<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN IPSec No Proposal Chosen in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173097#M54536</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;is right we'll need the responder site logs to see why it isn't working. Initiatior isn't going to tell you anything. I would remove the proxy-id as already mentioned, you don't actually need this and having proxy-id on can cause issues in and of itself when you can't tell exactly how the other end is configured.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2017 14:27:02 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-08-24T14:27:02Z</dc:date>
    <item>
      <title>VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173076#M54530</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I keep having issues with my IPSec sts VPN. Always have a No proposal chosen message on the Phase 2 proposal.&lt;/P&gt;&lt;P&gt;And then P2 proposal fails due to timeout.&lt;/P&gt;&lt;P&gt;I read that it could be IPSec crypto settings or proxy ID that don't match.&lt;/P&gt;&lt;P&gt;Proxy IDs are OK because when I put non-existing network, I don't have these messages.&lt;/P&gt;&lt;P&gt;Encryption settings seem also well configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the Fortigate P2 that was working before :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="M6P2.png" style="width: 749px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10911iB461F7FF81A4CD57/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="M6P2.png" alt="M6P2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the Palo Alto config that i'm trying to make working :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="crypto.png" style="width: 798px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10913iBD259C66B57DFE04/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="crypto.png" alt="crypto.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPsec tunnel.png" style="width: 798px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10915i0401BCE0C42A81E7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="IPsec tunnel.png" alt="IPsec tunnel.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPsec tunnel2.png" style="width: 790px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10914i1554EA252B1CB48B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="IPsec tunnel2.png" alt="IPsec tunnel2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 13:27:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173076#M54530</guid>
      <dc:creator>Naelwan</dc:creator>
      <dc:date>2017-08-24T13:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173085#M54531</link>
      <description>&lt;P&gt;Did you try without PFS or untick option 5 from the&amp;nbsp;&lt;SPAN&gt;Fortigate site? We need a full log output?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;EDIT:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Reading more, it looks like you don't have&amp;nbsp;to use any proxy IDs as both devices support route-based VPN&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://blog.webernetz.net/2015/01/26/ipsec-site-to-site-vpn-palo-alto-fortigate/" target="_blank"&gt;https://blog.webernetz.net/2015/01/26/ipsec-site-to-site-vpn-palo-alto-fortigate/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 14:01:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173085#M54531</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-24T14:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173092#M54532</link>
      <description>&lt;P&gt;I tried without PFS and&amp;nbsp;the result is the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have access to the remote firewall but as I remember, it is supposed to accept both proposals on DHGroup 5 and DHGroup 14.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the full log output :&lt;/P&gt;&lt;LI-SPOILER&gt;2017-08-24 15:52:58.828 +0200 [PNTF]: { 3: 12}: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;BR /&gt;====&amp;gt; Initiated SA: WAN_IP[500]-DST_WAN_IP[500] message id:0x8C47EF4D &amp;lt;====&lt;BR /&gt;2017-08-24 15:52:58.845 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4).&lt;BR /&gt;2017-08-24 15:53:01.015 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4).&lt;BR /&gt;2017-08-24 15:53:04.005 +0200 [PNTF]: { 3: }: notification message 36137:R-U-THERE-ACK, doi=1 proto_id=1 spi=596ffb652fb039fd 8ebc5e12d094fa99 (size=16).&lt;BR /&gt;2017-08-24 15:53:04.005 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4).&lt;BR /&gt;2017-08-24 15:53:05.884 +0200 [PERR]: packet (5) shorter than isakmp header size.&lt;BR /&gt;2017-08-24 15:53:09.005 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4).&lt;BR /&gt;2017-08-24 15:53:15.884 +0200 [PERR]: packet (5) shorter than isakmp header size.&lt;BR /&gt;2017-08-24 15:53:17.015 +0200 [PNTF]: { 3: }: notification message 14:NO-PROPOSAL-CHOSEN, doi=1 proto_id=3 spi=dd34eb2c(size=4).&lt;BR /&gt;2017-08-24 15:53:25.884 +0200 [PERR]: packet (5) shorter than isakmp header size.&lt;BR /&gt;2017-08-24 15:53:29.002 +0200 [PNTF]: { : 12}: ====&amp;gt; PHASE-2 NEGOTIATION FAILED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;BR /&gt;====&amp;gt; Failed SA: WAN_IP[500]-DST_WAN_IP[500] message id:0x8C47EF4D &amp;lt;==== Due to negotiation timeout.&lt;BR /&gt;2017-08-24 15:53:34.015 +0200 [PNTF]: { 3: }: notification message 36137:R-U-THERE-ACK, doi=1 proto_id=1 spi=596ffb652fb039fd 8ebc5e12d094fa99 (size=16).&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 14:00:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173092#M54532</guid>
