<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What ports are needed for site to site IPsec tunnels to work? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253778#M72053</link>
    <description>&lt;P&gt;IPSec - UDP 500&lt;/P&gt;&lt;P&gt;IPSec over NAT - UDP 4500&lt;/P&gt;&lt;P&gt;GlobalProtect - TCP 443 and UDP 4501&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2019 18:48:01 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2019-03-14T18:48:01Z</dc:date>
    <item>
      <title>What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253770#M72051</link>
      <description>&lt;P&gt;We have 2 palo alot firewalls &amp;amp; we are trying to establish a ipsec tunnel between both.&amp;nbsp; We proved that all vpn configurations are correct and were able to establish the tunnel &amp;amp; pass traffic but only if we add a firewall rule saying allow any/any/any/any at the very top of the rule base, which goes against our security requirements.&amp;nbsp; &amp;nbsp;Once we deleted the firewall rule the tunnels stopped working.&amp;nbsp; Simply put, we need to open firewall rules for site to site tunnels to work in our environment.&amp;nbsp; Does anyone know the Palo Alto TCP/UDP ports to open in order for phase 1 &amp;amp; 2 to go green?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 18:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253770#M72051</guid>
      <dc:creator>MarioMarquez</dc:creator>
      <dc:date>2019-03-14T18:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253778#M72053</link>
      <description>&lt;P&gt;IPSec - UDP 500&lt;/P&gt;&lt;P&gt;IPSec over NAT - UDP 4500&lt;/P&gt;&lt;P&gt;GlobalProtect - TCP 443 and UDP 4501&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 18:48:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253778#M72053</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-03-14T18:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253780#M72054</link>
      <description>&lt;P&gt;Thanks!&amp;nbsp; Which zones do these ports need to be opened on?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 18:51:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253780#M72054</guid>
      <dc:creator>MarioMarquez</dc:creator>
      <dc:date>2019-03-14T18:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253813#M72058</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The one from the internet, ie untrust.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 21:01:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253813#M72058</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-03-14T21:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253854#M72068</link>
      <description>&lt;P&gt;Usually vpn is terminated on UNTRUST interface.&lt;/P&gt;&lt;P&gt;Unless you have added "block any" rule to the end this traffic is permitted already by "interzone-default" policy.&lt;/P&gt;&lt;P&gt;If you terminate vpn on on some other interface (TRUST, LOOPBACK etc) and have NAT in place then you need to adjust your security policy accordingly.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 03:40:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253854#M72068</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-03-15T03:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253875#M72073</link>
      <description>Can you help me understand what your saying about the default security policy? It doesn't make sense to me. How can something be permitted already because of the inter-zone default policy when the default policy is to deny all inter-zone traffic? It seems like nothing is allowed out if the box accept intra-zone traffic and the rule-1 allow any to untrust.</description>
      <pubDate>Fri, 15 Mar 2019 08:15:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253875#M72073</guid>
      <dc:creator>MarioMarquez</dc:creator>
      <dc:date>2019-03-15T08:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253923#M72087</link>
      <description>&lt;P&gt;Hi I think I had typo in my answer about interzone. If traffic stays in same zone it is intrazone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically rules are evaluated top to down.&lt;/P&gt;&lt;P&gt;First one that matches will take effect. Either allows or blocks and based on security profile will check for viruses or not (only allow rules).&lt;/P&gt;&lt;P&gt;If no rule matches then one of last 2 will match.&lt;/P&gt;&lt;P&gt;intrazone-default will match if traffic source and destination is in same zone. For example if traffic from vpn peer will come from internet and you have configured IPSec gateway on WAN interface then this rule will match.&lt;/P&gt;&lt;P&gt;If traffic (based on NAT and virtual router) is destined to some other zone then "interzone-default" will match.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Those default rules will not log by default so you don't see any traffic that matches those rules.&lt;/P&gt;&lt;P&gt;To gain this visibility you have to click on the rule and choose "override".&lt;/P&gt;&lt;P&gt;Click on the rule name.&lt;/P&gt;&lt;P&gt;On "Actions" tab check "Log at session end".&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 13:31:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/253923#M72087</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-03-15T13:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/254810#M72316</link>
      <description>&lt;P&gt;Hi! I suggest install and setting VeePN and servers.&lt;BR /&gt;This vpn differs from other vpn providers:&lt;BR /&gt;1) Besides vpn you are provided with fully working vps&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;a) Personalized configurations for your vpn &amp;nbsp;&lt;BR /&gt;b) Regulated logs&lt;BR /&gt;c) Generating your own services, such as http&lt;BR /&gt;d) There is no 3rd silent persons, after setting up you are going to be the only owner&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 08:05:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/254810#M72316</guid>
      <dc:creator>BorisJones</dc:creator>
      <dc:date>2019-03-24T08:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/326856#M83231</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I am currently encountering an issue, UDP 500 and 4500 are not enough to get site to site vpn tunnel up and running. Is that esp also required to be allowed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;THanks&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Elroy&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2020 00:55:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/326856#M83231</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-05-08T00:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/326996#M83247</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I went beyond ports and use the L7 Applications. Including the screen shot below. I also allow ping as some devices send ping to monitor tunnel status.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OtakarKlier_0-1588945648361.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25506i9729B3A17314DFB4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OtakarKlier_0-1588945648361.png" alt="OtakarKlier_0-1588945648361.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2020 13:47:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/326996#M83247</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-05-08T13:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327277#M83293</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Thanks for your reply. Does that mean UDP 500 and 4500 are not enough and esp is also required? THanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Elroy&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 00:35:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327277#M83293</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-05-11T00:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327284#M83294</link>
      <description>&lt;P&gt;ideally if you have allowed ports , then it should work . for better security/clarity , instead of using service ports , you can use ipsec related applications as mentioned in earlier post .&lt;/P&gt;&lt;P&gt;Now , if it is still not working , then i would suggest you to check logs and see what exactly is getting denied and then allow it by ports OR application.&lt;/P&gt;&lt;P&gt;NOTE :- allow logging in default policies to see deny logs if it is hitting those policies&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it gives you a direction&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 05:10:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327284#M83294</guid>
      <dc:creator>KunalChopra</dc:creator>
      <dc:date>2020-05-11T05:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327285#M83295</link>
      <description>&lt;P&gt;Thank you so much for your response. In my scenario, I am considering if it is blocking by the intermediate network devices which is mainly port-based. So I have limited visibility on those devices. But thanks again and it gives some insights as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Elroy&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 05:14:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327285#M83295</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-05-11T05:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327287#M83296</link>
      <description>&lt;P&gt;you should not see any logs in your&amp;nbsp; firewall if some&amp;nbsp; intermediate device is blocking it and that way it can be confirmed.&lt;/P&gt;&lt;P&gt;Or if you want to dig in further , just apply packet capture with both ends public ip in filter.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 05:18:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327287#M83296</guid>
      <dc:creator>KunalChopra</dc:creator>
      <dc:date>2020-05-11T05:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: What ports are needed for site to site IPsec tunnels to work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327290#M83299</link>
      <description>&lt;P&gt;I have performed a packet capture and see that traffic is encap and no decap is sending back and most likely is using esp. My question is that ipsec should be using udp 500 and 4500 from documents. if I should enable esp as well&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Elroy&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 05:58:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-ports-are-needed-for-site-to-site-ipsec-tunnels-to-work/m-p/327290#M83299</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-05-11T05:58:48Z</dc:date>
    </item>
  </channel>
</rss>

