<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ipsec proxy Tunnel issue with multiple tunnels in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-proxy-tunnel-issue-with-multiple-tunnels/m-p/246217#M70133</link>
    <description>&lt;P&gt;HI Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configure Ipsec between PA and Cisco ASA, IPSEC is up but not traffic is passing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During the troubleshooting I have found for the proxy ID's configure in palo alto for some of the proxy id's only encapulation packet paloalto is sending and there is no decapusulation packet increasing for the proxy tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in the same Ipsec tunnel other proxy ID's are working fine. My firewall is running 8.0.13 which is recommened by Palo alto.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Replay protection is already disabled, Phase 1 is having 24 hours and Phase 2 has 1 hour life time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not seeing issue in negotiation, The proxy tunnel which is having issue is in the init state in PA side when analysing through command show vpn ikesa gateway&amp;nbsp; gatewayname.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest what can be done further to check this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Venky&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jan 2019 05:59:26 GMT</pubDate>
    <dc:creator>Venkatesan_radhakrishnan</dc:creator>
    <dc:date>2019-01-16T05:59:26Z</dc:date>
    <item>
      <title>Ipsec proxy Tunnel issue with multiple tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-proxy-tunnel-issue-with-multiple-tunnels/m-p/246217#M70133</link>
      <description>&lt;P&gt;HI Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configure Ipsec between PA and Cisco ASA, IPSEC is up but not traffic is passing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During the troubleshooting I have found for the proxy ID's configure in palo alto for some of the proxy id's only encapulation packet paloalto is sending and there is no decapusulation packet increasing for the proxy tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in the same Ipsec tunnel other proxy ID's are working fine. My firewall is running 8.0.13 which is recommened by Palo alto.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Replay protection is already disabled, Phase 1 is having 24 hours and Phase 2 has 1 hour life time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not seeing issue in negotiation, The proxy tunnel which is having issue is in the init state in PA side when analysing through command show vpn ikesa gateway&amp;nbsp; gatewayname.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest what can be done further to check this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Venky&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 05:59:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-proxy-tunnel-issue-with-multiple-tunnels/m-p/246217#M70133</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-01-16T05:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec proxy Tunnel issue with multiple tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-proxy-tunnel-issue-with-multiple-tunnels/m-p/246920#M70292</link>
      <description>&lt;P&gt;HI Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do anyone able to get my issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 07:19:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-proxy-tunnel-issue-with-multiple-tunnels/m-p/246920#M70292</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-01-22T07:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec proxy Tunnel issue with multiple tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-proxy-tunnel-issue-with-multiple-tunnels/m-p/246934#M70293</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97701"&gt;@Venkatesan_radhakrishnan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you can see statistics for encrypted packets, this means that the IPsec SA for the problematic proxy ids are successfully negotiated and Palo Alto firewall is actually sending traffic through the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I would say that your problem is most probably on the other and of the tunnel - on the ASA. IPsec SA are up, which means the VPN settings are correct, BUT: Can you confirm that the traffic from the tunnel is allowed on the ASA? Can you confirm the rest of the path has a correct route back to the ASA? Is there any NAT applied on the tunnel traffic on the ASA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having the fact that you have some proxy ids up and running eliminates any issues with phase1 setting and peer reachability&lt;BR /&gt;Having the fact that the problematic proxy ids are also up, but you see only uni-directional traffic eliminates any issues with phase2 encryption domains/selectors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 09:32:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-proxy-tunnel-issue-with-multiple-tunnels/m-p/246934#M70293</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-01-22T09:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Ipsec proxy Tunnel issue with multiple tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-proxy-tunnel-issue-with-multiple-tunnels/m-p/246935#M70294</link>
      <description>&lt;P&gt;HI Alex,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply, I will look on the ASA side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can understand this point Can you confirm the rest of the path has a correct route back to the ASA&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I will check the remaning asap.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 09:39:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-proxy-tunnel-issue-with-multiple-tunnels/m-p/246935#M70294</guid>
      <dc:creator>Venkatesan_radhakrishnan</dc:creator>
      <dc:date>2019-01-22T09:39:29Z</dc:date>
    </item>
  </channel>
</rss>

