<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN decapsulation bytes are increasing and encapsulation is constant in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169631#M53868</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When l was checking the logs l could see that&amp;nbsp;the traffic was arriving on the correct tunnel.37 interface and going out the eth 1/5 interface. from the PCAPs from the PA&amp;nbsp;FW l can see both ping request(10.10.1.85)/reply(10.81.224.11) as well as allow logs for this&amp;nbsp;particular session:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PCAP.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10611i0A7039FF52701754/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PCAP.PNG" alt="PCAP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test routing fib-lookup virtual-router default ip 10.10.1.85&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;runtime route lookup&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;virtual-router: default&lt;BR /&gt;destination: 10.10.1.85&lt;BR /&gt;result:&lt;BR /&gt;interface tunnel.37, metric 10&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Must be something fundamental (&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2017 15:38:10 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-08-02T15:38:10Z</dc:date>
    <item>
      <title>IPSec VPN decapsulation bytes are increasing and encapsulation is constant</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169611#M53860</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Followed this&amp;nbsp;article on teh troubleshooting session:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We currently have an issue with S2S VPN between Palo and WatchGuard Fws.&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;VPN is up (at least from Palo site). Traffic is initiated from the WatchGuard side (10.10.1.85 src ip) going to the dst ip 10.81.224.11 and visible from our side. From the VPN flow we can see that PA is doing decap bytes but not encap. WatchGuard side also can see that they are sending traffic but 0 bytes received back. I have checked policies and FIB lookup and all look good. But we must missing something.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thx,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 14:23:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169611#M53860</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-02T14:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN decapsulation bytes are increasing and encapsulation is constant</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169626#M53865</link>
      <description>&lt;P&gt;If you ping&amp;nbsp;&lt;SPAN&gt;10.10.1.85 that is at peer site from behind Palo and check traffic log what is egress interface for this traffic?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are those ping requests sent to correct tunnel interface?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 15:29:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169626#M53865</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-08-02T15:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN decapsulation bytes are increasing and encapsulation is constant</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169631#M53868</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When l was checking the logs l could see that&amp;nbsp;the traffic was arriving on the correct tunnel.37 interface and going out the eth 1/5 interface. from the PCAPs from the PA&amp;nbsp;FW l can see both ping request(10.10.1.85)/reply(10.81.224.11) as well as allow logs for this&amp;nbsp;particular session:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PCAP.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10611i0A7039FF52701754/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PCAP.PNG" alt="PCAP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test routing fib-lookup virtual-router default ip 10.10.1.85&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;runtime route lookup&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;virtual-router: default&lt;BR /&gt;destination: 10.10.1.85&lt;BR /&gt;result:&lt;BR /&gt;interface tunnel.37, metric 10&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Must be something fundamental (&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 15:38:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169631#M53868</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-02T15:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN decapsulation bytes are increasing and encapsulation is constant</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169634#M53870</link>
      <description>&lt;P&gt;Ok but can you ping from&amp;nbsp;&lt;SPAN&gt;10.81.224.11 to&amp;nbsp;10.10.1.85?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is Egress interface&amp;nbsp;tunnel.37&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you see encap counter increasing?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 15:59:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169634#M53870</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-08-02T15:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN decapsulation bytes are increasing and encapsulation is constant</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169635#M53871</link>
      <description>&lt;P&gt;I know&amp;nbsp;what do you mean&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;but unfortunately, l had no chance to test reverse traffic as the server admin was away.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Definitely, can confirm that PA can see the reply from the server and definitely based on the FIB Lookup it will forward to the tunnel.37 interface. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 16:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169635#M53871</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-02T16:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN decapsulation bytes are increasing and encapsulation is constant</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169643#M53876</link>
      <description>&lt;P&gt;Did you only check with icmp or also with establishing a tcp connection (not just the tcp handshake?&lt;/P&gt;&lt;P&gt;In addition to that, as I have learn, there is also always the possibility that one side made mistakes in the implementation of the algorithms ... so could you also share the pan-os version and the algorithms you used for the connection?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2017 17:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/169643#M53876</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-02T17:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN decapsulation bytes are increasing and encapsulation is constant</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/170209#M53998</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, initial test was with RDP session. PAN-OS 7.1.5 and l will share VPN config tomorrow. Thx all&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2017 12:09:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/170209#M53998</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-06T12:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN decapsulation bytes are increasing and encapsulation is constant</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/170303#M54025</link>
      <description>&lt;P&gt;Just&amp;nbsp;FYI:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Had a TAC case opened for this issue. &amp;nbsp;Some&amp;nbsp;&lt;SPAN&gt;PBF rule had a misconfigured object, so the firewall was sending the traffic using that rule (reply traffic). Good to know to check next time not only FIB Lookup but also check PFB Lookup. Correcting the object fixed the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-To-Test-Security-NAT-and-PBF-Rules-via-the-CLI/ta-p/55911" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-To-Test-Security-NAT-and-PBF-Rules-via-the-CLI/ta-p/55911&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;EDIT:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We were not able to initiate any traffic from teh Palo side as by design&amp;nbsp;we had no allow policy. It is one-way C2S traffic. Server cannot initiate the session.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2017 12:08:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-decapsulation-bytes-are-increasing-and-encapsulation/m-p/170303#M54025</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-07T12:08:10Z</dc:date>
    </item>
  </channel>
</rss>

