<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: phase 1 up phase 2 down in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/phase-1-up-phase-2-down/m-p/255458#M72482</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Under the IKE Gateway for the tunnel verify that the Local Identification and the Peer Identification are actually matching (in reverse order) for the selected tunnel.&lt;/P&gt;&lt;P&gt;The following is an example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA-1:&lt;/P&gt;&lt;P&gt;Local Identification:&amp;nbsp; &amp;nbsp; IP address&amp;nbsp; &amp;nbsp; 10.10.139.230&lt;/P&gt;&lt;P&gt;Peer Identification&amp;nbsp; &amp;nbsp; FQDN (hostname)&amp;nbsp; &amp;nbsp; TEST01&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA-2:&lt;/P&gt;&lt;P&gt;Local Identification:&amp;nbsp; &amp;nbsp; FQDN (hostname)&amp;nbsp; &amp;nbsp; TEST01&lt;/P&gt;&lt;P&gt;Peer Identification:&amp;nbsp; &amp;nbsp; IP address&amp;nbsp; &amp;nbsp;10.10.139.230&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What the log is saying is that essentially the peer device is sending the id of 10.175.150.0 as it's Local Identification, and that ID doesn't match any of your IKE Gateway's configured Peer Identification. Meaning that the firewall doesn't have an IKE Gateway configured for the device.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Mar 2019 18:23:45 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-03-29T18:23:45Z</dc:date>
    <item>
      <title>phase 1 up phase 2 down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/phase-1-up-phase-2-down/m-p/255443#M72480</link>
      <description>&lt;P&gt;( description contains 'IKE phase-1 negotiation is failed. Peer\'s ID payload 10.175.150.0 (type ipaddr) does not match a configured IKE gateway.' )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and ( description contains 'IKE phase-1 negotiation is failed as responder, main mode. Failed SA: 198.160.191.5[500]-173.182.112.167[500] cookie:5357205146f1b40c:a194d23cbec27a50. Due to timeout.' )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get above in system logs phase 1 is up but phase 2 not&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 16:06:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/phase-1-up-phase-2-down/m-p/255443#M72480</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-29T16:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: phase 1 up phase 2 down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/phase-1-up-phase-2-down/m-p/255458#M72482</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Under the IKE Gateway for the tunnel verify that the Local Identification and the Peer Identification are actually matching (in reverse order) for the selected tunnel.&lt;/P&gt;&lt;P&gt;The following is an example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA-1:&lt;/P&gt;&lt;P&gt;Local Identification:&amp;nbsp; &amp;nbsp; IP address&amp;nbsp; &amp;nbsp; 10.10.139.230&lt;/P&gt;&lt;P&gt;Peer Identification&amp;nbsp; &amp;nbsp; FQDN (hostname)&amp;nbsp; &amp;nbsp; TEST01&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA-2:&lt;/P&gt;&lt;P&gt;Local Identification:&amp;nbsp; &amp;nbsp; FQDN (hostname)&amp;nbsp; &amp;nbsp; TEST01&lt;/P&gt;&lt;P&gt;Peer Identification:&amp;nbsp; &amp;nbsp; IP address&amp;nbsp; &amp;nbsp;10.10.139.230&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What the log is saying is that essentially the peer device is sending the id of 10.175.150.0 as it's Local Identification, and that ID doesn't match any of your IKE Gateway's configured Peer Identification. Meaning that the firewall doesn't have an IKE Gateway configured for the device.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 18:23:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/phase-1-up-phase-2-down/m-p/255458#M72482</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-29T18:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: phase 1 up phase 2 down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/phase-1-up-phase-2-down/m-p/255486#M72486</link>
      <description>&lt;P&gt;Got it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 18:57:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/phase-1-up-phase-2-down/m-p/255486#M72486</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-03-29T18:57:43Z</dc:date>
    </item>
  </channel>
</rss>

