<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSEC GUI shows green for both phase 1 and 2 - Need to restart the ipsec to ping across the ipsec in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-gui-shows-green-for-both-phase-1-and-2-need-to-restart-the/m-p/259421#M73566</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gui shows both phase 1 and 2 up.&lt;/P&gt;&lt;P&gt;Can not ping lan IP at vendor end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i ping vendor lan ip&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i see below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;( description contains 'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 0.0.0.0/0 type IPv4_subnet protocol 0 port 0, received remote id: 192.168.46.32/28 type IPv4_subnet protocol 0 port 0.' )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to restart the phase 2 from gui to make it work&lt;/P&gt;&lt;P&gt;Need to know why every time i need to retstart the phase 2 to make this work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA has this proxy is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Local 10.0.0.0/8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remote 192.168.46.32/28&lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2019 15:55:24 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-05-01T15:55:24Z</dc:date>
    <item>
      <title>IPSEC GUI shows green for both phase 1 and 2 - Need to restart the ipsec to ping across the ipsec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-gui-shows-green-for-both-phase-1-and-2-need-to-restart-the/m-p/259421#M73566</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gui shows both phase 1 and 2 up.&lt;/P&gt;&lt;P&gt;Can not ping lan IP at vendor end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i ping vendor lan ip&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i see below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;( description contains 'IKE phase-2 negotiation failed when processing proxy ID. cannot find matching phase-2 tunnel for received proxy ID. received local id: 0.0.0.0/0 type IPv4_subnet protocol 0 port 0, received remote id: 192.168.46.32/28 type IPv4_subnet protocol 0 port 0.' )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to restart the phase 2 from gui to make it work&lt;/P&gt;&lt;P&gt;Need to know why every time i need to retstart the phase 2 to make this work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA has this proxy is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Local 10.0.0.0/8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remote 192.168.46.32/28&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 15:55:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-gui-shows-green-for-both-phase-1-and-2-need-to-restart-the/m-p/259421#M73566</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-01T15:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC GUI shows green for both phase 1 and 2 - Need to restart the ipsec to ping across the ipse</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-gui-shows-green-for-both-phase-1-and-2-need-to-restart-the/m-p/259436#M73569</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like the other end has configured the wrong proxy ID for your subnet. Instead of 10.0.0.0/8 they configured 0.0.0.0/0 or nothing is also possible and because of that they accept when you start the phase 2 tunnel but your firewall does not accept what the offer in the phase 2 negotiation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 18:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-gui-shows-green-for-both-phase-1-and-2-need-to-restart-the/m-p/259436#M73569</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-05-01T18:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC GUI shows green for both phase 1 and 2 - Need to restart the ipsec to ping across the ipse</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-gui-shows-green-for-both-phase-1-and-2-need-to-restart-the/m-p/259558#M73580</link>
      <description>&lt;P&gt;You are spot on&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 01:49:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-gui-shows-green-for-both-phase-1-and-2-need-to-restart-the/m-p/259558#M73580</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-02T01:49:08Z</dc:date>
    </item>
  </channel>
</rss>

