<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Proxies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303275#M78956</link>
    <description>&lt;P&gt;Hi John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A few things (that you are already aware of...) but need to shed light on them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The state of the VPN on the PANW side is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;state: init&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Meaning that the PANW is attempting to xmit traffic to setup the tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This does not make sense if you stated that proxyID is working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You cannot have an "init" on a firewall with a working VPN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What am I missing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do&amp;nbsp; &amp;nbsp;you have time for an actual phone call..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can send me a PM and we can take a look at this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you have remote desktop (zoom, webex, etc) that would be great as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Let me know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2019 18:06:51 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-12-11T18:06:51Z</dc:date>
    <item>
      <title>VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/302908#M78895</link>
      <description>&lt;P&gt;I have a VPN tunnel which is up and running.&amp;nbsp; In the tunnel, I have 2 proxyID's which have the same local address but different remote addresses.&lt;/P&gt;&lt;P&gt;I can only get 1 proxyid to connect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As an example, I current have proxyID1 connected and I can ping the other side.&amp;nbsp; In the cli, if I type test vpn ipsec-sa tunnel tunnel-name-proxyID2.&amp;nbsp; It does not come up. I also tried doing test vpn ike-sa gateway gateway-name, It still does not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now if I delete, proxyID1, ProxyID2 connects.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It appears that in the proxyID list, only the first proxy gets connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 14:29:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/302908#M78895</guid>
      <dc:creator>johncabrera</dc:creator>
      <dc:date>2019-12-10T14:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303050#M78919</link>
      <description>&lt;P&gt;What do your system logs show when both proxy ids are configured.&lt;/P&gt;&lt;P&gt;Clearly, there is a mis-configuration on the FW, whether it is through logic or anomaly. We just need to see more info to help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because we do not have access to your network, and there are millions of RFC1918 private networks, can you please show us the proxy IDs that you have configured, so that we can better understand your query?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I am presuming you have a single VPN with 2 proxy ids, versus 2 separate tunnels with overlapping proxy ids, which is not permissible.&lt;/P&gt;&lt;P&gt;This is why we should see all VPN proxy IDs for each tunnel interface you have configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 21:57:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303050#M78919</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-12-10T21:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303191#M78939</link>
      <description>&lt;P&gt;Here is the ike logs&lt;BR /&gt;&lt;BR /&gt;2019-12-10 11:02:47.014 -0500 [DEBG]: { 6: }: received notify type INVALID_KE_PAYLOAD&lt;BR /&gt;2019-12-10 11:02:47.014 -0500 [DEBG]: { 6: }: ikev2_process_child_notify(0x7ff5f1bbaea0, 0x7ff5e25b7b60), notify type INVALID_KE_PAYLOAD&lt;BR /&gt;2019-12-10 11:02:47.014 -0500 [PWRN]: { 6: }: 17 is not a child notify type&lt;BR /&gt;2019-12-10 11:02:47.014 -0500 [DEBG]: { 6: 63}: construct TS_r 10.127.0.0 -&amp;gt; 10.127.255.255&lt;BR /&gt;2019-12-10 11:02:47.014 -0500 [DEBG]: { 6: 63}: construct TS_i 10.16.48.0 -&amp;gt; 10.16.55.255&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is 1 tunnel with 3 'sub-tunnels'&lt;/P&gt;&lt;P&gt;The other side has a Cisco ASA.&amp;nbsp; The users connect to 10.16.48.0/21, which is a Citrix Netscaler.&amp;nbsp; They click on one of their apps which takes them to the 10.65.204.0 network.&lt;/P&gt;&lt;P&gt;Below is the ProxyID.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 673px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22981i3F90F2AFC9622292/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I also have static routes for the tunnel traffic&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.JPG" style="width: 544px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22984iC2F03B131AD6B645/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture2.JPG" alt="Capture2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 13:19:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303191#M78939</guid>
      <dc:creator>johncabrera</dc:creator>
      <dc:date>2019-12-11T13:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303222#M78943</link>
      <description>&lt;P&gt;Are these 3 proxy ids identical on the Cisco side, or perhaps you super-netted them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not see any info (or rather, not enough info) in your snippet of logs to confirm that proxyID2 is not up and operational.&lt;/P&gt;&lt;P&gt;Do you have anything to show us errors/warning/messages surrounding this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly.. (and may this is the key)&lt;/P&gt;&lt;P&gt;You have 3 static routes, pointing to tunnel.8 (yes)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, we do not have the screen captures to confirm this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise and lets keep working on this.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 14:44:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303222#M78943</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-12-11T14:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303265#M78953</link>
