- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
06-04-2014 12:51 PM
When trying to configure a site to site VPN tunnel from a PA 3020 to a Cisco 5505 firewal I am getting th following messages on the Cisco firewall
received encrypted packet with no matching sa dropping
all ipsec proposals found unacceptable
06-05-2014 01:20 PM
can you grab and clean up (replace any public IPs with something else i.e replace the Cisco address with Cisco-Address) the following from the 3020
show network tunnel ipsec (only need the lines for the tunnel having issues)
show network ike crypto-profiles ike-crypto-profiles
show network ike gateway (only need the gateway associated with this connection)
From the ASA - connect to ssh or console
show run
find the related Cisco command from this article - Sample IPSec Tunnel Configuration - Palo Alto Networks Firewall to Cisco ASA for the VPN
06-05-2014 01:54 PM
This may take me awhile
I tried to do a
show network ike crypto-profiles ike-crypto-profiles
on the 3020 it gave me an invalid syntax
06-06-2014 05:32 AM
try just show network ike crypto-profiles
06-06-2014 05:51 AM
I do not find an option for show network on the PA 3020 unless I am in the wrong place in the cli
06-06-2014 06:22 AM
are you in configure mode?
06-06-2014 06:40 AM
No didn't know I had to be, I have never done cisco or PA before I took this job so I am still learning a lot
06-06-2014 01:08 PM
Hello Infotech,
If you are still having problem to setup IPSec tunnel between Cisco to PAN, I would recommened you to open a ticket with support. They might help you for the same.
Thanks
06-09-2014 05:57 AM
Yes I have contacted support for assistance with my issue thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!