- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-11-2014 08:56 AM
I am setting up an IPSec tunnel to an ASA. I am getting an error message about the PEERID type only allowing IP but received FQDN. Per the other KB article, I changed the PAN Exchange mode to Aggressive.
Now the PAN received a FQDN of the ASA side and gave listed the FQDN in the system logs.
My question.. where in the ASA can you configure PEER and LOCAL ID in the Phase1 settings? I am not seeing that option so I cannot figure out how the PAN is getting the FQDN.
07-11-2014 09:04 AM
A related DOC, it shows configuration sample for both PAN and CISCO firewall.
( On CISCO: crypto isakmp profile XYZ self-identity user-FQDN/IP XYZ )
Thanks
01-03-2023 01:36 PM
Hello all! If anyone runs across this article and would like to use the link referenced in the solution please see the below link:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHVCA0
07-11-2014 09:01 AM
Your config on the firewall is expecting IP instead of FQDN
Check below. Choose the appropriate option and the error should go away.
07-11-2014 09:03 AM
I appreciate the input but that's not quite it...
The issue is that it is receiving a FQDN for the PEER ID from the Cisco ASA. I am looking for how to determine in the ASA where it is sending its FQDN as an ID because I do not see anything in the ASA that would send its FQDN.
07-11-2014 09:04 AM
A related DOC, it shows configuration sample for both PAN and CISCO firewall.
( On CISCO: crypto isakmp profile XYZ self-identity user-FQDN/IP XYZ )
Thanks
07-11-2014 09:08 AM
The crypto settings under number 2 showed me what to change. Thank you!
01-03-2023 01:36 PM
Hello all! If anyone runs across this article and would like to use the link referenced in the solution please see the below link:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHVCA0
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!