- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-14-2015 04:02 AM
Hi All,
We have configured IPSec VPN between PAN and AWS.
When i iniate the tunnel, IPSec and IKE SA installed successfully as a initiator.
then, IKE protocol IPSec SA delete message sent to peer. SPI:0x...
After a second, IPSec key deleted. Deleted SA..... please suggest
10-14-2015 06:49 AM
Can you set vpn on Palo into passive mode and initiate vpn from other side?
System log on Palo shows pretty exactly at what state vpn fails.
10-14-2015 08:46 AM
The only options are Main, Auto, and Agressive. You can play with those. But like pakumar pointed out. If its phase 2, it could be proxy id's.
Its under Ike Gateway -> Advanced Phase 1 options.
10-14-2015 08:52 AM
Of course i didnt look very hard, Yes there is a Passive option in the IKE gateway.
10-15-2015 12:42 AM
According to original post (Quote:"When i iniate the tunnel, IPSec and IKE SA installed successfully as a initiator.") I'd say all parameters are ok and IPSEC is esatblished sucesfully but DPD mechanism kicks in and takes it down.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!