<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN Between PA and Cisco ASA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165973#M53255</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disable DPD for now. Enable&amp;nbsp;debug mode so we can get more info:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; debug ike global on debug&lt;/P&gt;&lt;P&gt;xxxxxxxxxx&amp;gt; debug ike global show&lt;/P&gt;&lt;P&gt;sw.ikedaemon.debug.global: debug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ike-sa gateway (your gateway)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; tail follow yes mp-log ikemgr.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Configure debug back to "normal" mode:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; debug ike global on normal&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jul 2017 23:22:54 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-07-11T23:22:54Z</dc:date>
    <item>
      <title>S2S VPN Between PA and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165682#M53211</link>
      <description>&lt;P&gt;Hello!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've spent the last 2 days trying to get an IPSec tunnel working between a PAN 200 and Cisco ASA5505 but all my attempts have failed. I am not sure what the issue is and would reall appreciate any assistance to point me in the right direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a very simply setup. &amp;nbsp;I've configured both sides properly but for some reason the tunnel won't come up. Here are the config of both the PA and ASA:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA 200:&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;IKE&lt;/SPAN&gt;&lt;SPAN&gt; Crypto: IKEPhase1_To_ASA&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;DH&lt;/SPAN&gt;&lt;SPAN&gt; Group: group &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Authentication: sha1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Encryption: 3des&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Key lifetime: &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt; day&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;IPsec Crypto: IKEPhase2_To_ASA&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;DH&lt;/SPAN&gt;&lt;SPAN&gt; Group: group &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Authentication: sha1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Encryption: 3des&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Key lifetime: &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt; day &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Lifesize: 4608MB&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;IKE&lt;/SPAN&gt;&lt;SPAN&gt; Gateway: &lt;/SPAN&gt;&lt;SPAN&gt;STS_VPN_To_ASA&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Version: IKEv1 only mode&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Interface: e1&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Peer &lt;/SPAN&gt;&lt;SPAN&gt;IP&lt;/SPAN&gt;&lt;SPAN&gt; Address: &lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;PSK&lt;/SPAN&gt;&lt;SPAN&gt;: cisco &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Local Id: &lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Peer Id: &lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;IKEv1 Exchange Mode: main&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;IKE&lt;/SPAN&gt;&lt;SPAN&gt; Crypto Profile: IKEPhase1_To_ASA&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;IPSec Tunnel&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Tunnel Interface: tunnel.2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Type: Auto Key &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;IKE&lt;/SPAN&gt;&lt;SPAN&gt; Gateway: &lt;/SPAN&gt;&lt;SPAN&gt;STS_VPN_To_ASA&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;IPSec Crypto Profile: IKEPhase2_To_ASA &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Proxy IDs: &lt;/SPAN&gt;&lt;SPAN&gt;ASA_LAN_TO_LAN&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Local: &lt;/SPAN&gt;&lt;SPAN&gt;10.48&lt;/SPAN&gt;&lt;SPAN&gt;.11.150&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;24&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Remote: &lt;/SPAN&gt;&lt;SPAN&gt;192.168&lt;/SPAN&gt;&lt;SPAN&gt;.1.200&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;24&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;VR1&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Static Route&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Destination &lt;/SPAN&gt;&lt;SPAN&gt;192.168&lt;/SPAN&gt;&lt;SPAN&gt;.1.0&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;24&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Interface: tunnel.2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;System Monitor Logs:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;IKE&lt;/SPAN&gt;&lt;SPAN&gt; phase&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt; &lt;SPAN&gt;SA&lt;/SPAN&gt; &lt;SPAN&gt;is&lt;/SPAN&gt;&lt;SPAN&gt; expired &lt;/SPAN&gt;&lt;SPAN&gt;SA&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.2[&lt;/SPAN&gt;&lt;SPAN&gt;500&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.1[&lt;/SPAN&gt;&lt;SPAN&gt;5&lt;/SPAN&gt;&lt;SPAN&gt;] cookieL &lt;/SPAN&gt;&lt;SPAN&gt;19e72&lt;/SPAN&gt;&lt;SPAN&gt;...