<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ESP_TFC_PADDING_NOT_SUPPORTED in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/382701#M89878</link>
    <description>&lt;P&gt;Working with PA 5250 and ASA on the other end.&amp;nbsp; The tunnel between is up and communication flows across however we are seeing constant system errors being logged.&lt;/P&gt;
&lt;P&gt;When we enable the tunnel we get the following.&lt;/P&gt;
&lt;P&gt;IKEv2 child SA negotiation is succeeded as initiator, non-rekey. Established SA: x.x.x.x[500]-y.y.y.y[500] message id:0x00000C44, SPI:0xDB7C2CCE/0x2C52FBD3.&lt;/P&gt;
&lt;P&gt;IKEv2 child SA negotiation is failed as initiator, non-rekey. Failed SA: x.x.x.x[500]-y.y.y.y[500] message id:0x00000B7A. Error code 19&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The failed message keeps repeating approx. every 8 sec.&amp;nbsp; In examining the ikev2 settings we do not see any disparities between the two routers-- &lt;/P&gt;
&lt;P&gt;We have seen these messages however between these two peers&lt;/P&gt;
&lt;P&gt;IKEv2 SA negotiation is failed, received notify type ESP_TFC-PADDING_NOT_SUPPORTED&lt;/P&gt;
&lt;P&gt;IKEv2 SA negotiation is failed, received notify type NON_FIRST_FRAGMENTS_ALSO&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone shed some light?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 19:50:07 GMT</pubDate>
    <dc:creator>vnt90</dc:creator>
    <dc:date>2021-01-28T19:50:07Z</dc:date>
    <item>
      <title>ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/382701#M89878</link>
      <description>&lt;P&gt;Working with PA 5250 and ASA on the other end.&amp;nbsp; The tunnel between is up and communication flows across however we are seeing constant system errors being logged.&lt;/P&gt;
&lt;P&gt;When we enable the tunnel we get the following.&lt;/P&gt;
&lt;P&gt;IKEv2 child SA negotiation is succeeded as initiator, non-rekey. Established SA: x.x.x.x[500]-y.y.y.y[500] message id:0x00000C44, SPI:0xDB7C2CCE/0x2C52FBD3.&lt;/P&gt;
&lt;P&gt;IKEv2 child SA negotiation is failed as initiator, non-rekey. Failed SA: x.x.x.x[500]-y.y.y.y[500] message id:0x00000B7A. Error code 19&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The failed message keeps repeating approx. every 8 sec.&amp;nbsp; In examining the ikev2 settings we do not see any disparities between the two routers-- &lt;/P&gt;
&lt;P&gt;We have seen these messages however between these two peers&lt;/P&gt;
&lt;P&gt;IKEv2 SA negotiation is failed, received notify type ESP_TFC-PADDING_NOT_SUPPORTED&lt;/P&gt;
&lt;P&gt;IKEv2 SA negotiation is failed, received notify type NON_FIRST_FRAGMENTS_ALSO&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone shed some light?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 19:50:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/382701#M89878</guid>
      <dc:creator>vnt90</dc:creator>
      <dc:date>2021-01-28T19:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/383177#M89918</link>
      <description>&lt;P&gt;did you enable a DH group in the phase-2 crypto profile?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have (&lt;STRONG&gt;&lt;EM&gt;not&lt;/EM&gt;&lt;/STRONG&gt; set nopfs), could you share some of the config to help shed some light on what you are trying to negotiate&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2021 23:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/383177#M89918</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-01-31T23:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/383182#M89919</link>
      <description>&lt;P&gt;I've run a couple of tests and i get that error message (tfc padding) all the time when running IKEv2, so it may just be 'expected'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you may need to doublecheck your ProxyIDs to see why one child SA is failing&lt;/P&gt;&lt;P&gt;the remote end should see logging that match the message ID and have more detailed logging to indicate why it fails&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 00:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/383182#M89919</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-02-01T00:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/388146#M90457</link>
      <description>&lt;P&gt;Checked the proxy id's are the same on both ends.&amp;nbsp; What is causing the error is the fact that I have tunnel monitor turned on and set to a resource on their end (ex. 172.30.21.5)&amp;nbsp; Their ASA flags an error that they are receiving a ping from 172.30.21.1 to 172.30.21.5.&amp;nbsp; 172.30.21.1 is their gateway addr.&amp;nbsp;&amp;nbsp;&amp;nbsp; I don't know what address is used by the Palo to generate the "tunnel monitor ping" but I would not expect it to be their gateway addr .&amp;nbsp; Since the gateway address is not in the proxy id list the ASA flags it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKE Receiver: Packet received on a.b.c.d from 1.2.3.