<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why PA is Responder  for Phase 1 and Initiator for Phase 2 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260522#M73852</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems Phase 2 is down and system log shows below logs again and again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and ( description contains 'IKE phase-2 negotiation is failed as initiator, quick mode. Failed SA: 198.160.x.x[500]-173.182.x.x[500] message id:0xF55F380F. Due to negotiation timeout.' )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i do not have to device 173.182.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i run below command&amp;nbsp; i s&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show vpn ike-sa&lt;/P&gt;&lt;P&gt;IKEv1 phase-1 SAs&lt;BR /&gt;GwID/client IP Peer-Address Gateway Name Role Mode Algorithm Established Expiration V ST Xt Phase2&lt;/P&gt;&lt;P&gt;14 173.182.x.x CoC_13 Resp Main PSK/DH14/A256/SHA1 May.10 10:29:52 May.10 11:29:52 v1 13 2 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Show IKEv1 IKE SA: Total 6 gateways found. 5 ike sa found.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;IKEv1 phase-2 SAs&lt;BR /&gt;Gateway Name TnID Tunnel GwID/IP Role Algorithm SPI(in) SPI(out) MsgID ST Xt&lt;BR /&gt;------------ ---- ------ ------- ---- --------- ------- -------- ----- -- --&lt;/P&gt;&lt;P&gt;CoC_13 105 CoC-YYC_13:YYC_13 14 Init / / / 00000000 00000000 7A838C53 5 4&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Show IKEv1 phase2 SA: Total 6 gateways found. 9 ike sa found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Show IKEv2 SA: Total 2 gateways found. 2 ike sa found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why my PA is responder for Phase 1 and Initator for Phase 2?&lt;/P&gt;</description>
    <pubDate>Fri, 10 May 2019 16:37:52 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-05-10T16:37:52Z</dc:date>
    <item>
      <title>Why PA is Responder  for Phase 1 and Initiator for Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260522#M73852</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems Phase 2 is down and system log shows below logs again and again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and ( description contains 'IKE phase-2 negotiation is failed as initiator, quick mode. Failed SA: 198.160.x.x[500]-173.182.x.x[500] message id:0xF55F380F. Due to negotiation timeout.' )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i do not have to device 173.182.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i run below command&amp;nbsp; i s&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show vpn ike-sa&lt;/P&gt;&lt;P&gt;IKEv1 phase-1 SAs&lt;BR /&gt;GwID/client IP Peer-Address Gateway Name Role Mode Algorithm Established Expiration V ST Xt Phase2&lt;/P&gt;&lt;P&gt;14 173.182.x.x CoC_13 Resp Main PSK/DH14/A256/SHA1 May.10 10:29:52 May.10 11:29:52 v1 13 2 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Show IKEv1 IKE SA: Total 6 gateways found. 5 ike sa found.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;IKEv1 phase-2 SAs&lt;BR /&gt;Gateway Name TnID Tunnel GwID/IP Role Algorithm SPI(in) SPI(out) MsgID ST Xt&lt;BR /&gt;------------ ---- ------ ------- ---- --------- ------- -------- ----- -- --&lt;/P&gt;&lt;P&gt;CoC_13 105 CoC-YYC_13:YYC_13 14 Init / / / 00000000 00000000 7A838C53 5 4&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Show IKEv1 phase2 SA: Total 6 gateways found. 9 ike sa found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Show IKEv2 SA: Total 2 gateways found. 2 ike sa found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why my PA is responder for Phase 1 and Initator for Phase 2?&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 16:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260522#M73852</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-10T16:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why PA is Responder  for Phase 1 and Initiator for Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260632#M73879</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;why my PA is responder for Phase 1 and Initator for Phase 2?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Why not? &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How many proxy IDs do you have configured on that tunnel?&lt;/LI&gt;&lt;LI&gt;What timeouts do you have configured for phase 1 and 2?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example if you have only 1 phase 2 tunnel and a timeout of 8 hours in phase 1 and 1 hour for phase 2. At 2 am the other side establishes a connection so phase 1 and 2 will be setup. At that time your PA is responder for phase 1 and 2. After exchanging some packets there is no longer a connection so phase 2 will time out. For example at 4 am your side wants to connect to the remote network. As phase 2 already timed out a new one needs to be created but phase 1 is still up. --&amp;gt; your PA is responder in phase 1 and initiator of phase 2&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 11:43:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260632#M73879</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-05-12T11:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why PA is Responder  for Phase 1 and Initiator for Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260636#M73883</link>
      <description>&lt;P&gt;We have 1 Proxy ID.&lt;/P&gt;&lt;P&gt;Also Phase 1 and 2 Timers are set to 3600 sec.&lt;/P&gt;&lt;P&gt;Both Timers are same&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 16:09:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260636#M73883</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-12T16:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why PA is Responder  for Phase 1 and Initiator for Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260639#M73885</link>
      <description>&lt;P&gt;What I wrot is also possible in this case as the keys are renewed prior to expiration. So depending on the actual traffic in the tunnel you might end up with different roles for phase 1 and 2.&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 18:54:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260639#M73885</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-05-12T18:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why PA is Responder  for Phase 1 and Initiator for Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260787#M73925</link>
      <description>&lt;P&gt;Many Thanks Again&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 16:38:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/why-pa-is-responder-for-phase-1-and-initiator-for-phase-2/m-p/260787#M73925</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-05-13T16:38:30Z</dc:date>
    </item>
  </channel>
</rss>