&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;=============================================================================&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ASA 5505:&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;asa&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;01&lt;/SPAN&gt;&lt;SPAN&gt;# sh run&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;: Saved&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ASA&lt;/SPAN&gt;&lt;SPAN&gt; Version &lt;/SPAN&gt;&lt;SPAN&gt;8.0&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;4&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;hostname asa&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;01&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface Vlan1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;no nameif&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;no security&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;level&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;no ip address&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface Vlan100&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nameif outside&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;security&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;level &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip address &lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.1 &lt;/SPAN&gt;&lt;SPAN&gt;255.255&lt;/SPAN&gt;&lt;SPAN&gt;.255.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface Vlan200&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nameif inside&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;security&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;level &lt;/SPAN&gt;&lt;SPAN&gt;100&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip address &lt;/SPAN&gt;&lt;SPAN&gt;192.168&lt;/SPAN&gt;&lt;SPAN&gt;.1.200 &lt;/SPAN&gt;&lt;SPAN&gt;255.255&lt;/SPAN&gt;&lt;SPAN&gt;.255.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface Ethernet0&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface Ethernet0&lt;/SPAN&gt;&lt;SPAN&gt;/&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;switchport access vlan &lt;/SPAN&gt;&lt;SPAN&gt;100&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface Ethernet&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ftp mode passive&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;access&lt;/SPAN&gt;&lt;SPAN&gt;-list&lt;/SPAN&gt; &lt;SPAN&gt;ALLOWED_TRFC_TO_PAN&lt;/SPAN&gt;&lt;SPAN&gt; extended permit ip &lt;/SPAN&gt;&lt;SPAN&gt;192.168&lt;/SPAN&gt;&lt;SPAN&gt;.1.0 &lt;/SPAN&gt;&lt;SPAN&gt;255.255&lt;/SPAN&gt;&lt;SPAN&gt;.255.0 &lt;/SPAN&gt;&lt;SPAN&gt;10.48&lt;/SPAN&gt;&lt;SPAN&gt;.11.0 &lt;/SPAN&gt;&lt;SPAN&gt;255.255&lt;/SPAN&gt;&lt;SPAN&gt;.255.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;access&lt;/SPAN&gt;&lt;SPAN&gt;-list&lt;/SPAN&gt; &lt;SPAN&gt;ALLOWED_TRFC_TO_PAN&lt;/SPAN&gt;&lt;SPAN&gt; extended permit icmp &lt;/SPAN&gt;&lt;SPAN&gt;192.168&lt;/SPAN&gt;&lt;SPAN&gt;.1.0 &lt;/SPAN&gt;&lt;SPAN&gt;255.255&lt;/SPAN&gt;&lt;SPAN&gt;.255.0 &lt;/SPAN&gt;&lt;SPAN&gt;10.48&lt;/SPAN&gt;&lt;SPAN&gt;.11.0 &lt;/SPAN&gt;&lt;SPAN&gt;255.255&lt;/SPAN&gt;&lt;SPAN&gt;.255.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;access&lt;/SPAN&gt;&lt;SPAN&gt;-list&lt;/SPAN&gt;&lt;SPAN&gt; nonat extended permit ip &lt;/SPAN&gt;&lt;SPAN&gt;192.168&lt;/SPAN&gt;&lt;SPAN&gt;.1.0 &lt;/SPAN&gt;&lt;SPAN&gt;255.255&lt;/SPAN&gt;&lt;SPAN&gt;.255.0 &lt;/SPAN&gt;&lt;SPAN&gt;10.48&lt;/SPAN&gt;&lt;SPAN&gt;.11.0 &lt;/SPAN&gt;&lt;SPAN&gt;255.255&lt;/SPAN&gt;&lt;SPAN&gt;.255.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;pager lines &lt;/SPAN&gt;&lt;SPAN&gt;24&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;mtu outside &lt;/SPAN&gt;&lt;SPAN&gt;1500&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;mtu inside &lt;/SPAN&gt;&lt;SPAN&gt;1500&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;icmp unreachable rate&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;limit &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt; burst&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;size &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;no asdm history enable&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;arp timeout &lt;/SPAN&gt;&lt;SPAN&gt;14400&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;global&lt;/SPAN&gt;&lt;SPAN&gt; (outside) &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt; interface&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nat (inside) &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt; access&lt;/SPAN&gt;&lt;SPAN&gt;-list&lt;/SPAN&gt;&lt;SPAN&gt; nonat&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;nat (inside) &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt; &lt;SPAN&gt;0.0&lt;/SPAN&gt;&lt;SPAN&gt;.0.0 &lt;/SPAN&gt;&lt;SPAN&gt;0.0&lt;/SPAN&gt;&lt;SPAN&gt;.0.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;route outside &lt;/SPAN&gt;&lt;SPAN&gt;0.0&lt;/SPAN&gt;&lt;SPAN&gt;.0.0 &lt;/SPAN&gt;&lt;SPAN&gt;0.0&lt;/SPAN&gt;&lt;SPAN&gt;.0.0 &lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.1 &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;timeout xlate &lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;timeout conn &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; half&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;closed &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; udp &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;02&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; icmp &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;02&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;timeout sunrpc &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; h323 &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;05&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; h225 &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; mgcp &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;05&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; mgcp&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;pat &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;05&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;timeout sip &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;30&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; sip_media &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;02&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; sip&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;invite &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;03&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; sip&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;disconnect &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;02&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;timeout sip&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;provisional&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;media &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;02&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; uauth &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;05&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;00&lt;/SPAN&gt;&lt;SPAN&gt; absolute&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;dynamic&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;access&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;policy&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;record DfltAccessPolicy&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;no snmp&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;server location&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;no snmp&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;server contact&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;snmp&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;server enable traps snmp authentication linkup linkdown coldstart&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto ipsec transform&lt;/SPAN&gt;&lt;SPAN&gt;-set&lt;/SPAN&gt; &lt;SPAN&gt;MYSET&lt;/SPAN&gt;&lt;SPAN&gt; esp&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;3des esp&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;sha&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;hmac&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto ipsec security&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;association lifetime seconds &lt;/SPAN&gt;&lt;SPAN&gt;86400&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto ipsec security&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;association lifetime kilobytes &lt;/SPAN&gt;&lt;SPAN&gt;4608000&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto &lt;/SPAN&gt;&lt;SPAN&gt;map&lt;/SPAN&gt; &lt;SPAN&gt;ASA_TO_PAN_MAP&lt;/SPAN&gt; &lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt; match address &lt;/SPAN&gt;&lt;SPAN&gt;ALLOWED_TRFC_TO_PAN&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto &lt;/SPAN&gt;&lt;SPAN&gt;map&lt;/SPAN&gt; &lt;SPAN&gt;ASA_TO_PAN_MAP&lt;/SPAN&gt; &lt;SPAN&gt;10&lt;/SPAN&gt; &lt;SPAN&gt;set&lt;/SPAN&gt;&lt;SPAN&gt; peer &lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto &lt;/SPAN&gt;&lt;SPAN&gt;map&lt;/SPAN&gt; &lt;SPAN&gt;ASA_TO_PAN_MAP&lt;/SPAN&gt; &lt;SPAN&gt;10&lt;/SPAN&gt; &lt;SPAN&gt;set&lt;/SPAN&gt;&lt;SPAN&gt; transform&lt;/SPAN&gt;&lt;SPAN&gt;-set&lt;/SPAN&gt; &lt;SPAN&gt;MYSET&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto &lt;/SPAN&gt;&lt;SPAN&gt;map&lt;/SPAN&gt; &lt;SPAN&gt;ASA_TO_PAN_MAP&lt;/SPAN&gt; &lt;SPAN&gt;10&lt;/SPAN&gt; &lt;SPAN&gt;set&lt;/SPAN&gt;&lt;SPAN&gt; security&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;association lifetime seconds &lt;/SPAN&gt;&lt;SPAN&gt;86400&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto &lt;/SPAN&gt;&lt;SPAN&gt;map&lt;/SPAN&gt; &lt;SPAN&gt;ASA_TO_PAN_MAP&lt;/SPAN&gt; &lt;SPAN&gt;10&lt;/SPAN&gt; &lt;SPAN&gt;set&lt;/SPAN&gt;&lt;SPAN&gt; security&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;association lifetime kilobytes &lt;/SPAN&gt;&lt;SPAN&gt;4608000&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto &lt;/SPAN&gt;&lt;SPAN&gt;map&lt;/SPAN&gt; &lt;SPAN&gt;ASA_TO_PAN_MAP&lt;/SPAN&gt;&lt;SPAN&gt; interface outside&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto isakmp enable outside&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;crypto isakmp policy &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;authentication pre&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;share&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;encryption 3des&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;hash&lt;/SPAN&gt;&lt;SPAN&gt; sha&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;group &lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;lifetime &lt;/SPAN&gt;&lt;SPAN&gt;86400&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;telnet timeout &lt;/SPAN&gt;&lt;SPAN&gt;5&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ssh timeout &lt;/SPAN&gt;&lt;SPAN&gt;5&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;console timeout &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;threat&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;detection basic&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;threat&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;threat&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;detection statistics access&lt;/SPAN&gt;&lt;SPAN&gt;-list&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;no threat&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;detection statistics tcp&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;intercept&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;tunnel&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;group &lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.2 &lt;/SPAN&gt;&lt;SPAN&gt;type&lt;/SPAN&gt;&lt;SPAN&gt; ipsec&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;l2l&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;tunnel&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;group &lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.2 ipsec&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;attributes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;pre&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;shared&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;key &lt;/SPAN&gt;&lt;SPAN&gt;*&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;class&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;map&lt;/SPAN&gt;&lt;SPAN&gt; inspection_default&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;match default&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;inspection&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;traffic&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;: end&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;asa&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;01&lt;/SPAN&gt;&lt;SPAN&gt;#&lt;/SPAN&gt;&lt;/DIV&gt;-----&lt;/DIV&gt;&lt;DIV&gt;Best, ~sK&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 10 Jul 2017 21:42:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165682#M53211</guid>
      <dc:creator>Sadik_Khirbash</dc:creator>
      <dc:date>2017-07-10T21:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN Between PA and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165693#M53212</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l am not sure if your Proxy IDs look right (host with /24 subnet mask and the&amp;nbsp;whole subnet from ASA side).&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;will be able to help, l am sure &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 23:13:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165693#M53212</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-10T23:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN Between PA and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165700#M53213</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48414"&gt;@Sadik_Khirbash&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Honestly there is a bit here that I wouldn't say is 'right' in the way that I setup site-to-site tunnels, that being said I'm not going to say that the way I configure them is the 'correct' way either.&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;is correct though your proxy IDs I would say are wrong, I generally would use the actual network ranges, so for example 10.191.0.0/16 or 192.168.100.0/24 and so on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without knowing what your configuration actually states the following bugs me a bit on the IKE Gateway configuration; but that's probably just because I can't see the entire device config and it's likely fine.&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;Local Id:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Peer Id:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;What does your ike logs say on both devices, that should give you a fair insight into what is actually going on? The easiest way to really troubleshoot any of this is the logs on both devices as it will generally get you pointed in the proper direction.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 23:37:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165700#M53213</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-10T23:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN Between PA and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165701#M53214</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48414"&gt;@Sadik_Khirbash&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A few things I noticed on my end here when looking at your configuration. Although you are not showing the Phase 2 configuration on the PAN side, it is easy to spot how it should look like by looking at your ASA config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;mentioned,&lt;/P&gt;&lt;P&gt;Unless there is a specific reason you should not have to specify the Local and Peer ID if the VPN is between gateways with static IP addresses. In other words, unless your two firewalls are using dynamic IP address for the public IP, you should not define a Local and Peer IP whatosever, otherwise, it will mess up the phase 1 negotiation. If that's the case for you, and you really need to use this configuration, make sure that it is also properly defined on the remote side of the connection, in this case the ASA.&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;Local Id:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Peer Id:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;172.16&lt;/SPAN&gt;&lt;SPAN&gt;.200.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/IPSec-VPN-Tunnel-with-Peer-Having-Dynamic-IP-Address/ta-p/94161" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/IPSec-VPN-Tunnel-with-Peer-Having-Dynamic-IP-Address/ta-p/94161&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Second, confirm your phase 2 ProxyID configuration on the PAN side. It should be mirrored exactly the way your ASA is showing, but in opposite directions.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;PAN200 - IPSEC Phase 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ProxyID1&lt;BR /&gt;Local: 10.48.11.0/24&lt;BR /&gt;Remote: 192.168.