<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec P2P VPN Tunnel not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237482#M68036</link>
    <description>&lt;P&gt;So when there is no interesting traffic on GUI of IPsec tunnel we will see both reds?&lt;/P&gt;&lt;P&gt;mean both ike and ipsec will be down with out interesting traffic?&lt;/P&gt;</description>
    <pubDate>Sun, 28 Oct 2018 04:06:58 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2018-10-28T04:06:58Z</dc:date>
    <item>
      <title>IPSec P2P VPN Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237272#M67977</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to terminate on PaloAlto VM-100 (8.0.13) an IPsec tunnel.&lt;/P&gt;&lt;P&gt;It seems that the other side is not able to connect at all. We have checke all IKE settings and they seem OK.&lt;BR /&gt;I am using a Loopback interface with an external IP address (exactly as I am using for the GlobalProtect VPN which is working fine).&lt;BR /&gt;Do I have to create any NAT rules for the IPsec tunnel to work? I do not have any NAT rules for Global Protect.&lt;/P&gt;&lt;P&gt;Thank you for any suggestions.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 12:20:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237272#M67977</guid>
      <dc:creator>Filip_Fronczak</dc:creator>
      <dc:date>2018-10-26T12:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec P2P VPN Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237289#M67980</link>
      <description>&lt;P&gt;Do you see allowed IKE packets comming to this IP? What do the logs of the other device say? Do you have any VPN related logs on your device for this connection?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 13:25:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237289#M67980</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-10-26T13:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec P2P VPN Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237290#M67981</link>
      <description>&lt;P&gt;The connectio has been created from the scratch on the partner (initiator) side and it started to work.&lt;/P&gt;&lt;P&gt;Seems that everything was OK on our side.&lt;/P&gt;&lt;P&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 14:18:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237290#M67981</guid>
      <dc:creator>Filip_Fronczak</dc:creator>
      <dc:date>2018-10-26T14:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec P2P VPN Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237462#M68029</link>
      <description>&lt;P&gt;Well... tonight I had to restart the PA and after I saw that the IPsec is all red.&lt;/P&gt;&lt;P&gt;I went to CLI and:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; show vpn ike-sa gateway xxx_IKE_GW&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#800000"&gt;IKE SA for gateway ID 1 not found.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; test vpn ike-sa gateway xxx_IKE_GW&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#008000"&gt;Start time: Oct.28 01:47:20&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#008000"&gt;Initiate 1 IKE SA.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; show vpn ike-sa gateway xxx_IKE_GW&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;IKEv1 phase-1 SAs&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;GwID/client IP Peer-Address Gateway Name Role Mode Algorithm Established Expiration V ST Xt Phase2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;-------------- ------------ ------------ ---- ---- --------- ----------- ---------- - -- -- ------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1 nn.nn.254.2 xxx_IKE_GW Init Main PSK/ DH2/3DES/SHA1 Oct.28 01:47:20 Oct.28 08:47:20 v1 13 1 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Show IKEv1 IKE SA: Total 1 gateways found. 1 ike sa found.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;IKEv1 phase-2 SAs&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Gateway Name TnID Tunnel GwID/IP Role Algorithm SPI(in) SPI(out) MsgID ST Xt&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;------------ ---- ------ ------- ---- --------- ------- -------- ----- -- --&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;xxx_IKE_GW 3 xxx:xxx 1 Resp ESP/ DH2/tunl/SHA1 F4010E4C 60330C71 1C5EA19E 9 1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Show IKEv1 phase2 SA: Total 1 gateways found. 1 ike sa found.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;There is no IKEv2 SA found.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that invoking the &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;test vpn ike-sa gateway xxx_IKE_GW&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;command initiated the IKE SA.&lt;/P&gt;&lt;P&gt;Why didn't it work automatically? Do I always have to do this after reboot? I guess it should wor by itself, shouldn't it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;See my other thread about the GlobalProtect GW:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/GlobalProtect-stopped-to-work-after-appliance-reboot/m-p/237468/thread-id/68035/highlight/false#M68039" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/GlobalProtect-stopped-to-work-after-appliance-reboot/m-p/237468/thread-id/68035/highlight/false#M68039&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 14:30:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237462#M68029</guid>
      <dc:creator>Filip_Fronczak</dc:creator>
      <dc:date>2018-10-28T14:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec P2P VPN Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237466#M68033</link>
      <description>&lt;P&gt;Unless you have vpn monitoring configured vpn tunnel is initiated only if devices try to send traffic to other side (if there is interesting traffic).&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 00:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237466#M68033</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-28T00:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec P2P VPN Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237482#M68036</link>
      <description>&lt;P&gt;So when there is no interesting traffic on GUI of IPsec tunnel we will see both reds?&lt;/P&gt;&lt;P&gt;mean both ike and ipsec will be down with out interesting traffic?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 04:06:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237482#M68036</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-28T04:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec P2P VPN Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237499#M68040</link>
      <description>&lt;P&gt;Yes&lt;/P&gt;&lt;P&gt;If you want it to be green then configure tunnel monitoring.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 14:32:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237499#M68040</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-10-28T14:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec P2P VPN Tunnel not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237503#M68043</link>
      <description>&lt;P&gt;Thanks for reply back.&lt;/P&gt;&lt;P&gt;Will enable tunnel Monitor and give it a test.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 14:47:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-p2p-vpn-tunnel-not-working/m-p/237503#M68043</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-28T14:47:22Z</dc:date>
    </item>
  </channel>
</rss>