      <description>&lt;P&gt;Yes, I have 3 static routes going to tunnel.8&lt;/P&gt;&lt;P&gt;On the Cisco side, it uses access-list. You create the tunnel and then you give the remote side (which is us) what access it has. I have access to the following networks.&lt;BR /&gt;extended permit ip 10.16.48.0 255.255.248.0 10.127.0.0 255.255.0.0&lt;BR /&gt;extended permit ip 10.65.204.0 255.255.254.0 10.127.0.0 255.255.0.0&lt;BR /&gt;extended permit ip 10.65.206.0 255.255.254.0 10.127.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;id: 67&lt;BR /&gt;type: IPSec&lt;BR /&gt;gateway id: 6&lt;BR /&gt;local ip: 40.135.184.5&lt;BR /&gt;peer ip: 166.109.10.2&lt;BR /&gt;inner interface: tunnel.8&lt;BR /&gt;outer interface: ethernet1/1&lt;BR /&gt;state: init&lt;BR /&gt;session: 197787&lt;BR /&gt;tunnel mtu: 1448&lt;BR /&gt;soft lifetime: N/A&lt;BR /&gt;hard lifetime: N/A&lt;BR /&gt;lifetime remain: N/A&lt;BR /&gt;lifesize remain: N/A&lt;BR /&gt;monitor: off&lt;BR /&gt;monitor packets seen: 0&lt;BR /&gt;monitor packets reply:0&lt;BR /&gt;en/decap context: 3855&lt;BR /&gt;local spi: 00000000&lt;BR /&gt;remote spi: 00000000&lt;BR /&gt;key type: auto key&lt;BR /&gt;protocol: ESP&lt;BR /&gt;auth algorithm: NOT ESTABLISHED&lt;BR /&gt;enc algorithm: NOT ESTABLISHED&lt;BR /&gt;proxy-id:&lt;BR /&gt;local ip: 10.127.0.0/16&lt;BR /&gt;remote ip: 10.16.48.0/21&lt;BR /&gt;protocol: 0&lt;BR /&gt;local port: 0&lt;BR /&gt;remote port: 0&lt;BR /&gt;anti replay check: yes&lt;BR /&gt;copy tos: no&lt;BR /&gt;enable gre encap: no&lt;BR /&gt;authentication errors: 0&lt;BR /&gt;decryption errors: 0&lt;BR /&gt;inner packet warnings: 0&lt;BR /&gt;replay packets: 0&lt;BR /&gt;packets received&lt;BR /&gt;when lifetime expired:0&lt;BR /&gt;when lifesize expired:0&lt;BR /&gt;sending sequence: 0&lt;BR /&gt;receive sequence: 0&lt;BR /&gt;encap packets: 0&lt;BR /&gt;decap packets: 0&lt;BR /&gt;encap bytes: 0&lt;BR /&gt;decap bytes: 0&lt;BR /&gt;key acquire requests: 59&lt;BR /&gt;owner state: 0&lt;BR /&gt;owner cpuid: s1dp0&lt;BR /&gt;ownership: 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I got on a call with tech support and this error message: INVALID_KE_PAYLOAD is due to a different DH-Group.&lt;/P&gt;&lt;P&gt;After the call, I verified with the other side and we both have the same group.&lt;/P&gt;&lt;P&gt;What I find interesting is that we have another tunnel and on the other side they also have a Cisco ASA. I have 5 proxyID's and they all work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 17:51:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303265#M78953</guid>
      <dc:creator>johncabrera</dc:creator>
      <dc:date>2019-12-11T17:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303275#M78956</link>
      <description>&lt;P&gt;Hi John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A few things (that you are already aware of...) but need to shed light on them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The state of the VPN on the PANW side is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;state: init&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Meaning that the PANW is attempting to xmit traffic to setup the tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This does not make sense if you stated that proxyID is working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You cannot have an "init" on a firewall with a working VPN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What am I missing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do&amp;nbsp; &amp;nbsp;you have time for an actual phone call..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can send me a PM and we can take a look at this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you have remote desktop (zoom, webex, etc) that would be great as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Let me know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 18:06:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303275#M78956</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-12-11T18:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303280#M78958</link>
      <description>&lt;P&gt;I have to step out now.&amp;nbsp; I can send you a PM on Thurs.&amp;nbsp; I do not have a zoom account.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are right, I cannot make sense of this.&amp;nbsp; If I delete Proxy-1 that goes to 10.64.204.0 and create another ProxyID that goes to 10.16.48.0. This works.&amp;nbsp; Somehow the PANW does not like both of these proxies working together.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 18:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303280#M78958</guid>
      <dc:creator>johncabrera</dc:creator>
      <dc:date>2019-12-11T18:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303283#M78960</link>
      <description>&lt;P&gt;If you can schedule for later in day (after 4pm EST) that works best for me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Zoom.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;email me at &lt;A href="mailto:steven.cantwell@cloudharmonics.com" target="_blank"&gt;steven.cantwell@cloudharmonics.com&lt;/A&gt;&amp;nbsp;and I will schedule it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 18:55:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/303283#M78960</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-12-11T18:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/347021#M86572</link>
      <description>&lt;P&gt;What was the end resolution to this? I'm having this identical problem with a tunnel to a Cisco ASA. I have 4 proxy ID's and only one will work. If i clear the tunnel and start with a different host it too will work but the others won't. This post says resolved but I don't see the resolution. Thanks&lt;BR /&gt;&lt;BR /&gt;Scot&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 22:07:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/347021#M86572</guid>
      <dc:creator>Scot_Maciver</dc:creator>
      <dc:date>2020-09-04T22:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Proxies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/347679#M86656</link>
      <description>&lt;P&gt;Scottt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ensure all 4 remote networks (from the Cisco side) are configured as Proxy IDs in the PANW FW.&lt;/P&gt;
&lt;P&gt;Ensure that the routing table on the PANW shows 4 routes, one for each proxy ID network, that you created.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Steve&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 20:16:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-proxies/m-p/347679#M86656</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-09-08T20:16:29Z</dc:date>
    </item>
  </channel>
</rss>