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-VPN/ta-p/68931" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-VPN/ta-p/68931&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, run the following commands to troubleshoot and if you can post the output that would help us to assist you:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step 1:&lt;/STRONG&gt; Open two Putty sessions to your PA-200. On &lt;STRONG&gt;Screen One&lt;/STRONG&gt;, run the follwoing command:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;tail follow yes ike&amp;nbsp;tail follow yes mp-log ikemgr.log&lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;Step 2: &lt;/STRONG&gt;On Screen two run the following command:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test Phase 1&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;test vpn ike-sa&lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;Step 3: &lt;/STRONG&gt;Go back to &lt;STRONG&gt;Screen One&lt;/STRONG&gt; and read the outputs. if you can copy and post in this thread that would be help us to analyze the messages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let us know how it goes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 11 Jul 2017 00:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165701#M53214</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-07-11T00:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN Between PA and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165968#M53252</link>
      <description>&lt;P&gt;Thanks all for the input.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt;, I tried to use this command but it was inavliad.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;tail follow yes ike&amp;nbsp;tail follow yes mp-log ikemgr.log&lt;/PRE&gt;&lt;P&gt;The PAN's side Phase 2 config is as follows:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;IPsec Crypto: IKEPhase2_To_ASA&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;DH&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Group: group&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Authentication: sha1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Encryption: 3des&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Key lifetime:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;day&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Lifesize: 4608MB&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;======================================================================================&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I have tried to config the Proxy IDs as listed above and also tried/played with using differnt prefixs but that didn't make any effect.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;The phase 1 and phase 2 parameters of the ASA and PA are identical as I listed above.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Let me know what other info you'd like me to post that will be helpful.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Best,, ~sK&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 11 Jul 2017 22:48:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165968#M53252</guid>
      <dc:creator>Sadik_Khirbash</dc:creator>
      <dc:date>2017-07-11T22:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN Between PA and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165970#M53253</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48414"&gt;@Sadik_Khirbash&lt;/a&gt;&lt;/P&gt;&lt;P&gt;My apologies for my fat finger. The command is:&lt;/P&gt;&lt;PRE&gt;tail follow yes mp-log ikemgr.log&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;The phase 2 ProxyID is a crucial piece of this configuration, and it would be important for us that you ensure it configured properly. The concern is not the Phase 2 paramenters, but the Proxy ID configuration at this point.&lt;/P&gt;&lt;P&gt;That's how your Proxy ID should be configured on the PA-200 side.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ProxyID1.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10350i2FBE9A833466FB52/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ProxyID1.PNG" alt="ProxyID1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Run the above command and post the output for us, then maybe we can shine some light on it for you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 22:54:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165970#M53253</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-07-11T22:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN Between PA and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165971#M53254</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt;.. Thanks for the prompt response. &amp;nbsp;I did change the Proxy IDs to what you specified. Here's the output after executing the command:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rbash@PA-200&amp;gt; tail follow yes mp-log ikemgr.log&lt;BR /&gt;2017-07-11 16:13:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:13:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:13:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:14:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:14:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:14:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:14:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:14:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:14:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:15:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:15:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:15:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;/P&gt;&lt;P&gt;2017-07-11 16:15:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:15:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:15:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:16:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;/P&gt;&lt;P&gt;2017-07-11 