<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166488#M53344</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any particular clients facing this&amp;nbsp;issue?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jul 2017 08:14:51 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-07-14T08:14:51Z</dc:date>
    <item>
      <title>Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166479#M53342</link>
      <description>&lt;P&gt;We have a setup with a primary PA firewall 1 that pass through Globalprotect VPN traffic to a second PA firewall 2. We've seen sporadic connection problems when connecting a Globalprotect client. Sometimes it can spend up to 2 minutes to establish the VPN. When these connection problems occur firewall 1 will log unknown-udp on port 4501. Besides allowing any application with service ports in the Globalprotect policy, is it possible to improve reliability when using ipsec application?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 07:19:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166479#M53342</guid>
      <dc:creator>Trond.Olsen</dc:creator>
      <dc:date>2017-07-14T07:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166488#M53344</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any particular clients facing this&amp;nbsp;issue?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 08:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166488#M53344</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-14T08:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166720#M53378</link>
      <description>&lt;P&gt;This is on Windows 64-bit using the latest client software.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 08:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166720#M53378</guid>
      <dc:creator>Trond.Olsen</dc:creator>
      <dc:date>2017-07-17T08:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166836#M53390</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is hard to conclude based on this info. In your GP policy, do you have services as "any" or "application-default"? Do you have an&amp;nbsp;ability to raise the TAC case providing them with the PCAP from the firewall when the issue is visible?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 18:27:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166836#M53390</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-17T18:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166873#M53397</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37017"&gt;@Trond.Olsen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This should be a fairly stable signature; I would raise a case with TAC and see if they could work with you on it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 20:15:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166873#M53397</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-17T20:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166944#M53402</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&lt;BR /&gt;Policy was initially configured with default-application. We've experienced better reliabilty using service ports instead. Still get sporadic VPN connections thats logged as unknown-udp on port 4501 though but it working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also forgot to mention that there is a destination NAT policy involved.&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;BR /&gt;Its a bit hard to do packet capture since vpn connections generate so much data. We've got no reliable way to reproduce unknown-udp application detection. But I'll keep it in mind in case we have do to some further digging.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 06:24:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166944#M53402</guid>
      <dc:creator>Trond.Olsen</dc:creator>
      <dc:date>2017-07-18T06:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166988#M53408</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l don't think DNAT should or causing issues. If application is identified incorrectly (unknown-udp it is also app within the database) then TAC case is the next destination &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; Please post the outcome&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 12:03:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/166988#M53408</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-18T12:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable ipsec detection for ipsec-esp-udp application when connecting Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/188901#M57267</link>
      <description>&lt;P&gt;An update: This was a hard to replicate APP-ID misidentification but got fixed in content update 752-4343.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:33:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unstable-ipsec-detection-for-ipsec-esp-udp-application-when/m-p/188901#M57267</guid>
      <dc:creator>Trond.Olsen</dc:creator>
      <dc:date>2017-11-28T09:33:31Z</dc:date>
    </item>
  </channel>
</rss>

