<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ikev2 with cisco Router using certificate problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-with-cisco-router-using-certificate-problem/m-p/344762#M86234</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after I finished the ikev2 configuration(using &lt;STRONG&gt;Distinguished Name (Subject)&lt;/STRONG&gt; from PAN and Cisco Router using &lt;STRONG&gt;identity local dn&lt;/STRONG&gt; ), I got this isse:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;received ID_I (type dn [CN=externalrouter.robinlab.org,unstructuredName=externalrouter.robinlab.org]) does not match peers id&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;IKEv2 IKE SA negotiation is failed as responder&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luping&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2020 11:56:15 GMT</pubDate>
    <dc:creator>Luping</dc:creator>
    <dc:date>2020-08-20T11:56:15Z</dc:date>
    <item>
      <title>ikev2 with cisco Router using certificate problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-with-cisco-router-using-certificate-problem/m-p/344762#M86234</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after I finished the ikev2 configuration(using &lt;STRONG&gt;Distinguished Name (Subject)&lt;/STRONG&gt; from PAN and Cisco Router using &lt;STRONG&gt;identity local dn&lt;/STRONG&gt; ), I got this isse:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;received ID_I (type dn [CN=externalrouter.robinlab.org,unstructuredName=externalrouter.robinlab.org]) does not match peers id&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;IKEv2 IKE SA negotiation is failed as responder&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luping&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 11:56:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-with-cisco-router-using-certificate-problem/m-p/344762#M86234</guid>
      <dc:creator>Luping</dc:creator>
      <dc:date>2020-08-20T11:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: ikev2 with cisco Router using certificate problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-with-cisco-router-using-certificate-problem/m-p/344780#M86237</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/140623"&gt;@Luping&lt;/a&gt;There seems to be mismatch in the DN name you have configured under IKE gateway and the certificate present under certificate profile. Also verify IKE version configuration at both ends.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 12:57:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-with-cisco-router-using-certificate-problem/m-p/344780#M86237</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-08-20T12:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: ikev2 with cisco Router using certificate problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-with-cisco-router-using-certificate-problem/m-p/344782#M86239</link>
      <description>&lt;P&gt;I changed the configuration using preshare for Ikev2, it works. Just if I change to certificate, it show me this error message. it should no IKE missconfigure...&lt;/P&gt;&lt;P&gt;and DN, I just use the subject-name CN, you can see both find the same DN "externalrouter.robinlab.org".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"CN=externalrouter.robinlab.org,unstructuredName=externalrouter.robinlab.org" --- &lt;/EM&gt;what is "&lt;STRONG&gt;unstructuredName&lt;/STRONG&gt;"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PKI Configuration from Router:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;crypto pki trustpoint CA&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;enrollment terminal&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;serial-number none&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;fqdn externalrouter.robinlab.org&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ip-address none&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;subject-name CN=externalrouter.robinlab.org&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;revocation-check none&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;rsakeypair sslkey&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 13:05:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-with-cisco-router-using-certificate-problem/m-p/344782#M86239</guid>
      <dc:creator>Luping</dc:creator>
      <dc:date>2020-08-20T13:05:59Z</dc:date>
    </item>
  </channel>
</rss>

