<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec VPN PAlo alto Mikrotik Phase 2 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/350192#M86933</link>
    <description>&lt;P&gt;Nobody will guess where the problem is without debugs.&lt;/P&gt;&lt;P&gt;If config is corect in general, then probably issue is about phae2 mismatch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything what you need to find a problem is there:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Sep 2020 16:43:44 GMT</pubDate>
    <dc:creator>pawelzwierz</dc:creator>
    <dc:date>2020-09-17T16:43:44Z</dc:date>
    <item>
      <title>IPsec VPN PAlo alto Mikrotik Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/350089#M86924</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I setup IPsec tunnel between palo alto and mikrotik.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I found an example &lt;A href="https://grzegorzkowalik.com/mikrotik-site-to-site-vpn-z-palo-alto-networks/" target="_self"&gt;here&lt;/A&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I did everything step by step 1-13(see below)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have PAlo alto version 9.1.3-h and Router os ver. 6.43.13. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;phase 2 doesn’t work. How to befriend these devices? Help me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;SPAN&gt;Config PALO Alto&lt;BR /&gt;1.Create a new interface and add address (gateway default for tunnel in Virtual Router).&lt;BR /&gt;2.New&amp;nbsp; Zone security&lt;BR /&gt;3. Setup Phase 1 (it is IKE Crypto &amp;amp; IKE Gateway)&lt;BR /&gt;4. Phase 2 (profile incryption)&lt;BR /&gt;5.setup Ipsec Tunnels&lt;BR /&gt;6.In&amp;nbsp; virtual gateway we need add network.&lt;BR /&gt;7.Rules of security. first of allow connect and second rule allow traffic throw tunnel.&lt;BR /&gt;&lt;BR /&gt;Config Mikrotik.&lt;BR /&gt;8.Access to network throw tunnel (without NAT)&lt;BR /&gt;9.Allow ports 500 and 4500.&lt;BR /&gt;10.Politics IPSec&lt;BR /&gt;11.Peer profile&lt;BR /&gt;12.Politics.&lt;BR /&gt;13.Setup Peer.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 13:08:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/350089#M86924</guid>
      <dc:creator>melnikov</dc:creator>
      <dc:date>2020-09-17T13:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN PAlo alto Mikrotik Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/350192#M86933</link>
      <description>&lt;P&gt;Nobody will guess where the problem is without debugs.&lt;/P&gt;&lt;P&gt;If config is corect in general, then probably issue is about phae2 mismatch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything what you need to find a problem is there:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 16:43:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/350192#M86933</guid>
      <dc:creator>pawelzwierz</dc:creator>
      <dc:date>2020-09-17T16:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN PAlo alto Mikrotik Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/350199#M86937</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I also suggest to update your routeros.&lt;/P&gt;&lt;P&gt;6.43.x is a little bit too old. 6.47.3 is stable at the moment.&lt;/P&gt;&lt;P&gt;And if you have a running phase 1 ipsec vpn, check your phase2 settings.&lt;/P&gt;&lt;P&gt;Most of the time you have no matching SAs.&lt;/P&gt;&lt;P&gt;Which device is passive?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 18:12:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/350199#M86937</guid>
      <dc:creator>LANtecGmbH</dc:creator>
      <dc:date>2020-09-17T18:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN PAlo alto Mikrotik Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/350254#M86945</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i would check first if the parameters are identical on both sides. Also check the Proxy-IDs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;run this command on cli to show logs&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;less mp-log ikemgr.log&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 17 Sep 2020 23:20:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/350254#M86945</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2020-09-17T23:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN PAlo alto Mikrotik Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/352072#M87133</link>
      <description>&lt;P&gt;There is a problem with local networks behind tunnels ipsec&lt;BR /&gt;The tunnel went up.&lt;BR /&gt;I allowed on Palo Alto:&lt;BR /&gt;in property Ipsec tunnel: Proxy id remote and Local address&lt;BR /&gt;in Virtual Router static route to network behind Mikrotik throw interface tunnel with nexthop(address tunnel.80)&lt;BR /&gt;I allowed in rules:&lt;BR /&gt;All traffic from local lan to ipsec tunnel&lt;BR /&gt;From address Palo alto to Mikrotik (round trip) added application gre,ike,ipsec&lt;/P&gt;&lt;P&gt;The Mikrotik have done tunnel in logs all good&lt;BR /&gt;In setting of ipsec policy I pointed out local networks (throw Mikrotik and Palo Alto)&lt;BR /&gt;Added NAT rules allowing traffic from Microtik network to LAN Palo Alto.&lt;BR /&gt;Added Firewall rules for Protocols 17,51,50,47&lt;/P&gt;&lt;P&gt;Local Networks are not available between each other.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 08:38:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/352072#M87133</guid>
      <dc:creator>melnikov</dc:creator>
      <dc:date>2020-09-25T08:38:41Z</dc:date>
    </item>
    <item>
      <title>Site 2 site allows only two networkRe: IPsec VPN PAlo alto Mikrotik Phase 2</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/357817#M87815</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Site 2 site allows only two networks to be pulled inside the tunnel (one of them behind the mikrotik and the other one behind the palo alto).I’ve tried different settings and it doesn't help.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Has anyone had experience building a tunnel between them based on GRE tunnel over IPsec or IPIP + IPSEC?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Several networks need to be passed through the tunnel.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 15:23:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-palo-alto-mikrotik-phase-2/m-p/357817#M87815</guid>
      <dc:creator>melnikov</dc:creator>
      <dc:date>2020-10-21T15:23:13Z</dc:date>
    </item>
  </channel>
</rss>

