Port 4500 ipsec/udp traffice

Reply
Highlighted
L4 Transporter

Port 4500 ipsec/udp traffice

How do I check to see it the PA is dropping port 4500 traffic?


Accepted Solutions
Highlighted
L7 Applicator

NO, It's not blocked by PAN. Your VPN gateway ( SonicWALL) is not accepting the IKE messages. The issue is not related to PAN.

Hope this helps.

Thanks

View solution in original post


All Replies
Highlighted
L6 Presenter

Hello Infotech,

There are mulitple ways to do so.

1. Packet capture with proper source/destination IP/Port.

2. From Traffic log

3. show session all filter source <> destination <> source-port <> and destination-port <>

Let me know if you need additional information.

Regards,

Hardik Shah

Highlighted
L4 Transporter

I see no port 4500 traffic at all, I don't see anything being blocked to or from port 4500

Highlighted
L6 Presenter

Can you do packet capture on firewall to make sure, no other device is blocking traffic for port 4500 inbetween.

Highlighted
L4 Transporter

I did a packet capture and I see no 4500 traffic present, blocked or anything else. the source is also from a remote vendor in the internet. I am see the ike 500 traffice going out from the vpn device and nothing else

Highlighted
L6 Presenter

Hi Infotech,

It means PAN is not receiving traffic on port 4500.

Can you check on other end firewall if its sending any traffic on port 4500 ?

Regards,

Hardik Shah

Highlighted
L4 Transporter

So that means its not an issue on the PA but an issue outside in the internet or  the sender. The sender says that don't see any ike 500 traffice to respond too. I will see if I they can send some 4500 traffic

Highlighted
L4 Transporter

Can you also please check if you have any implicit deny rule configured at the bottom of the rule base on the PA. This at times may cause some unintended issues for traffic terminating on the device.

Highlighted
L4 Transporter

I have a clean up rule at the bottom but wouldn't it show up in the logs as dropped?

Highlighted
L6 Presenter

Hi Infotech,

Upload complete capture from PANW.  I think something in between is not allowing packets on both 500/4500.

Regards,

Hardik Shah

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!