Solved

Microsoft Azure Site-to-Site VPN with Palo Alto

Posted on 2016-10-27
  • Azure
  • VPN
  • Networking
  • Windows Networking
  • IPsec
  • +1
3
120 Views
Last Modified: 2016-11-03
Hello Experts,

I'm trying to build a Microsoft Azure site-to-site vpn where the local end device is a Palo Alto Networks firewall.

I have been trying to follow the example shown here ....

https://live.paloaltonetworks.com/t5/Integration-Articles/Configuring-IKEv2-VPN-for-Microsoft-Azure-Environment/ta-p/60340

But I'm not having any luck establishing a connection.

Has anyone successfully established a connection with a Palo Alto firewall?

Kind regards

Carlton
0
Comment
Question by:Member_2_7966113
  • 2
3 Comments
 

Author Comment

by:Member_2_7966113
ID: 41864088
Hello Experts,

I have managed to establish a connection in Microsoft Azure, see image, however the Tunnel won't come up in Palo Alto, but IKE is up

( description contains 'IKEv2 child SA negotiation is failed as initiator, non-rekey. Failed SA: 64.187.124.5[500]-13.89.33.31[500] message id:0x00000107. Error code 111' )

Can someone please shed some light on the problem?

Cheers
azure.png
paloalto.png
0
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 500 total points
ID: 41864699
Check the routing table of devices between the firewalls.  A route table entry may need to be added or removed to provide proper network connectivity.
0
 

Author Closing Comment

by:Member_2_7966113
ID: 41872919
Hi Istvan, Thanks for responding

Cheers
0

Featured Post

Superior storage. Superior surveillance.

WD Purple drives are built for 24/7, always-on, high-definition security systems. With support for up to 8 hard drives and 32 cameras, WD Purple drives are optimized for surveillance.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now