<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Works but.... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10762#M7934</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured an IPSec site to site VPN between Palo Alto Firewall and Checkpoint Firewall. &lt;/P&gt;&lt;P&gt;Everything works perfectly as expected, but I get constant Logs : IKE-Phase 2 negotiation failed when processing proxy ID. cannot find matching phase 2 tunnel for received proxy ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the proxy IDs and tunnel seems to work. But still I get the above mentioned log constantly with severity "informatikonal".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what is going wrong??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Nov 2014 13:05:56 GMT</pubDate>
    <dc:creator>Neo.The.One</dc:creator>
    <dc:date>2014-11-19T13:05:56Z</dc:date>
    <item>
      <title>VPN Works but....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10762#M7934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured an IPSec site to site VPN between Palo Alto Firewall and Checkpoint Firewall. &lt;/P&gt;&lt;P&gt;Everything works perfectly as expected, but I get constant Logs : IKE-Phase 2 negotiation failed when processing proxy ID. cannot find matching phase 2 tunnel for received proxy ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the proxy IDs and tunnel seems to work. But still I get the above mentioned log constantly with severity "informatikonal".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what is going wrong??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 13:05:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10762#M7934</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-11-19T13:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Works but....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10763#M7935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Above mentioned log should come in the event of Proxy ID mismatch, which you have already corrected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And in this case firewall should not establish phase-2.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are these older logs or new logs? If its new logs than make sure its for the same tunnel and not any other tunnel? If its for the same tunnel than its a strange behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 14:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10763#M7935</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-11-19T14:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Works but....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10764#M7936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone tries to send traffic from a different subnet OR to a different subnet, which is not part of your PROXY ID, then the firewall will drop those packets with above mentioned messages.&amp;nbsp; Since PROXY ID will not match for that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may check &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;ike&lt;/SPAN&gt;-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mgr&lt;/SPAN&gt; logs to get the source/destination IP of that dropped traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;less&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;mp&lt;/SPAN&gt;-log ikemgr.log&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;show&lt;/SPAN&gt; log system direction equal backward&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can either &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;user&lt;/SPAN&gt; Space-Bar &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;to go&lt;/SPAN&gt; down the logs or use "shift + g"&amp;nbsp; to go at the bottom of the logs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Nov 2014 16:33:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10764#M7936</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-19T16:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Works but....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10765#M7937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your replies but the problem still persists. The tunnel goes down intermittently in a day. The tunnel seems to work for 80% of time in a day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19490"&gt;hshah&lt;/A&gt; - The logs above are new logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt; - I tried running the command &lt;SPAN lang="DE" style="font-size: 10.0pt; font-family: 'Courier New'; color: #3b3b3b; background: white;"&gt;&lt;STRONG style=": ; color: #3366ff;"&gt;tail follow yes mp-log ikemgr.log&lt;/STRONG&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN lang="DE"&gt;and following was the output&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;====&amp;gt; Initiated SA: IP-ADDRESSES-HERE message id:0x42D6F11F &amp;lt;====&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;2014-11-21 11:05:19 [INTERNAL_ERR]: can't find matching selector&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;2014-11-21 11:05:19 [PROTO_ERR]: failed to get sainfo.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;2014-11-21 11:05:19 [INTERNAL_ERR]: failed to pre-process packet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;2014-11-21 11:05:21 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS RESPONDER, (QUICK MODE) &amp;lt;====&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;Any suggestions as to what can be going wrong? This is strange behavior!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Courier New'; color: #1f497d;"&gt;Thanks!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Nov 2014 10:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10765#M7937</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-11-24T10:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Works but....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10766#M7938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem was resolved. The problem was missing proxy IDs for external interfaces. Thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Nov 2014 11:19:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-works-but/m-p/10766#M7938</guid>
      <dc:creator>Neo.The.One</dc:creator>
      <dc:date>2014-11-25T11:19:30Z</dc:date>
    </item>
  </channel>
</rss>

