- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-30-2014 01:18 PM
I have created site to site vpn tunnels from a palo alto 3020 to ASA 5505 firewalls. The show green and active through the CLI and the web console. But when I try to ping a server on the other side of the tunnel I get no reply, is the tunnel up? Is it really passing traffic?
07-01-2014 06:29 AM
It was proxy id's. I removed some and corrected some and now it pings Thanks
07-01-2014 10:25 AM
Gr8... Thanks alot for detailed information...
07-01-2014 01:12 PM
I take it back it went down again and the same time as always at 2:40 pm CST and it will come back up again tonight, So its still not working right
07-01-2014 03:39 PM
If proxy ids are diff., tunnel will not come up.
Proxy ID is one of the phase-2 parameter.
07-02-2014 05:43 AM
Its not that the tunnel won't come up but it goes down every day at the same time and then is back up and working in the morning no matter what the prosy id's are set.
07-02-2014 07:47 AM
It means re-key negotiation is not working fine. Tunnel is between different vendors, so sometimes re-key could be the issue.
07-02-2014 07:51 AM
Check the PFS settings, or make sure key negotiation time is exactly same on both the firewalls.
07-02-2014 01:02 PM
Where are the PFS settings?
07-02-2014 01:03 PM
In Phase-II if you select group2 or any group, that is considered as a PFS.
Make sure its disabled or enabled on both the devices.
07-02-2014 01:11 PM
Example from GUI:
Thanks
07-02-2014 01:14 PM
Okay why would I want to disable that?
07-02-2014 01:15 PM
Hello Infotech,
We said It should be Either Enabled or Disabled on both the end.
Lets say if you want to keep it Enable on PAN then make sure its enabled on peer as well.
Regards,
hardik Shah
07-02-2014 01:46 PM
I checked and they are set the same
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!