<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Phase 2 tunnel is not up in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/phase-2-tunnel-is-not-up/m-p/424789#M94289</link>
    <description>&lt;P&gt;One of my clients configure the site to site tunnel from AWS to Palo alto device the phase 1 is able to up but the second phase is not up it is because we didn't&amp;nbsp; enter the proxy id for or something else i should go for troubleshoot kindly help.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 14:03:40 GMT</pubDate>
    <dc:creator>FarhanKoujalgi</dc:creator>
    <dc:date>2021-08-05T14:03:40Z</dc:date>
    <item>
      <title>Phase 2 tunnel is not up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/phase-2-tunnel-is-not-up/m-p/424789#M94289</link>
      <description>&lt;P&gt;One of my clients configure the site to site tunnel from AWS to Palo alto device the phase 1 is able to up but the second phase is not up it is because we didn't&amp;nbsp; enter the proxy id for or something else i should go for troubleshoot kindly help.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 14:03:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/phase-2-tunnel-is-not-up/m-p/424789#M94289</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-08-05T14:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 tunnel is not up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/phase-2-tunnel-is-not-up/m-p/424840#M94298</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/181525"&gt;@FarhanKoujalgi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Proxy IDs on palo alto side are required to mentioned whenever peer end is acting as Policy based VPN because Palo Alto always act as Route based vpn. Now in order to check if proxy id is causing the issues, you should check the system logs by filtering VPN logs which will give you more clarity on the issue. If issue with proxy ids, you will see logs like &lt;STRONG&gt;&lt;EM&gt;proxy-id mismatch / &lt;SPAN&gt;negotiation failed when processing proxy ID&lt;/SPAN&gt;.&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;EM&gt;Proxy ID's need to be identical on both VPN peers for negotiation to be successful.&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Apart from that, I would recommend you to verify the Phase 2 IPSEC parameters, routes for the traffic to be routed from tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 15:31:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/phase-2-tunnel-is-not-up/m-p/424840#M94298</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-08-05T15:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Phase 2 tunnel is not up</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/phase-2-tunnel-is-not-up/m-p/425244#M94335</link>
      <description>&lt;P&gt;&lt;A href="mailto:Hi@SutareMayur" target="_blank"&gt;Hi@SutareMayur&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thank you for your solution and support the tunnel is up while add proper proxy id.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 16:37:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/phase-2-tunnel-is-not-up/m-p/425244#M94335</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-08-07T16:37:44Z</dc:date>
    </item>
  </channel>
</rss>

