<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nat-t not enabled on vpn tunnel has impact on other tunnels in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nat-t-not-enabled-on-vpn-tunnel-has-impact-on-other-tunnels/m-p/207295#M60779</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I think a bit more clarity is required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If NAT-T is required, but not enabled, the ipsec/phase2 should not stand up at all and your users wouldn't be able to get at anything (not simply RDP). NAT-T should impact the establishment of your new tunnels, I don't see how (short of a very unusual bug) that it would affect encap traffic inside another tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Did the new tunnels fully establish?&lt;/LI&gt;&lt;LI&gt;Could users access services over the new tunnel?&lt;/LI&gt;&lt;LI&gt;Were services other than RDP affected on the other (historical) tunnels?&lt;/LI&gt;&lt;LI&gt;Have you done a config audit and compared the last known working config, to the new config to verify that&amp;nbsp;that&amp;nbsp;was the only change?&lt;/LI&gt;&lt;LI&gt;Are all your tunnels using static peer IP addressing, or are some of them configured as dynamic?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 25 Mar 2018 20:55:47 GMT</pubDate>
    <dc:creator>SARowe_NZ</dc:creator>
    <dc:date>2018-03-25T20:55:47Z</dc:date>
    <item>
      <title>nat-t not enabled on vpn tunnel has impact on other tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-t-not-enabled-on-vpn-tunnel-has-impact-on-other-tunnels/m-p/207092#M60747</link>
      <description>&lt;P&gt;&lt;BR /&gt;i just had a weird behavior. i have several ipsec tunnels for clients using the ncp secure entry client.&lt;BR /&gt;&lt;BR /&gt;they all have tunnels configured with certificates and a dynamic peer ip. yesterday i created two new tunnels but forgot to check the nat-t checkbox. and some of the users couldn't get a connection via rdp. my understanding was that it shouldn't impact other vpn tunnels as they established the connection to the correct tunnel with nat-t enabled. i don't know if its really the nat-t checkbox but it was the only difference to the other tunnels i configured.&lt;BR /&gt;&lt;BR /&gt;pan os version is 8.0.5 and app version is 793-4594.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;is this a design failure?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 08:45:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-t-not-enabled-on-vpn-tunnel-has-impact-on-other-tunnels/m-p/207092#M60747</guid>
      <dc:creator>VARNObit</dc:creator>
      <dc:date>2018-03-23T08:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: nat-t not enabled on vpn tunnel has impact on other tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-t-not-enabled-on-vpn-tunnel-has-impact-on-other-tunnels/m-p/207295#M60779</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry I think a bit more clarity is required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If NAT-T is required, but not enabled, the ipsec/phase2 should not stand up at all and your users wouldn't be able to get at anything (not simply RDP). NAT-T should impact the establishment of your new tunnels, I don't see how (short of a very unusual bug) that it would affect encap traffic inside another tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Did the new tunnels fully establish?&lt;/LI&gt;&lt;LI&gt;Could users access services over the new tunnel?&lt;/LI&gt;&lt;LI&gt;Were services other than RDP affected on the other (historical) tunnels?&lt;/LI&gt;&lt;LI&gt;Have you done a config audit and compared the last known working config, to the new config to verify that&amp;nbsp;that&amp;nbsp;was the only change?&lt;/LI&gt;&lt;LI&gt;Are all your tunnels using static peer IP addressing, or are some of them configured as dynamic?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Mar 2018 20:55:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-t-not-enabled-on-vpn-tunnel-has-impact-on-other-tunnels/m-p/207295#M60779</guid>
      <dc:creator>SARowe_NZ</dc:creator>
      <dc:date>2018-03-25T20:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: nat-t not enabled on vpn tunnel has impact on other tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nat-t-not-enabled-on-vpn-tunnel-has-impact-on-other-tunnels/m-p/207325#M60785</link>
      <description>&lt;P&gt;Hi Shannon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to answer your questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. i could not test the new tunnels, because i was not at customers side and i can not use the ncp client anymore (have no license)&lt;/P&gt;&lt;P&gt;2. could also not be tested&lt;/P&gt;&lt;P&gt;3. yes even a ping does'nt go through the tunnel. But there were other tunnels that were not affected and worked properly.&lt;/P&gt;&lt;P&gt;4. i compared the configuration of other tunnels to the new tunnels and this was the only difference. as soon as i disabled the new tunnels everything worked just fine again.&lt;/P&gt;&lt;P&gt;5. the tunnels using ncp as client are all dynamic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Kind Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gregor&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 06:15:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nat-t-not-enabled-on-vpn-tunnel-has-impact-on-other-tunnels/m-p/207325#M60785</guid>
      <dc:creator>VARNObit</dc:creator>
      <dc:date>2018-03-26T06:15:59Z</dc:date>
    </item>
  </channel>
</rss>

