IPsec VPN PAlo alto Mikrotik Phase 2

Announcements

Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Reply
melnikov
L1 Bithead

IPsec VPN PAlo alto Mikrotik Phase 2

Hello!

I setup IPsec tunnel between palo alto and mikrotik.
I found an example here.
I did everything step by step 1-13(see below)

I have PAlo alto version 9.1.3-h and Router os ver. 6.43.13.
phase 2 doesn’t work. How to befriend these devices? Help me.

 

 

Config PALO Alto
1.Create a new interface and add address (gateway default for tunnel in Virtual Router).
2.New  Zone security
3. Setup Phase 1 (it is IKE Crypto & IKE Gateway)
4. Phase 2 (profile incryption)
5.setup Ipsec Tunnels
6.In  virtual gateway we need add network.
7.Rules of security. first of allow connect and second rule allow traffic throw tunnel.

Config Mikrotik.
8.Access to network throw tunnel (without NAT)
9.Allow ports 500 and 4500.
10.Politics IPSec
11.Peer profile
12.Politics.
13.Setup Peer.

pawelzwierzynski
L2 Linker

Nobody will guess where the problem is without debugs.

If config is corect in general, then probably issue is about phae2 mismatch.

 

Everything what you need to find a problem is there:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC

LANtecGmbH
L0 Member

Hi,

I also suggest to update your routeros.

6.43.x is a little bit too old. 6.47.3 is stable at the moment.

And if you have a running phase 1 ipsec vpn, check your phase2 settings.

Most of the time you have no matching SAs.

Which device is passive?

 

 

Best

 

 

Abdul-Fattah
L4 Transporter

Hi,

 

i would check first if the parameters are identical on both sides. Also check the Proxy-IDs.

 

run this command on cli to show logs

less mp-log ikemgr.log
melnikov
L1 Bithead

There is a problem with local networks behind tunnels ipsec
The tunnel went up.
I allowed on Palo Alto:
in property Ipsec tunnel: Proxy id remote and Local address
in Virtual Router static route to network behind Mikrotik throw interface tunnel with nexthop(address tunnel.80)
I allowed in rules:
All traffic from local lan to ipsec tunnel
From address Palo alto to Mikrotik (round trip) added application gre,ike,ipsec

The Mikrotik have done tunnel in logs all good
In setting of ipsec policy I pointed out local networks (throw Mikrotik and Palo Alto)
Added NAT rules allowing traffic from Microtik network to LAN Palo Alto.
Added Firewall rules for Protocols 17,51,50,47

Local Networks are not available between each other.

melnikov
L1 Bithead

Site 2 site allows only two networks to be pulled inside the tunnel (one of them behind the mikrotik and the other one behind the palo alto).I’ve tried different settings and it doesn't help.
Has anyone had experience building a tunnel between them based on GRE tunnel over IPsec or IPIP + IPSEC?
Several networks need to be passed through the tunnel.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!