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPSEC: Received on ESP packet (SPI=0x1234567,sequence number=0x123444354)from 1.2.3.4(user=1.2.3.4)to a.b.c.d&amp;nbsp; The decapsulate inner packet doesn’t match the negotiated policy in the SA.&amp;nbsp; The packet specifies its destination as 172.30.21.5 its source as 172.30.21.1, and its protocol as icmp.&amp;nbsp; The SA specifies its local proxy as 172.30.21.5/255.255.255.255/ip/0 and its remote_proxy as (the list of agreed ips for our side).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Local:a.b.c.d:500 Remote:1.2.3.4:500 Username 1.2.3.4 IKEv2 Negotiation aborted due to ERROR: Create child exchange failed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume that their gateway is proxing the ping from our end.&amp;nbsp; Don't know how to resolve this.&amp;nbsp; 1) what palo address is used to generate the ping for "tunnel monitoring"&amp;nbsp; 2) is there a setting in the ASA to stop the proxying of the ping?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thnks for the help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 16:46:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/388146#M90457</guid>
      <dc:creator>vnt90</dc:creator>
      <dc:date>2021-02-26T16:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/388192#M90460</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/13565"&gt;@vnt90&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;When you enable tunnel monitoring the tunnel interface IP is used for the ICMP request to the monitored IP. On the ASA, do you have ICMP inspection enabled at all?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 21:09:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/388192#M90460</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-02-26T21:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/399004#M91554</link>
      <description>&lt;P&gt;We're running into this problem now between a PA-220 and a ASA using IKEv2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were you able to identify the problem?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 16:00:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/399004#M91554</guid>
      <dc:creator>Drew-Gilman</dc:creator>
      <dc:date>2021-04-16T16:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/412144#M92807</link>
      <description>&lt;P&gt;I just started this problem between two PA&lt;/P&gt;&lt;P&gt;PA-220 and VM-100&lt;/P&gt;&lt;P&gt;No network changes done,&amp;nbsp;&lt;/P&gt;&lt;P&gt;31st of May&amp;nbsp;ESP_TFC_PADDING_NOT_SUPPORTED in System Log , first event and suddenly customer starts to report the issues with dropping tunnels..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 16:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/412144#M92807</guid>
      <dc:creator>PiankaMariusz</dc:creator>
      <dc:date>2021-06-09T16:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/512611#M106508</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Does anyone have the solution to the problem?&lt;/P&gt;
&lt;P&gt;The same thing is happening to me. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 21:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/512611#M106508</guid>
      <dc:creator>EmilianoMedinaC</dc:creator>
      <dc:date>2022-08-22T21:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/512807#M106541</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/224543"&gt;@EmilianoMedinaC&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you using IKEv1 or IKEv2 ?&lt;/P&gt;
&lt;P&gt;Can you perform some VPN debugging and get some logs to help us further ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 24 Aug 2022 08:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/512807#M106541</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-08-24T08:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/594584#M118338</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We are also&amp;nbsp;facing this problem between two PA-3220 and VM-300.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No network changes done, and both phases are up only.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;ESP_TFC_PADDING_NOT_SUPPORTED&lt;/STRONG&gt; in System Log , first event and suddenly customer starts to report the issues with dropping tunnels.&lt;/P&gt;
&lt;P&gt;Please share any solutions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 05:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/594584#M118338</guid>
      <dc:creator>Abdulkareem</dc:creator>
      <dc:date>2024-08-12T05:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: ESP_TFC_PADDING_NOT_SUPPORTED</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/617524#M122009</link>
      <description>&lt;P&gt;Any solution yet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 20:10:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/esp-tfc-padding-not-supported/m-p/617524#M122009</guid>
      <dc:creator>msdphi</dc:creator>
      <dc:date>2024-11-13T20:10:31Z</dc:date>
    </item>
  </channel>
</rss>

