-proxy-id-member-to-ipsec-tunnel/m-p/159221#M52070</link>
      <description>&lt;P&gt;Did you add new ProxyID to both sides of the tunnel?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 15:54:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-proxy-id-member-to-ipsec-tunnel/m-p/159221#M52070</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-06-02T15:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a Proxy ID member to IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/adding-a-proxy-id-member-to-ipsec-tunnel/m-p/159275#M52090</link>
      <description>&lt;P&gt;I'm dealing with outside vendors for these tunnels. They said they&amp;nbsp;added to their side of the tunnel but I can't actually see. Is there any way on the PAN to see if a pair of phase 2 addresses is trying to negotiate? e.g. say on the PAN side Proxy-ID-10 is Local 10.10.5.5/32 and Remote 192.168.5.5. Proxy-IDs 1 through 9 are fine and state active but 10 is init. Is there any way to see the of 192.168.5.5/10.10.5.5 are trying to become part of the phase 2?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2017 19:48:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/adding-a-proxy-id-member-to-ipsec-tunnel/m-p/159275#M52090</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2017-06-02T19:48:25Z</dc:date>
    </item>
  </channel>
</rss>

