<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/337760#M85007</link>
    <description>&lt;P&gt;Also on 9.1. Admin Guide site 907.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After Upgrading from working 9.0.8 with multiple IKE crypto profiles on same Interface / IP I got an auto commit error.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="status auto commit job public.JPG" style="width: 758px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26722iAE9BFDA4CEFD5C27/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="status auto commit job public.JPG" alt="status auto commit job public.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ike crypto profile.JPG" style="width: 854px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26721i9CA7A935023B60E3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ike crypto profile.JPG" alt="ike crypto profile.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jul 2020 15:54:08 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2020-07-10T15:54:08Z</dc:date>
    <item>
      <title>several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241559#M69171</link>
      <description>&lt;P&gt;Hello dear colleagues,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;according to the documentation, there is a limitation for IKE gateways:&lt;/P&gt;&lt;P&gt;All IKE gateways configured on the same interface or local IP address must use the same crypto&lt;BR /&gt;profile. (c)&amp;nbsp;&lt;/P&gt;&lt;P&gt;The same restriction is mentioned in the PANOS v8.1 course.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all, it seems strange that we cannot use different IKE options for different peers. Second, I use different IKE Crypto Profiles for different IKE gateways on the same public interface without any problem. I can see that they do use different algorithms for encrypting, hashing, DH group, etc. So it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Is it some obsolete information they just forgot to remove?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vladimir Stepanov&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 10:56:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241559#M69171</guid>
      <dc:creator>vladimir.stepanov</dc:creator>
      <dc:date>2018-11-29T10:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241581#M69177</link>
      <description>&lt;P&gt;Can you point out where it is in documentation?&lt;/P&gt;&lt;P&gt;You can definitely use diferent crypto profiles on same interface in diferent IKE gateways.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 14:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241581#M69177</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-11-29T14:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241586#M69180</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/69451"&gt;@vladimir.stepanov&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;mentioned this is either poorly worded or simply not correct. You can only assign one profile per IKE gateway (obviously), but as long as you use a different IKE gateway you can have multiple profiles assigned regardless of them sharing the same physical interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 14:56:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241586#M69180</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-29T14:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241600#M69187</link>
      <description>&lt;P&gt;At first I have seen it in the paloalto online course for Pan-OS 8.1, module about Site-to-Site VPN, IKE Gateway configuration. After I started to search and found the same in the PAN-OS Admin Guide 8.0 - Page 691&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ike crypto profiles.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17744i056DE8DB855C6402/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ike crypto profiles.PNG" alt="ike crypto profiles.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 15:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241600#M69187</guid>
      <dc:creator>vladimir.stepanov</dc:creator>
      <dc:date>2018-11-29T15:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241652#M69206</link>
      <description>&lt;P&gt;???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have never seen or heard of this note and since 5.0 I use different profiles for the ike gateways ... also with 8.0&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2018 22:25:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241652#M69206</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-11-29T22:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241689#M69211</link>
      <description>&lt;P&gt;Definitelly a mistake. This would make firewall practically useless for VPNs.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2018 07:04:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241689#M69211</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-11-30T07:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241699#M69213</link>
      <description>&lt;P&gt;Ok, thanks everybody, I am going to report them about this mistake. Just strange that this is mentioned in several sources.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2018 09:43:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/241699#M69213</guid>
      <dc:creator>vladimir.stepanov</dc:creator>
      <dc:date>2018-11-30T09:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/337760#M85007</link>
      <description>&lt;P&gt;Also on 9.1. Admin Guide site 907.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After Upgrading from working 9.0.8 with multiple IKE crypto profiles on same Interface / IP I got an auto commit error.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="status auto commit job public.JPG" style="width: 758px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26722iAE9BFDA4CEFD5C27/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="status auto commit job public.JPG" alt="status auto commit job public.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ike crypto profile.JPG" style="width: 854px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26721i9CA7A935023B60E3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ike crypto profile.JPG" alt="ike crypto profile.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 15:54:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/337760#M85007</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-07-10T15:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/337983#M85047</link>
      <description>&lt;P&gt;Are your peers configured with dynamic IPs?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 03:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/337983#M85047</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2020-07-13T03:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/337997#M85049</link>
      <description>&lt;P&gt;Yes, my peers configured with dynamic IP's&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 05:41:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/337997#M85049</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-07-13T05:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/338072#M85064</link>
      <description>&lt;P&gt;From 9.1 you can't commit unless all dynamic peers have same crypto profile.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 12:55:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/338072#M85064</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2020-07-13T12:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/338080#M85067</link>
      <description>&lt;P&gt;Sounds like a bad joke.&amp;nbsp;This is an irony&amp;nbsp;that&amp;nbsp;would&amp;nbsp;be funny were&amp;nbsp;it not&amp;nbsp;so&amp;nbsp;tragic.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 14:11:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/338080#M85067</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-07-13T14:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/339541#M85259</link>
      <description>&lt;P&gt;Yes, that sounds like a step backwards in 9.1. What is the logic behind this?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 06:07:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/339541#M85259</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2020-07-20T06:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/340029#M85357</link>
      <description>&lt;P&gt;Is it mentioned somewhere in the release notes? I didn't found it, so I am afraid that they just broken it occasionally.&lt;/P&gt;&lt;P&gt;It is sad, the paloalto is becoming a really **bleep** product. The support is awful, it needs to explain to support engineers how things should work. During one of my last discussions, I have spent four hours proving with references to the documentation and with tests in the lab I created especially for this. And this ticket is still on the engineering side for 8 months without any estimate.&lt;/P&gt;&lt;P&gt;Another problem unresolved for more than three months and the only feedback is that they may be fix it in 9.0.11, but for now there is even no estimation date for 9.0.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;GeoIP is not reliable and there is no easy procedure on how to fix errors there, the support proposes to rollback the content database to the old that was a week ago, or just wait, "maybe it will be fixed in some future update".&lt;/P&gt;&lt;P&gt;&amp;nbsp; External dynamic lists from the PaloAlto are abandoned before there were thousands of malicious IPs, not just hundreds.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 10:04:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/340029#M85357</guid>
      <dc:creator>ppk_vs</dc:creator>
      <dc:date>2020-07-22T10:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/340039#M85359</link>
      <description>&lt;P&gt;I have had the exact same experience.&lt;BR /&gt;And the GeoIP bug hits also the fqdn-Objects. For this bug support needed 12d to find out and publish to me.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 11:47:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/340039#M85359</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-07-22T11:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/345693#M86374</link>
      <description>&lt;P&gt;We have the same problem int 9.0.9-h1 with dynamic peers, we didn't have a problem on 9.0.4&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 08:02:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/345693#M86374</guid>
      <dc:creator>MortensenKnud</dc:creator>
      <dc:date>2020-08-27T08:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: several IKE Crypto Profiles on the same interface for SITE-to-SITE VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/367399#M88833</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any documentation related to this issue, Where I can show to my customer?.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Dec 2020 05:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-ike-crypto-profiles-on-the-same-interface-for-site-to/m-p/367399#M88833</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2020-12-05T05:05:31Z</dc:date>
    </item>
  </channel>
</rss>

