<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN  between PA 3020 8.0 to Cisco ASA 9.x code. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209037#M61133</link>
    <description>&lt;P&gt;So that's one of the things I was needing to understand.&lt;/P&gt;&lt;P&gt;Am I creating a PID for every host that has access over the tunnel?&lt;/P&gt;&lt;P&gt;Or does a subnet range work for this?&lt;/P&gt;&lt;P&gt;On the ASA side I have an ACL just allowing a few host to access the tunnel.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Apr 2018 15:35:16 GMT</pubDate>
    <dc:creator>brian.schroeder</dc:creator>
    <dc:date>2018-04-06T15:35:16Z</dc:date>
    <item>
      <title>S2S VPN  between PA 3020 8.0 to Cisco ASA 9.x code.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/208949#M61118</link>
      <description>&lt;P&gt;First thing,&lt;/P&gt;&lt;P&gt;I know there are postings about this out on the web and community about this. The problem I'm having is everything out there is on old ASA code.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to understand the configuration on the PA. I have my tunnel interface configured, IKE Crypto, IPSec Crypto, IKE Gateway, and IPSec Tunnel. I can't get the Phase 1 to come up. I've verified the DH Groups, Authentication, and Encryption setting are the same on both sides. Can someone point me in a direction where they think my problem might be?&lt;/P&gt;&lt;P&gt;Thanks for any help given,&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 23:40:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/208949#M61118</guid>
      <dc:creator>brian.schroeder</dc:creator>
      <dc:date>2018-04-05T23:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN  between PA 3020 8.0 to Cisco ASA 9.x code.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209011#M61128</link>
      <description>&lt;P&gt;Checking (and posting) logs would be a good start.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 10:11:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209011#M61128</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-04-06T10:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN  between PA 3020 8.0 to Cisco ASA 9.x code.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209033#M61131</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48699"&gt;@brian.schroeder&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Did you verify that your proxy-ids are setup correctly. As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;stated logs would be the thing that will tell you what's actually happening.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 15:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209033#M61131</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-06T15:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN  between PA 3020 8.0 to Cisco ASA 9.x code.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209035#M61132</link>
      <description>&lt;P&gt;I'll be pulling those soon.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 15:31:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209035#M61132</guid>
      <dc:creator>brian.schroeder</dc:creator>
      <dc:date>2018-04-06T15:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN  between PA 3020 8.0 to Cisco ASA 9.x code.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209037#M61133</link>
      <description>&lt;P&gt;So that's one of the things I was needing to understand.&lt;/P&gt;&lt;P&gt;Am I creating a PID for every host that has access over the tunnel?&lt;/P&gt;&lt;P&gt;Or does a subnet range work for this?&lt;/P&gt;&lt;P&gt;On the ASA side I have an ACL just allowing a few host to access the tunnel.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 15:35:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209037#M61133</guid>
      <dc:creator>brian.schroeder</dc:creator>
      <dc:date>2018-04-06T15:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN  between PA 3020 8.0 to Cisco ASA 9.x code.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209040#M61134</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48699"&gt;@brian.schroeder&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Cisco is policy-based while the Palo Alto is route-based. The Palo Alto is essentially defaulting to 0.0.0.0/0 source and 0.0.0.0/0 destiantion. If they don't match things aren't going to form correctly. You can use a network range as long as that's what the ASA is sending; if they don't match you'll still have an issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's two good articles about proxy-ids &lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Help-with-IPSec-Proxy-IDs-with-overlapping-IPs/ta-p/69123" target="_blank"&gt;HERE&lt;/A&gt;&amp;nbsp;and &lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Why-Use-a-VPN-Proxy-ID/ta-p/69524" target="_blank"&gt;HERE&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 15:45:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209040#M61134</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-06T15:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN  between PA 3020 8.0 to Cisco ASA 9.x code.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209041#M61135</link>
      <description>&lt;P&gt;Initiate vpn traffic from ASA side and check logs on Palo.&lt;/P&gt;&lt;P&gt;Monitor &amp;gt; System&lt;/P&gt;&lt;P&gt;If you can't identify issue yourself then share logs here.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 15:54:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209041#M61135</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-04-06T15:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN  between PA 3020 8.0 to Cisco ASA 9.x code.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209188#M61170</link>
      <description>&lt;P&gt;ACL for crypo-map on Cisco and Proxy IDs on PA must match for VPN to work. While PA isn't too strict about exact matches, policy based FWs like ASA usually are.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But check logs first, you will find the answer there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2018 06:57:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/s2s-vpn-between-pa-3020-8-0-to-cisco-asa-9-x-code/m-p/209188#M61170</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-04-09T06:57:49Z</dc:date>
    </item>
  </channel>
</rss>

