<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221795#M63831</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We chnaged the proposal several times with no success. It seems like issue is in the life time. But we also change this paramether. We will try tomorrow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jul 2018 18:26:43 GMT</pubDate>
    <dc:creator>BigPalo</dc:creator>
    <dc:date>2018-07-11T18:26:43Z</dc:date>
    <item>
      <title>VPN not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221680#M63813</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are configuring a VPn between Palo Alto and PFsense. The VPN is configured properly but its nos getting up. No phase 1 up. We have treid to change all values proposals and lifetime.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the log. We tried to change lifetime with no success. Whats happening?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;====&amp;gt; Initiated SA: 1.1.1.1[500]-2.2.2.2[500] cookie:4ff9f28d21a8b446:cc5af7ee92b1eb65 &amp;lt;====&lt;BR /&gt;2018-07-11 09:51:42 [INFO]: received Vendor ID: draft-ietf-ipsra-isakmp-xauth-06.txt&lt;BR /&gt;2018-07-11 09:51:42 [INFO]: received Vendor ID: DPD&lt;BR /&gt;2018-07-11 09:51:42 [INFO]: received Vendor ID: FRAGMENTATION&lt;BR /&gt;2018-07-11 09:51:42 [INFO]: received Vendor ID: RFC 3947&lt;BR /&gt;2018-07-11 09:51:42 [INFO]: received Vendor ID: draft-ietf-ipsec-nat-t-ike-02&lt;BR /&gt;&lt;BR /&gt;2018-07-11 09:51:42 [INFO]: Selected NAT-T version: RFC 3947&lt;BR /&gt;2018-07-11 09:51:42 [PROTO_ERR]: invalid life duration.&lt;BR /&gt;2018-07-11 09:51:42 [PROTO_ERR]: invalid life duration.&lt;BR /&gt;2018-07-11 09:51:42 [PROTO_ERR]: no suitable proposal found.&lt;BR /&gt;2018-07-11 09:51:42 [PROTO_ERR]: 0:? - 2.2.2.2[500]:(nil):failed to get valid proposal.&lt;BR /&gt;2018-07-11 09:51:42 [PROTO_ERR]: failed to process packet.&lt;BR /&gt;2018-07-11 09:51:42 [INFO]: ====&amp;gt; PHASE-1 SA DELETED &amp;lt;====&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 08:00:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221680#M63813</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2018-07-11T08:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221776#M63828</link>
      <description>&lt;P&gt;your crypto map needs to be synced&lt;/P&gt;
&lt;P&gt;both ends expect to talk different protocols:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;018-07-11 09:51:42 [PROTO_ERR]: no suitable proposal found.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2018-07-11 09:51:42 [PROTO_ERR]: 0:? - 2.2.2.2[500]:(nil):failed to get valid proposal.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;this means they could not decide if they want (for example) sha256 and aes1024, or md5+3des&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 16:43:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221776#M63828</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-07-11T16:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221795#M63831</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We chnaged the proposal several times with no success. It seems like issue is in the life time. But we also change this paramether. We will try tomorrow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 18:26:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221795#M63831</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2018-07-11T18:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221849#M63835</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;stated that's kind of what this type of error message means. Can you verify that you are actually offering up the correct protocols that you wish to utilize and try again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 21:07:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221849#M63835</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-11T21:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221852#M63838</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turn on debugging for the ike process (debug ike global on debug) then take a look at the ikemgr logs. This will then show you exactly what the peer and the remote end is proposing and where the mismatch lies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The log format will be for example aes256:aes512, where 256 is local and 512 is remote.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S - don't forget to turn off debugging afterwards!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 21:14:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-not-working/m-p/221852#M63838</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-07-11T21:14:50Z</dc:date>
    </item>
  </channel>
</rss>