      <dc:creator>Naelwan</dc:creator>
      <dc:date>2017-08-24T14:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173093#M54533</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Palo is an initiator. If you want more details we need responder site logs or configure Palo in passive mode.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 14:04:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173093#M54533</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-24T14:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173097#M54536</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;is right we'll need the responder site logs to see why it isn't working. Initiatior isn't going to tell you anything. I would remove the proxy-id as already mentioned, you don't actually need this and having proxy-id on can cause issues in and of itself when you can't tell exactly how the other end is configured.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 14:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173097#M54536</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-24T14:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173098#M54537</link>
      <description>&lt;P&gt;If I remove the Proxy IDs, the P2 Proposal fails due to a timeout, but without "no proposal chosen" message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have an easy access to the remote firewall but I'll post its logs as soon as I can.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note that I don't know what is the remote firewall. The Fortigate was the firewall that I replaced by the Palo. Its configuration was workin though.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 14:29:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173098#M54537</guid>
      <dc:creator>Naelwan</dc:creator>
      <dc:date>2017-08-24T14:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173099#M54538</link>
      <description>&lt;P&gt;If you remove the configuration from one side, another side should do the same otherwise it is pointless as all P1 and P2 criteria&amp;nbsp;must match.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 14:31:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173099#M54538</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-24T14:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173100#M54539</link>
      <description>&lt;P&gt;I know that all parameters must match, that's why I'm trying to make the exact replica of my old Fortigate into the Palo.&lt;/P&gt;&lt;P&gt;The only thing that seems to be different for the P2 is that I can't select several DH groups.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 14:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173100#M54539</guid>
      <dc:creator>Naelwan</dc:creator>
      <dc:date>2017-08-24T14:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173131#M54547</link>
      <description>&lt;P&gt;What PAN-OS version do you have installed? What IKE version is configured?&lt;/P&gt;&lt;P&gt;You wrote that the tunnel was working already: did you do anything before it stopped working (may be a PAN-OS update)?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 17:40:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173131#M54547</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-24T17:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173218#M54558</link>
      <description>&lt;P&gt;Have you tried Group 5 for PFS? Just because the Fortigate had both groups 14 and 5 enabled doesn't mean the other side will accept both&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 13:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173218#M54558</guid>
      <dc:creator>9t89m8fu</dc:creator>
      <dc:date>2017-08-25T13:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN IPSec No Proposal Chosen</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173565#M54607</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-OS version is 8.0.3&lt;/P&gt;&lt;P&gt;IKE v1 only.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2152"&gt;@9t89m8fu&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I've tried PFS 5 before but didn't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've just tried again as a double check and ... it works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I might have changed something else but can't remember what.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks everyone for the help.&lt;/P&gt;&lt;P&gt;BR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 08:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ipsec-no-proposal-chosen/m-p/173565#M54607</guid>
      <dc:creator>Naelwan</dc:creator>
      <dc:date>2017-08-29T08:25:27Z</dc:date>
    </item>
  </channel>
</rss>

