<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKE gateway is not allowed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/256380#M72738</link>
    <description>&lt;P&gt;Whatever firewall is the dynamic peer&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;needs&lt;/EM&gt;&lt;/STRONG&gt; to be the initiator of the VPN tunnel and not the responder. Ensure that you don't have the "Enable Passive Mode" option checked.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Apr 2019 20:07:06 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-04-05T20:07:06Z</dc:date>
    <item>
      <title>IKE gateway is not allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/256167#M72677</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;BR /&gt;I've just installed a PA 3220 and there're dynamics VPNs tunnel. IKEs are up. However,&amp;nbsp; phase 2 (tunnel) aren't coming up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the logs I see the following logs for all VPNs .&lt;BR /&gt;"initiate negotiation to dynamic peer from IKE gateway is not allowed"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;My outside interface is allowing IKE and IPSec, I don't see packets being dropped.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 20:10:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/256167#M72677</guid>
      <dc:creator>WRibeiro</dc:creator>
      <dc:date>2019-04-04T20:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: IKE gateway is not allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/256193#M72682</link>
      <description>&lt;P&gt;Do you have any other logs?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 21:10:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/256193#M72682</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-04-04T21:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: IKE gateway is not allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/256281#M72705</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's what I can see on the logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IKE Down.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19422iCB06487B5B00705F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="IKE Down.JPG" alt="IKE Down.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 10:35:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/256281#M72705</guid>
      <dc:creator>WRibeiro</dc:creator>
      <dc:date>2019-04-05T10:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: IKE gateway is not allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/256380#M72738</link>
      <description>&lt;P&gt;Whatever firewall is the dynamic peer&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;needs&lt;/EM&gt;&lt;/STRONG&gt; to be the initiator of the VPN tunnel and not the responder. Ensure that you don't have the "Enable Passive Mode" option checked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 20:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/256380#M72738</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-05T20:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: IKE gateway is not allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/306646#M79653</link>
      <description>&lt;P&gt;The Enable Passive Mode option should be checked on the non-dynamic addressed firewall &lt;STRONG&gt;and not&lt;/STRONG&gt; on the dynamic remote firewalls?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;With&amp;nbsp;this option enabled, the firewall responds to incoming connection negotiations as it would normally do, &lt;STRONG&gt;but it will no longer initiate outgoing negotiations.&lt;/STRONG&gt; "&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 14:00:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/306646#M79653</guid>
      <dc:creator>jeremy.larsen</dc:creator>
      <dc:date>2020-01-14T14:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: IKE gateway is not allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/306653#M79654</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107910"&gt;@jeremy.larsen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Correct. On the non-dynamic firewall you want passive-mode enabled, and on the dynamic firewall you want to ensure that passive mode is not enabled. That will ensure that only the dynamic firewall is attempting to establish communication with the non-dynamic firewall, which works perfectly fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 14:06:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-gateway-is-not-allowed/m-p/306653#M79654</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-01-14T14:06:09Z</dc:date>
    </item>
  </channel>
</rss>

