<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic troubleshooting ipsec with dynamic side in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ipsec-with-dynamic-side/m-p/262499#M74377</link>
    <description>&lt;P&gt;Hello, everyone,&lt;/P&gt;&lt;P&gt;Currently I have the problem to build an IPSec tunnel between a PA200 (A) and a PA220 (B).&lt;BR /&gt;My one side A has a Telekom hybrid Internet connection (its a german product with LTE and cable connection) to a Speedport router. Thus only one dynamic official IP.&lt;BR /&gt;The other side B is a normal company connection with a fixed IP address. I have configured my tunnel so that only side A is allowed to start the tunnel. (B side enable passive mode)&lt;/P&gt;&lt;P&gt;If I now start the tunnel on page A, I also see in the monitoring at page B the requests ike on port 500 for port 500. Unfortunately then nothing happens further and page A has then a Faild Due to timeout.&lt;BR /&gt;You can also see that page A transmits data but does not receive any data.&lt;BR /&gt;What could that be? What is the best way to narrow down the problem?&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2019 09:24:25 GMT</pubDate>
    <dc:creator>clonesheep</dc:creator>
    <dc:date>2019-05-29T09:24:25Z</dc:date>
    <item>
      <title>troubleshooting ipsec with dynamic side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ipsec-with-dynamic-side/m-p/262499#M74377</link>
      <description>&lt;P&gt;Hello, everyone,&lt;/P&gt;&lt;P&gt;Currently I have the problem to build an IPSec tunnel between a PA200 (A) and a PA220 (B).&lt;BR /&gt;My one side A has a Telekom hybrid Internet connection (its a german product with LTE and cable connection) to a Speedport router. Thus only one dynamic official IP.&lt;BR /&gt;The other side B is a normal company connection with a fixed IP address. I have configured my tunnel so that only side A is allowed to start the tunnel. (B side enable passive mode)&lt;/P&gt;&lt;P&gt;If I now start the tunnel on page A, I also see in the monitoring at page B the requests ike on port 500 for port 500. Unfortunately then nothing happens further and page A has then a Faild Due to timeout.&lt;BR /&gt;You can also see that page A transmits data but does not receive any data.&lt;BR /&gt;What could that be? What is the best way to narrow down the problem?&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 09:24:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ipsec-with-dynamic-side/m-p/262499#M74377</guid>
      <dc:creator>clonesheep</dc:creator>
      <dc:date>2019-05-29T09:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting ipsec with dynamic side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ipsec-with-dynamic-side/m-p/262513#M74379</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you configured Proxy-IDs, as if the PA wants to establish an IPSec tunnel with Non-PA device, we need to configure it because of Route based approach.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 11:13:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ipsec-with-dynamic-side/m-p/262513#M74379</guid>
      <dc:creator>Saurabh0145</dc:creator>
      <dc:date>2019-05-29T11:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting ipsec with dynamic side</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ipsec-with-dynamic-side/m-p/264214#M74409</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have sites with multiple VPN's and I think I understand what you are trying to accomplish. You want all traffic to go down TunnelA as primary with TunnelB as secondary? If yes, setup the tunnels the same with settings on both. Both tunnels will be up at the same time, this is OK. Then control traffic with routing, either static routes with monitors and weights or OSPF with Metrics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 14:19:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/troubleshooting-ipsec-with-dynamic-side/m-p/264214#M74409</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-31T14:19:23Z</dc:date>
    </item>
  </channel>
</rss>

