<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site 2 Site VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162740#M52744</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;On my tunnels I have the following applications allowed so they are not blocked. I also whitelist the source/destination IP's for my site to site vpns for added protection:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 102px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9872i7C4307C419ACE8C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jun 2017 14:14:30 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2017-06-22T14:14:30Z</dc:date>
    <item>
      <title>Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162696#M52730</link>
      <description>&lt;P&gt;I have an issue where we have ike traffic comeing from the end point which is being allowed but the ipsec-esp is being caught by the deny all rule. The strange thing is that the the rule to allow ike and ipsec-esp is on the same rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do carry out NAT on the public IP for some ports , is this this the issues &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9870i254A21D2DF11F3E7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can any one please point me in the right direction&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 12:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162696#M52730</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2017-06-22T12:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162704#M52731</link>
      <description>&lt;P&gt;Please show us that rule. What about port/services - are You using defualt one?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 13:18:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162704#M52731</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2017-06-22T13:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162722#M52736</link>
      <description>&lt;P&gt;Based on the external source IP (your remote office) temporary allow all traffic (any) and observe the behaviour. ESP has no port number so no it is not a NAT issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 13:49:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162722#M52736</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-06-22T13:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162725#M52739</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/31654"&gt;@_slv_&lt;/a&gt;&amp;nbsp;already pointed out your rule is likely malformed so the traffic isn't getting caught. A picture of the rule would do wonders here over the logs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 13:55:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162725#M52739</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-22T13:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162740#M52744</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;On my tunnels I have the following applications allowed so they are not blocked. I also whitelist the source/destination IP's for my site to site vpns for added protection:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 102px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9872i7C4307C419ACE8C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 14:14:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/162740#M52744</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-06-22T14:14:30Z</dc:date>
    </item>
  </channel>
</rss>

