<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec S2S VPN between Palo Alto and 3rd party Security FW Vendor -&amp;gt; ISAKMP Negotiation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-palo-alto-and-3rd-party-security-fw-vendor/m-p/241294#M69113</link>
    <description>&lt;P&gt;It's been my experience that as long as the tunnel peers can communicate the "tunnel Info" icon will come up, but if no "interesting traffic" is going down the tunnel then the icon for the "IKE Info" will show down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's an example from one of my FWs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tunnels.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17694i9828ADA6A10F9925/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Tunnels.PNG" alt="Tunnels.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Nov 2018 13:51:34 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2018-11-27T13:51:34Z</dc:date>
    <item>
      <title>IPSec S2S VPN between Palo Alto and 3rd party Security FW Vendor -&gt; ISAKMP Negotiation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-palo-alto-and-3rd-party-security-fw-vendor/m-p/241280#M69111</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to setup a Site to Site VPN between a Palo Alto FW and a 3rd Party Security FW Vendor;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to undestand under which condition the Palo Alto FW would attempt to start an ISAKMP negotiation (for Phase 1) with the IPSec peer counterpart.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm familiar with the Cisco ASA setup - where, for ex., the tunnel is brought up only when interesting traffic is actually attempting to flow through the Unit -&amp;gt; how is the behavior in the case of the PA ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the unit attempt to start the IPSEC tunnel automatically as soon as the config is pushed / committed (also without any interesting traffic hitting the unit) ?&lt;/P&gt;&lt;P&gt;Is this is the case, assuming that the tunnel could not be successfully established on the 1st attempt, does the PA attempt periodically to perform the ISAKMP negotiation ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't labbed this scenario yet (planning on doing) - nevertheless any heads up would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 12:43:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-palo-alto-and-3rd-party-security-fw-vendor/m-p/241280#M69111</guid>
      <dc:creator>CarloInt</dc:creator>
      <dc:date>2018-11-27T12:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec S2S VPN between Palo Alto and 3rd party Security FW Vendor -&gt; ISAKMP Negotiation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-palo-alto-and-3rd-party-security-fw-vendor/m-p/241294#M69113</link>
      <description>&lt;P&gt;It's been my experience that as long as the tunnel peers can communicate the "tunnel Info" icon will come up, but if no "interesting traffic" is going down the tunnel then the icon for the "IKE Info" will show down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's an example from one of my FWs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Tunnels.PNG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17694i9828ADA6A10F9925/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Tunnels.PNG" alt="Tunnels.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 13:51:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-s2s-vpn-between-palo-alto-and-3rd-party-security-fw-vendor/m-p/241294#M69113</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-11-27T13:51:34Z</dc:date>
    </item>
  </channel>
</rss>

