<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IpSec VPN Phase1 negotiation problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/385288#M90129</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I check the VPN Router side and it s ok. Let me share the details;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remote IPSec Gateway: Palo Alto WAN Ip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel Access from Local IP address: Subnet Address&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Address for VPN:&amp;nbsp;192.168.30.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Subnet Mask:&amp;nbsp;255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tunnel access from remote IP addresses:&amp;nbsp;Subnet Address&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Address for VPN: 20.1.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Subnet Mask:&amp;nbsp;255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Phase 1 Configs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mode: Main&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Local Identifier Type: Local WAN IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remote Identifier Type:&amp;nbsp;Remote WAN IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Everythings look fine. I don't understand where came this 192.168.225.100 ip from &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Feb 2021 05:05:31 GMT</pubDate>
    <dc:creator>Lacrymae</dc:creator>
    <dc:date>2021-02-11T05:05:31Z</dc:date>
    <item>
      <title>IpSec VPN Phase1 negotiation problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/384958#M90095</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two 4G router and two ipsec vpn tunnel. Routers are exactly same.&lt;/P&gt;&lt;P&gt;VPN configs are exactly same (except Ips) one tunnel up and running but other one failed at Phase1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It gives me "IKE phase-1 negotiation is failed. Peer\'s ID payload 192.168.225.100 (type ipaddr) does not match a configured IKE gateway." error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I global search on Palo Alto for&amp;nbsp;192.168.225 nothing return. So i have not any 192.168.225.xxx ip configuration in palo alto.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So this ip coming from 4G router? But not possible i think. Becase i configure it and router LAN is 192.168.30.0/24 so connected machine ip is 192.168.30.100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am realy stuck at this point. Any help is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 08:05:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/384958#M90095</guid>
      <dc:creator>Lacrymae</dc:creator>
      <dc:date>2021-02-10T08:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: IpSec VPN Phase1 negotiation problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/385040#M90101</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/168430"&gt;@Lacrymae&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The log is saying that the peer device is sending 192.168.225.100 as it's Local ID.&amp;nbsp; This ID doesn't match the IKE Gateway's Peer Identification you have configured on the PA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd check the peer's local ID configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 10 Feb 2021 10:40:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/385040#M90101</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-02-10T10:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: IpSec VPN Phase1 negotiation problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/385076#M90103</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use Archer MR200 for ipsec VPN setup. Double check and device LAN setting details are;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ip Address: 192.168.30.1&lt;/P&gt;&lt;P&gt;Subnet:255.255.255.0&lt;/P&gt;&lt;P&gt;DHCP: Enable&lt;/P&gt;&lt;P&gt;Ip Address Pool: 192.168.30.100 -&amp;nbsp;192.168.30.199&lt;/P&gt;&lt;P&gt;Default Gateway: 192.168.30.1&lt;/P&gt;&lt;P&gt;Primary DNS:&amp;nbsp;192.168.30.1&lt;/P&gt;&lt;P&gt;Secondary DNS: 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How it could be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 14:02:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/385076#M90103</guid>
      <dc:creator>Lacrymae</dc:creator>
      <dc:date>2021-02-10T14:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: IpSec VPN Phase1 negotiation problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/385103#M90104</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/168430"&gt;@Lacrymae&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm unfamiliar with Archer MR200 but I doubt that you'll find the local ID in your device LAN settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try finding the VPN setting and search for IKE policy or IKE configuration which is where I would expect your local ID and remote/peer ID should be configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 15:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/385103#M90104</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-02-10T15:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: IpSec VPN Phase1 negotiation problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/385288#M90129</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I check the VPN Router side and it s ok. Let me share the details;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remote IPSec Gateway: Palo Alto WAN Ip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel Access from Local IP address: Subnet Address&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Address for VPN:&amp;nbsp;192.168.30.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Subnet Mask:&amp;nbsp;255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tunnel access from remote IP addresses:&amp;nbsp;Subnet Address&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IP Address for VPN: 20.1.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Subnet Mask:&amp;nbsp;255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Phase 1 Configs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mode: Main&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Local Identifier Type: Local WAN IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remote Identifier Type:&amp;nbsp;Remote WAN IP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Everythings look fine. I don't understand where came this 192.168.225.100 ip from &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 05:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/385288#M90129</guid>
      <dc:creator>Lacrymae</dc:creator>
      <dc:date>2021-02-11T05:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: IpSec VPN Phase1 negotiation problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/1230795#M124475</link>
      <description>&lt;P&gt;The solution to this is on the Palo end IKE Gateways &amp;gt; Remote Peer Identification: add the IP&amp;nbsp;&lt;SPAN&gt;192.168.225.100.&lt;BR /&gt;&lt;BR /&gt;This is common on home scale routers and even Meraki FWs do that.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This is not an issue rather an added functionality.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APurohit_0-1748929328955.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67880i16D1A0BFE110CB02/image-size/medium?v=v2&amp;amp;px=400" role="button" title="APurohit_0-1748929328955.png" alt="APurohit_0-1748929328955.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Mark resolved if works for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Work for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Abs&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 05:46:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase1-negotiation-problem/m-p/1230795#M124475</guid>
      <dc:creator>A.Purohit</dc:creator>
      <dc:date>2025-06-03T05:46:29Z</dc:date>
    </item>
  </channel>
</rss>

