<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN SITE TO SITE PALO ALTO NETWORKS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/216837#M62769</link>
    <description>&lt;P&gt;After configuring the new zone, did you create a security policy rule to allow traffic? e,g,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from: VPNZone&lt;/P&gt;&lt;P&gt;source: any&lt;/P&gt;&lt;P&gt;to: any&lt;/P&gt;&lt;P&gt;destination: any&lt;/P&gt;&lt;P&gt;application:any&lt;/P&gt;&lt;P&gt;service: any&lt;/P&gt;&lt;P&gt;action: allow&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jun 2018 13:20:40 GMT</pubDate>
    <dc:creator>LukeBullimore</dc:creator>
    <dc:date>2018-06-06T13:20:40Z</dc:date>
    <item>
      <title>VPN SITE TO SITE PALO ALTO NETWORKS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/215859#M62561</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configure a VPN tunnel between two firewalls Palo alto Networks . The tunnel status is up but the other network is unreacheable.&lt;/P&gt;&lt;P&gt;I configure the tunnel on the trust zone . I restart the firewalls without result . The first PA-500 with PANOS 7.1.0 and the second with PANOS 8.0.3&lt;/P&gt;&lt;P&gt;Should I do an upgrade to the OS? Or there is any suggestion to do ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will appreciate your helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 09:10:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/215859#M62561</guid>
      <dc:creator>ra7oub4</dc:creator>
      <dc:date>2018-05-30T09:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SITE TO SITE PALO ALTO NETWORKS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/215873#M62562</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73583"&gt;@ra7oub4&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you configure routes to the tunnel interface ? Any information in the logs ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Eitherway, both PAN-OS versions are rather old and I would recommend upgrading.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;7.1.0 was released in March 2016.&lt;/P&gt;
&lt;P&gt;8.0.3 was released in June 2017.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A good resource with a lot of info :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/IPSec-and-tunneling-resource-list/ta-p/67721" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/IPSec-and-tunneling-resource-list/ta-p/67721&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 09:49:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/215873#M62562</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-05-30T09:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SITE TO SITE PALO ALTO NETWORKS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/215876#M62563</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply . Yes I configure the necessary route&amp;nbsp;. I follow all the steps listed in this article&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-IPSec-VPN/ta-p/56535&amp;nbsp;" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-IPSec-VPN/ta-p/56535&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the logs, I found this information :&lt;/P&gt;&lt;P&gt;IKEv2 child SA negotiation is started as initiator, rekey. Initiated SA: x.x.x.x[500]-y.y.y.y[500] message id:0x00000000.&lt;BR /&gt;IKEv2 child SA negotiation is started as initiator, rekey. Initiated SA&lt;BR /&gt;IKEv2 IPSec SA delete message sent to peer. Protocol:ESP, SPI:0x982EEEEA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you any suggestion to do . Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 10:07:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/215876#M62563</guid>
      <dc:creator>ra7oub4</dc:creator>
      <dc:date>2018-05-30T10:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SITE TO SITE PALO ALTO NETWORKS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/215895#M62570</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73583"&gt;@ra7oub4&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm leaning towards some negotiation issues... doublecheck if settings are the same on both ends.&lt;/P&gt;
&lt;P&gt;Also try increasing the debug level for more information :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Troubleshoot-IPSec-VPN-connectivity-issues/ta-p/59187&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Advanced-VPN-IPSec-troubleshooting-8-0-enable-debugging-per-VPN/ta-p/169303" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Advanced-VPN-IPSec-troubleshooting-8-0-enable-debugging-per-VPN/ta-p/169303&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 13:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/215895#M62570</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2018-05-30T13:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SITE TO SITE PALO ALTO NETWORKS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/216300#M62668</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You mentioned you applied your tunnel interface to the "Trust" zone. Is there a possibility that your VPN traffic is being NATted?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What happens if you make a new zone for the tunnel interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 15:59:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/216300#M62668</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-01T15:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SITE TO SITE PALO ALTO NETWORKS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/216810#M62765</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response . I try to configure the VPN in another Zone called VPNZone without result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found this logs in the monitor tab:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKE protocol IPSec SA delete message sent to peer.&lt;BR /&gt;IKE daemon configuration load phase-2 succeeded&lt;BR /&gt;IKE daemon configuration load phase-1 succeeded&lt;BR /&gt;IKE daemon configuration load phase-1 aborted&lt;BR /&gt;IKE daemon configuration load phase-2 aborted&lt;BR /&gt;Installed SA: 1.1.1.1[500]-2.2.2.2[500] SPI:0xBC2E363C/0xCAE56096 lifetime 3600 Sec lifesize unlimited&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will appreciate all your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 11:24:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/216810#M62765</guid>
      <dc:creator>ra7oub4</dc:creator>
      <dc:date>2018-06-06T11:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SITE TO SITE PALO ALTO NETWORKS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/216837#M62769</link>
      <description>&lt;P&gt;After configuring the new zone, did you create a security policy rule to allow traffic? e,g,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from: VPNZone&lt;/P&gt;&lt;P&gt;source: any&lt;/P&gt;&lt;P&gt;to: any&lt;/P&gt;&lt;P&gt;destination: any&lt;/P&gt;&lt;P&gt;application:any&lt;/P&gt;&lt;P&gt;service: any&lt;/P&gt;&lt;P&gt;action: allow&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 13:20:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/216837#M62769</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-06T13:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SITE TO SITE PALO ALTO NETWORKS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/216874#M62779</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I configured this security rule without result .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I allow trafic:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From :&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPNZone&lt;/P&gt;&lt;P&gt;InternalZone&lt;/P&gt;&lt;P&gt;source: any&lt;/P&gt;&lt;P&gt;TO:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;InternalZone&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;VPNZone&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;destination: any&lt;/P&gt;&lt;P&gt;application:any&lt;/P&gt;&lt;P&gt;service: any&lt;/P&gt;&lt;P&gt;action: allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I modify the destination to any?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jun 2018 16:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-site-to-site-palo-alto-networks/m-p/216874#M62779</guid>
      <dc:creator>ra7oub4</dc:creator>
      <dc:date>2018-06-06T16:39:13Z</dc:date>
    </item>
  </channel>
</rss>

