Solved

Microsoft Azure Site-to-Site VPN with Palo Alto

Posted on 2016-10-27
3
345 Views
Last Modified: 2016-11-03
Hello Experts,

I'm trying to build a Microsoft Azure site-to-site vpn where the local end device is a Palo Alto Networks firewall.

I have been trying to follow the example shown here ....

https://live.paloaltonetworks.com/t5/Integration-Articles/Configuring-IKEv2-VPN-for-Microsoft-Azure-Environment/ta-p/60340

But I'm not having any luck establishing a connection.

Has anyone successfully established a connection with a Palo Alto firewall?

Kind regards

Carlton
0
Comment
Question by:Member_2_7966113
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 1

Author Comment

by:Member_2_7966113
ID: 41864088
Hello Experts,

I have managed to establish a connection in Microsoft Azure, see image, however the Tunnel won't come up in Palo Alto, but IKE is up

( description contains 'IKEv2 child SA negotiation is failed as initiator, non-rekey. Failed SA: 64.187.124.5[500]-13.89.33.31[500] message id:0x00000107. Error code 111' )

Can someone please shed some light on the problem?

Cheers
azure.png
paloalto.png
0
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 500 total points
ID: 41864699
Check the routing table of devices between the firewalls.  A route table entry may need to be added or removed to provide proper network connectivity.
0
 
LVL 1

Author Closing Comment

by:Member_2_7966113
ID: 41872919
Hi Istvan, Thanks for responding

Cheers
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A look into Log Analysis and Effective Critical Alerting.
On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question