<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN tunnel not coming up in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191494#M57667</link>
    <description>&lt;P&gt;correct, you should now see the negotiation taking place on the remote peer and see more info regarding what is succeeding and what is failing&lt;/P&gt;
&lt;P&gt;you can access the system logs and filter for ( subtype eq vpn )&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2017 09:43:51 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-12-13T09:43:51Z</dc:date>
    <item>
      <title>IPSec VPN tunnel not coming up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191251#M57636</link>
      <description>&lt;P&gt;I configured IPSec VPN tunnel between my&amp;nbsp; 2 PA FWs. The physical interfaces are up but the tunnel is not up. I am a Cisco guy and new to the PA. I am trying to see ipvpn traffic va the Monitor. But I did not see any traffic. How do I check for my ike phase 1 and ipsec phase 2 to make sure that all the parameters and the password matched on both side. Also, how do I need which side is the initiator and which side is the receiver? Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 04:06:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191251#M57636</guid>
      <dc:creator>jac101</dc:creator>
      <dc:date>2017-12-12T04:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel not coming up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191300#M57640</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59566"&gt;@jac101&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have you checked this article:&amp;nbsp;&lt;A title="Getting Started: VPN " href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-VPN/ta-p/68931" target="_blank"&gt;Getting Started: VPN&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can initiate from one peer by running&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&amp;gt; test vpn ike-sa gateway &amp;lt;gateway&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&amp;gt; test vpn ipsec-sa tunnel &amp;lt;value&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;the best place to start looking is in the 'system' log, the responder should have most information you need to fix configuration mismatches&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 10:28:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191300#M57640</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-12T10:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel not coming up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191328#M57648</link>
      <description>&lt;P&gt;How do I need which FW is the receiver?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 14:30:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191328#M57648</guid>
      <dc:creator>jac101</dc:creator>
      <dc:date>2017-12-12T14:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel not coming up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191329#M57649</link>
      <description>&lt;P&gt;if you execute the commands on firewall A, firewall B will be the receiver&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 14:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191329#M57649</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-12T14:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel not coming up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191333#M57650</link>
      <description>&lt;P&gt;I did the commands from my main FW. So the next step is to go to the remote FW and look at the Monitor. Correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5220A(active)&amp;gt; test vpn ike-sa gateway PHASE1-gtw2&lt;/P&gt;&lt;P&gt;Start time: Dec.12 10:28:45&lt;BR /&gt;Initiate 1 IKE SA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5220A(active)&amp;gt; test vpn ipsec-sa tunnel PHASE2-tunnel&lt;/P&gt;&lt;P&gt;Start time: Dec.12 10:29:18&lt;BR /&gt;Initiate 1 IPSec SA for tunnel PHASE2-tunnel.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:33:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191333#M57650</guid>
      <dc:creator>jac101</dc:creator>
      <dc:date>2017-12-12T15:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel not coming up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191494#M57667</link>
      <description>&lt;P&gt;correct, you should now see the negotiation taking place on the remote peer and see more info regarding what is succeeding and what is failing&lt;/P&gt;
&lt;P&gt;you can access the system logs and filter for ( subtype eq vpn )&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 09:43:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-not-coming-up/m-p/191494#M57667</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-13T09:43:51Z</dc:date>
    </item>
  </channel>
</rss>

