<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPsec VPN with AH generates core files in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-ah-generates-core-files/m-p/260918#M73967</link>
    <description>&lt;P&gt;Hi team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two VM-50 v9.01, one in SiteA and another in SiteB. I set up an IPsec tunnel between them with: IKE-v1 : phase1 (aggressive mode)&amp;nbsp; and phase2 (quick mode) with ESP.&amp;nbsp; it works fine and I'am able to ping from a vlan in SiteA to another vlan in SiteB .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to test AH instead of ESP. However everytime I want to send a ping from SiteA to SiteB, the firewall in SiteB craches and generates a core file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I perform a "test vpn ike-sa gateway mygateway" and "test vpn ipsec-sa myipsec" it works fine and I can see the SA created in both firewall. However when I send a packet from SiteA to SiteB, I can see the packet leaving firewall in SiteA with the apropriate AH header inserted. But as soon as the packet arrives in the firewall in SiteB, it craches.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can provide pcaps and core files , or anything you may need to help me.&lt;/P&gt;&lt;P&gt;Does anybody try to do the same ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appriciated&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2019 15:14:27 GMT</pubDate>
    <dc:creator>Karim.Benyelloul</dc:creator>
    <dc:date>2019-05-14T15:14:27Z</dc:date>
    <item>
      <title>IPsec VPN with AH generates core files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-ah-generates-core-files/m-p/260918#M73967</link>
      <description>&lt;P&gt;Hi team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two VM-50 v9.01, one in SiteA and another in SiteB. I set up an IPsec tunnel between them with: IKE-v1 : phase1 (aggressive mode)&amp;nbsp; and phase2 (quick mode) with ESP.&amp;nbsp; it works fine and I'am able to ping from a vlan in SiteA to another vlan in SiteB .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to test AH instead of ESP. However everytime I want to send a ping from SiteA to SiteB, the firewall in SiteB craches and generates a core file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I perform a "test vpn ike-sa gateway mygateway" and "test vpn ipsec-sa myipsec" it works fine and I can see the SA created in both firewall. However when I send a packet from SiteA to SiteB, I can see the packet leaving firewall in SiteA with the apropriate AH header inserted. But as soon as the packet arrives in the firewall in SiteB, it craches.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can provide pcaps and core files , or anything you may need to help me.&lt;/P&gt;&lt;P&gt;Does anybody try to do the same ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appriciated&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 15:14:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-ah-generates-core-files/m-p/260918#M73967</guid>
      <dc:creator>Karim.Benyelloul</dc:creator>
      <dc:date>2019-05-14T15:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with AH generates core files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-ah-generates-core-files/m-p/260951#M73980</link>
      <description>&lt;P&gt;It would be odd to have two PA devices utilize AH. I would open a ticket with support and see if they can duplicate the issue; it sounds like it may be a bug with 9.0&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 16:50:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-ah-generates-core-files/m-p/260951#M73980</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-05-14T16:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with AH generates core files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-ah-generates-core-files/m-p/261614#M74166</link>
      <description>&lt;P&gt;Hmmm as I said in my description I am in a lab environment and I wanted to test different configuration to make sure that I'm doing things right, I don't think that the support would accept my issue as a "ticket" ... It would be nice if anyone could try to setup AH between two Paloaltos and keep me in touch if it works for him.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 08:34:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-with-ah-generates-core-files/m-p/261614#M74166</guid>
      <dc:creator>Karim.Benyelloul</dc:creator>
      <dc:date>2019-05-20T08:34:13Z</dc:date>
    </item>
  </channel>
</rss>