16:16:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:16:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:16:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:16:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:16:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:17:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:17:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:17:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:17:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:17:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:17:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:18:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:18:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:18:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:18:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:18:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:18:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:19:04.175 -0700 ikemgr: panike_daemon phase 1 started, config size 17633&lt;BR /&gt;2017-07-11 16:19:04.178 -0700 ikemgr: panike_daemon phase 1 step 2 finished&lt;BR /&gt;2017-07-11 16:19:04.329 -0700 ikemgr: panike_daemon phase 1 step 4 finished&lt;BR /&gt;2017-07-11 16:19:04.329 -0700 pan IKE cfg phase-1 triggered.&lt;BR /&gt;2017-07-11 16:19:04 [INFO]: loading new config from /tmp/.rtoFSH&lt;BR /&gt;2017-07-11 16:19:05.130 -0700 ikemgr: panike_daemon phase 1 step 5 finished&lt;BR /&gt;2017-07-11 16:19:05.130 -0700 ikemgr: panike_daemon phase 1 config change detected&lt;BR /&gt;2017-07-11 16:19:05.130 -0700 ikemgr: panike_daemon phase 1 finished with status 1&lt;BR /&gt;2017-07-11 16:19:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:19:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:19:25.090 -0700 ikemgr: panike_daemon phase 2 started&lt;BR /&gt;2017-07-11 16:19:25.090 -0700 pan IKE cfg phase-2 triggered.&lt;BR /&gt;2017-07-11 16:19:25 [INFO]: VPN tunnel IPSec_Tunnel:ASA_LAN_TO_LAN(S2S_VPN_To_ASA) changed, deleting SA&lt;BR /&gt;2017-07-11 16:19:25 [INFO]: VPN tunnel IPSec_Tunnel:ASA_LAN_TO_LAN(S2S_VPN_To_ASA) changed, deleting SA&lt;BR /&gt;2017-07-11 16:19:25.091 -0700 ikemgr: panike_daemon phase 2 finished&lt;BR /&gt;2017-07-11 16:19:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:19:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:19:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:19:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:20:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:20:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:20:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:20:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:20:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:20:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:21:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:21:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:21:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:21:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:21:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:21:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:22:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:22:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:22:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:22:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:22:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:22:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:23:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:23:16 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:23:26 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:23:36 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:23:46 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:23:56 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;BR /&gt;2017-07-11 16:24:06 [PROTO_NOTIFY]: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=7d59e57bd6c54727 c40ffc76ee828c4e (size=16).&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 23:07:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165971#M53254</guid>
      <dc:creator>Sadik_Khirbash</dc:creator>
      <dc:date>2017-07-11T23:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN Between PA and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165973#M53255</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disable DPD for now. Enable&amp;nbsp;debug mode so we can get more info:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; debug ike global on debug&lt;/P&gt;&lt;P&gt;xxxxxxxxxx&amp;gt; debug ike global show&lt;/P&gt;&lt;P&gt;sw.ikedaemon.debug.global: debug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; test vpn ike-sa gateway (your gateway)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; tail follow yes mp-log ikemgr.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Configure debug back to "normal" mode:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt; debug ike global on normal&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 23:22:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/165973#M53255</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-11T23:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN Between PA and Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/166186#M53284</link>
      <description>&lt;P&gt;What version is PA-200 running?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 19:21:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-and-cisco-asa/m-p/166186#M53284</guid>
      <dc:creator>PAN-Expert</dc:creator>
      <dc:date>2017-07-12T19:21:10Z</dc:date>
    </item>
  </channel>
</rss>

