<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query on DH group for IPSEC VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-dh-group-for-ipsec-vpn/m-p/331517#M83931</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The phase 1 properties are not correct for both sides of the tunnel. The 'receiving' side of the VPN should provide more information as to why. However start with the basics and make sure your ike settings are identical on both devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check your logs to make sure you are not dropping any of the traffic (doesnt sound like it however).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jun 2020 21:30:53 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2020-06-03T21:30:53Z</dc:date>
    <item>
      <title>Query on DH group for IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-dh-group-for-ipsec-vpn/m-p/330937#M83849</link>
      <description>&lt;DIV&gt;&lt;SPAN&gt;We are having issue in building an IPSEC tunnel on a Palo firewall. Using ver 9.1.2.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Getting below error&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;'IKE phase-1 negotiation is failed. Couldn't find configuration for IKE phase-1 request for peer IP...&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;The peer IP type is Dynamic with no proxy ID in use. We are using IKEv1, DPD is disabled, NAT-t is enabled, Phase1 &amp;amp; 2 are matching at both ends, Exchange modes are also matching. PA is enabled in passive mode.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;We had to set DH Group to no-pfs under IPsec crypto profile.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;When setting no-pfs value is there any other setting we need to set on palo side for the tunnel to work?&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Jun 2020 00:26:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-dh-group-for-ipsec-vpn/m-p/330937#M83849</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2020-06-02T00:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Query on DH group for IPSEC VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-dh-group-for-ipsec-vpn/m-p/331517#M83931</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The phase 1 properties are not correct for both sides of the tunnel. The 'receiving' side of the VPN should provide more information as to why. However start with the basics and make sure your ike settings are identical on both devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check your logs to make sure you are not dropping any of the traffic (doesnt sound like it however).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 21:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-dh-group-for-ipsec-vpn/m-p/331517#M83931</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-06-03T21:30:53Z</dc:date>
    </item>
  </channel>
</rss>

