- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
03-19-2024 11:01 PM
Hi Everybody,
We updated from 10.2.7 to 10.2.8 and had a lot of troubles with our Site-2-Site IKEv1, IKEv2 Prefered gateway connections. I'm not sure if the IKE Version is the root problem, but that was the pattern that was visible in the short time for this change.
Phase 1 came not up, initiated in both directions.
There are the msg in the logs:
Us-2-endpoint: 'IKE phase-1 negotiation is failed as responder, main mode. Failed SA:
Endpoint-2-us: the logs said always "Connection Timeout".
Sophos, FritzBox and Azure were the other endpoints, we were not able to etablish phase 1. After Downgrading to 10.2.7 everything worked, also with 10.2.7-h3 is everything working.
We did not seen in the traffic monitor any traffic for the phase1, although we otherwise saw this connection traffic in an intrazone (Untrust-2-Untrust) rule. With PANOS 10.2.7 and H3 it was visible again
Also without Zone Protection, the connection came not up, it was like something was blocking the connection, without generating logs.
I didn't find something in the release notes that point to this issue. Somebody else with this experience?
Happy firewalling
04-17-2024 03:03 AM
There are two NAT rules (destination-translation) for the Exchange2019 mail server, starting from version 1.2.8 they stopped working. They work for some time, then they are blocked, there is no information in the logs.
In version 1.2.9 the same thing.
04-23-2024 07:03 PM - edited 04-23-2024 07:04 PM
Thanks for providing valuable insight @FabioHufschmid ! If you ever have the time, please open up a support ticket and share details of your findings.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!