<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKE SA negotiation is started as initiator, non-rekey in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406315#M92089</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Thanks for fast replay , i try this but still no luck,&amp;nbsp; It is also very strange i have this same configuration on different location and it works without any problems.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After change the ike to passive i have this information in logs :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Lukaszm1_0-1620811014093.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33785i638248B0F7F21B4B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Lukaszm1_0-1620811014093.png" alt="Lukaszm1_0-1620811014093.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 May 2021 10:14:30 GMT</pubDate>
    <dc:creator>Lukaszm1</dc:creator>
    <dc:date>2021-05-12T10:14:30Z</dc:date>
    <item>
      <title>IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406276#M92084</link>
      <description>&lt;P&gt;Hello :),&lt;/P&gt;&lt;P&gt;I have a problem with VPN from PA-220 to Azure. The logs show this information : "IKEv2 IKE SA negotiation is started as initiator, non-rekey. Initiated SA "&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every change I made it always is this same error. Is there any way to resolve this issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 07:36:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406276#M92084</guid>
      <dc:creator>Lukaszm1</dc:creator>
      <dc:date>2021-05-12T07:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406287#M92085</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114868"&gt;@Lukaszm1&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The log you have shared doesn't contain any error. It indicates that FW is trying to negotiate Phase1. The key point here is that FW is starting the negotiation ("as initiator"), due to the nature of the IPsec the initiator will not log the real reason why negotiation is failing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can try to enable passive mode under the IKE Gateway advance options - this will force the firewall to act only as responder and waits for the Azure to trigger negotiation. That way you should see more "detailed" log what could be the reason for the unsuccessful negotiation. Note that in thi case you need to find a way to tell Azure to start first - either by sending traffic from azure to on-prem network or by any "azure troubleshooting commands".&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 08:20:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406287#M92085</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-05-12T08:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406315#M92089</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Thanks for fast replay , i try this but still no luck,&amp;nbsp; It is also very strange i have this same configuration on different location and it works without any problems.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After change the ike to passive i have this information in logs :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Lukaszm1_0-1620811014093.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33785i638248B0F7F21B4B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Lukaszm1_0-1620811014093.png" alt="Lukaszm1_0-1620811014093.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 10:14:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406315#M92089</guid>
      <dc:creator>Lukaszm1</dc:creator>
      <dc:date>2021-05-12T10:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406390#M92098</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114868"&gt;@Lukaszm1&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These logs are not related to the VPN negotiation, but rather with configuration commit.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AlexanderAstardzhiev_0-1620827089325.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33790i88011591EC51B2B5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AlexanderAstardzhiev_0-1620827089325.png" alt="AlexanderAstardzhiev_0-1620827089325.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have enabled passive mode on the FW and you don't see anything else it probably means Azure is not even trying.&lt;/P&gt;&lt;P&gt;If you don't have a way to force Azure to start negotiation, you can disable again the passive mode and run packet capture for IKE packets on the FW. Under CLI run:&lt;BR /&gt;&amp;gt; debug ike pcap on (this will capture any ike packets so if you have other tunnel already running in this fw it will capture them as well)&lt;BR /&gt;&amp;gt; debug ike pcap view&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 13:51:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406390#M92098</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-05-12T13:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406708#M92146</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks again, I found what was the problem, I make a mistake in polices and there was a bad ip address on it to the azure ;/ .&amp;nbsp;&lt;/P&gt;&lt;P&gt;No it is working &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks ! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 06:18:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/406708#M92146</guid>
      <dc:creator>Lukaszm1</dc:creator>
      <dc:date>2021-05-14T06:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/414807#M93184</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114868"&gt;@Lukaszm1&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having the very same issue,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you mean by "there was a bad IP on it to azure"?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 17:54:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/414807#M93184</guid>
      <dc:creator>bcalderon</dc:creator>
      <dc:date>2021-06-23T17:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/414919#M93199</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182084"&gt;@bcalderon&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the configuration on the&amp;nbsp;&lt;STRONG&gt;Policies&amp;nbsp;&lt;/STRONG&gt;there should be entry with information that You allow the connection from Your WAN ip address to the other site IP Address.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 04:42:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/414919#M93199</guid>
      <dc:creator>Lukaszm1</dc:creator>
      <dc:date>2021-06-24T04:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/415011#M93208</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114868"&gt;@Lukaszm1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So a Security Policy could prevent the establishment of phase 1?&amp;nbsp;&lt;BR /&gt;I thought a policy could affect the traffic flow between zones, but once the tunnel was up and running...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, going to check that&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 13:49:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/415011#M93208</guid>
      <dc:creator>bcalderon</dc:creator>
      <dc:date>2021-06-24T13:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/415201#M93229</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/182084"&gt;@bcalderon&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In My case it do the job, after add proper ip address it established with no problem. Try to do that and see what happend. On the application add " ike and ipsec" it should be enough to have more granular control.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 04:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/415201#M93229</guid>
      <dc:creator>Lukaszm1</dc:creator>
      <dc:date>2021-06-25T04:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: IKE SA negotiation is started as initiator, non-rekey</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/415280#M93242</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114868"&gt;@Lukaszm1&lt;/a&gt;,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks a lot for your help,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually, the issue was solved with a reboot haha,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When doubt, reboot!&lt;BR /&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 16:52:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ike-sa-negotiation-is-started-as-initiator-non-rekey/m-p/415280#M93242</guid>
      <dc:creator>bcalderon</dc:creator>
      <dc:date>2021-06-25T16:52:59Z</dc:date>
    </item>
  </channel>
</rss>

