Thursday, September 27, 2018

Ikev2 Site to Site VPN on a Palo Alto firewall towards a Cisco ASA

Hi everyone,

Has anyone here ever setup a IKEV2 site to site vpn between a Palo Alo firewall and a Cisco ASA.

I was just working with a company at setting this up. I manage the Cisco ASA and they manage the Palo Alto. I was unable to establish a successful site to site vpn using ikev2. Once we moved it to ikev1 it came up instantly.

I already have many ikev2 vpns running on my ASA to other sites successfully but none of them are to Palo Alto firewalls.

The network guys from the company I was working with told me that with Palo Alto, you keed to put in a ikev1 pre-shared key along with the remote and local authentication keys for ikev2...

I found it strange that the Palo Alto would need any ikev1 configuration if you are trying to use ikev2 as that would defeat the purpose really. Can anyone clarify what is required to setup a IKEV2 site to site vpn on a Palo Alto firewall. I have done some research but everything I find is just setting up ikev1 from what I can see.

Thanks in advance..



No comments:

Post a Comment