<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: site 2 site with Meraki NAT'd behind ISP router?? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/171920#M54306</link>
    <description>&lt;P&gt;Its configured as below with passive mode and NAT-T enabled.&lt;/P&gt;&lt;P&gt;192.168.20.101 is the IP on meraki external interface. which comnnects a 4G WIFI on its LAN. 4G WIFI itself gets a private IP from ISP and the at some point ISP NAT's the 4G private IP to a public IP&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.JPG" style="width: 605px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10811iFD1626A3D284D8E5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture2.JPG" alt="Capture2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logs&lt;/P&gt;&lt;P&gt;====&amp;gt; Initiated SA: X.X.X.131[500]-Y.Y.Y.245[4511] cookie:c4e0d99306433667:bd243bf0d0ae78cc &amp;lt;====&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: RFC 3947&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02&lt;/P&gt;&lt;P&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: draft-ietf-ipsec-nat-t-ike-00&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: DPD&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Selected NAT-T version: RFC 3947&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Hashing X.X.X.131[500] with algo #2&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: NAT-D payload #0 doesn't match&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Hashing Y.Y.Y.245[4511] with algo #2&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: NAT-D payload #1 doesn't match&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: NAT detected: ME PEER&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Hashing Y.Y.Y.245[4511] with algo #2&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Hashing X.X.X.131[500] with algo #2&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Adding remote and local NAT-D payloads.&lt;BR /&gt;2017-08-16 10:18:11 [PROTO_NOTIFY]: ====&amp;gt; PHASE-1 NEGOTIATION SUCCEEDED AS RESPONDER, MAIN MODE &amp;lt;====&lt;BR /&gt;====&amp;gt; Established SA: X.X.X.131[4500]-Y.Y.Y.245[16212] cookie:c4e0d99306433667:bd243bf0d0ae78cc lifetime 28800 Sec &amp;lt;====&lt;BR /&gt;2017-08-16 10:19:05 [INFO]: IKE IPSEC KEY_DELETE recvd: SPI:0x2A30BF32.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Aug 2017 17:50:34 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2017-08-16T17:50:34Z</dc:date>
    <item>
      <title>site 2 site with Meraki NAT'd behind ISP router??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169194#M53783</link>
      <description>&lt;P&gt;We have a remote site connected behind ISP router and Meraki receives 192.168.X.X IP from it, and all networks locally are connected further to Meraki. The main site has public IP directly on the firewall. Not sure how to make configuration work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 03:44:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169194#M53783</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-08-01T03:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: site 2 site with Meraki NAT'd behind ISP router??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169224#M53785</link>
      <description>&lt;P&gt;For S2S VPN use NAT-T function. Put the main site into the passive mode, so Meraki site always initiates a connection. This&amp;nbsp;way you don't have to worry about port forwarding for 4500, 500 and ESP on the ISP router.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 06:51:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169224#M53785</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-01T06:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: site 2 site with Meraki NAT'd behind ISP router??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169233#M53787</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&lt;/P&gt;&lt;P&gt;And you probably need to configure the internal IP of the meraki-device as remote identification on your firewall (or use a completely different ike identifier or the public IP on your meraki as local identifier)&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 07:25:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169233#M53787</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-01T07:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: site 2 site with Meraki NAT'd behind ISP router??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169959#M53958</link>
      <description>&lt;P&gt;I had enabled NAT-T but its not working. I get this error which point to the private WAN IP that Meraki has got.&lt;/P&gt;&lt;P&gt;"IKE phase-1 negotiation is failed. Peer\'s ID payload 192.168.20.101 (type ipaddr) does not match a configured IKE gateway"&lt;/P&gt;&lt;P&gt;Also enabling passive mode doesn't seem to work as i don't see any traffic from Meraki IP untill i disable it.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 21:38:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169959#M53958</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-08-03T21:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: site 2 site with Meraki NAT'd behind ISP router??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169960#M53959</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Did you read my post? This is the solution for your problem...&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 21:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/169960#M53959</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-03T21:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: site 2 site with Meraki NAT'd behind ISP router??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/170634#M54070</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Did it work when you configure the private IP address as remote peed ID in the IKE gateway object on your paloalto?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 21:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/170634#M54070</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-08T21:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: site 2 site with Meraki NAT'd behind ISP router??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/171920#M54306</link>
      <description>&lt;P&gt;Its configured as below with passive mode and NAT-T enabled.&lt;/P&gt;&lt;P&gt;192.168.20.101 is the IP on meraki external interface. which comnnects a 4G WIFI on its LAN. 4G WIFI itself gets a private IP from ISP and the at some point ISP NAT's the 4G private IP to a public IP&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.JPG" style="width: 605px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10811iFD1626A3D284D8E5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture2.JPG" alt="Capture2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logs&lt;/P&gt;&lt;P&gt;====&amp;gt; Initiated SA: X.X.X.131[500]-Y.Y.Y.245[4511] cookie:c4e0d99306433667:bd243bf0d0ae78cc &amp;lt;====&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: RFC 3947&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02&lt;/P&gt;&lt;P&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: draft-ietf-ipsec-nat-t-ike-00&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: received Vendor ID: DPD&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Selected NAT-T version: RFC 3947&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Hashing X.X.X.131[500] with algo #2&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: NAT-D payload #0 doesn't match&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Hashing Y.Y.Y.245[4511] with algo #2&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: NAT-D payload #1 doesn't match&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: NAT detected: ME PEER&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Hashing Y.Y.Y.245[4511] with algo #2&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Hashing X.X.X.131[500] with algo #2&lt;BR /&gt;2017-08-16 10:18:11 [INFO]: Adding remote and local NAT-D payloads.&lt;BR /&gt;2017-08-16 10:18:11 [PROTO_NOTIFY]: ====&amp;gt; PHASE-1 NEGOTIATION SUCCEEDED AS RESPONDER, MAIN MODE &amp;lt;====&lt;BR /&gt;====&amp;gt; Established SA: X.X.X.131[4500]-Y.Y.Y.245[16212] cookie:c4e0d99306433667:bd243bf0d0ae78cc lifetime 28800 Sec &amp;lt;====&lt;BR /&gt;2017-08-16 10:19:05 [INFO]: IKE IPSEC KEY_DELETE recvd: SPI:0x2A30BF32.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 17:50:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/171920#M54306</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-08-16T17:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: site 2 site with Meraki NAT'd behind ISP router??</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/171980#M54326</link>
      <description>&lt;P&gt;Clearly, you are not getting&amp;nbsp;P2 established. What do you have in the proxy id section on both peers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MX-Z/Site-to-site_VPN/Troubleshooting_Non-Meraki_Site-to-site_VPN_Peers" target="_blank"&gt;https://documentation.meraki.com/MX-Z/Site-to-site_VPN/Troubleshooting_Non-Meraki_Site-to-site_VPN_Peers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 22:23:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-with-meraki-nat-d-behind-isp-router/m-p/171980#M54326</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-16T22:23:51Z</dc:date>
    </item>
  </channel>
</rss>

