<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ipsec VPN to Cisco ASA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-to-cisco-asa/m-p/9505#M6981</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for both answers.&lt;/P&gt;&lt;P&gt;After reading the guide und checking the logs the vpn tunnel is up and running now.&lt;/P&gt;&lt;P&gt;The asa admin disabled the isakmp keepalive settings at his box and i configured a proxy id in the ipsec tunnel cause the asa uses policy-based vpns instead of rotue based vpn's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Christian &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 May 2012 14:11:48 GMT</pubDate>
    <dc:creator>cfpa</dc:creator>
    <dc:date>2012-05-24T14:11:48Z</dc:date>
    <item>
      <title>Ipsec VPN to Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-to-cisco-asa/m-p/9502#M6978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;right now we are trying to setuop a ipsec vpn between out palo alto 4.0.7 box and a cisco asa 8.2 box ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cause we are running into troubles whithin the ike setup, i would like to know the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. How can i debug the vpn setup in the pa ? I'm used to ASA's but this is my first vpn setup on a PA. I want to check why the tunnel does not come up (i did the setup regarding to the documentation)&lt;/P&gt;&lt;P&gt;2. I found the follwing as fixed in the release note of 4.1.6:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;39844 – IPSec VPN tunnel not coming up when Palo Alto Networks firewall initiates a connection to a Cisco ASA device.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Is it possible that im hitting that bug ? In which software version was this bug introduced ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Many thanks,&lt;BR /&gt;Christian&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 14:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-to-cisco-asa/m-p/9502#M6978</guid>
      <dc:creator>cfpa</dc:creator>
      <dc:date>2012-05-23T14:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec VPN to Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-to-cisco-asa/m-p/9503#M6979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should see log entries including attempts to make connections in Monitor--&amp;gt;Logs--&amp;gt;System&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To test a IPSec tunnel, from the command line on the PA,&lt;/P&gt;&lt;P&gt;clear vpn ike-sa gateway &amp;lt;name of IKE Gateway in Network--&amp;gt;Network Profiles--&amp;gt;IKE Gateways&amp;gt;&lt;/P&gt;&lt;P&gt;clear vpn ipsec-sa tunnel &amp;lt;name of IPSec tunnel in Network--&amp;gt;IPSec Tunnels&amp;gt;&lt;/P&gt;&lt;P&gt;test vpn ipsec-sa tunnel &amp;lt;name of IPSec tunnel in Network--&amp;gt;IPSec Tunnels&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've only encountered bug #39844 in PAN-OS version 4.1.5.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 16:09:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-to-cisco-asa/m-p/9503#M6979</guid>
      <dc:creator>bstapleton</dc:creator>
      <dc:date>2012-05-23T16:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec VPN to Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-to-cisco-asa/m-p/9504#M6980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This document&amp;nbsp; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1328"&gt;https://live.paloaltonetworks.com/docs/DOC-1328&lt;/A&gt; gives a sample configuration between PAN and Cisco ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also look at the ike manager logs to get more info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;less mp-log ikemgr.log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 16:25:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-to-cisco-asa/m-p/9504#M6980</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-05-23T16:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec VPN to Cisco ASA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-to-cisco-asa/m-p/9505#M6981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for both answers.&lt;/P&gt;&lt;P&gt;After reading the guide und checking the logs the vpn tunnel is up and running now.&lt;/P&gt;&lt;P&gt;The asa admin disabled the isakmp keepalive settings at his box and i configured a proxy id in the ipsec tunnel cause the asa uses policy-based vpns instead of rotue based vpn's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Christian &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 14:11:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-to-cisco-asa/m-p/9505#M6981</guid>
      <dc:creator>cfpa</dc:creator>
      <dc:date>2012-05-24T14:11:48Z</dc:date>
    </item>
  </channel>
</rss>

