<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connect AP150W to thrid-Party IPSec-Gateway in Hero Discussions</title>
    <link>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78860#M51</link>
    <description>&lt;P&gt;Hi Heroes,&lt;/P&gt;&lt;P&gt;has anyone already managed to connect an AP150W to a third-Party Firewall with IPSec? I always get the error “Aggressive Mode ID not matching” on conecntrator side. I tried with Watchguard and Sophos Firewalls - same error for both manufactorers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
    <pubDate>Mon, 12 Oct 2020 16:10:44 GMT</pubDate>
    <dc:creator>Marco_Lorenz</dc:creator>
    <dc:date>2020-10-12T16:10:44Z</dc:date>
    <item>
      <title>Connect AP150W to thrid-Party IPSec-Gateway</title>
      <link>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78860#M51</link>
      <description>&lt;P&gt;Hi Heroes,&lt;/P&gt;&lt;P&gt;has anyone already managed to connect an AP150W to a third-Party Firewall with IPSec? I always get the error “Aggressive Mode ID not matching” on conecntrator side. I tried with Watchguard and Sophos Firewalls - same error for both manufactorers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 16:10:44 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78860#M51</guid>
      <dc:creator>Marco_Lorenz</dc:creator>
      <dc:date>2020-10-12T16:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Connect AP150W to thrid-Party IPSec-Gateway</title>
      <link>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78861#M52</link>
      <description>&lt;P&gt;Marco,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I never tried this but the error messages seems to indicate an issue in the IPSec phase1.&lt;/P&gt;&lt;P&gt;Try to&amp;nbsp;disable the “aggressive mode”.&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 15:56:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78861#M52</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-10-29T15:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Connect AP150W to thrid-Party IPSec-Gateway</title>
      <link>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78862#M53</link>
      <description>&lt;P&gt;Sorry to bump that thread but has anyone managed to get this working? Either IPSec or GRE? Some of our customers want to have setups which are not bridging the traffic at the access point thus a IPSec/GRE tunnel to the customers firewall would be way better.&lt;/P&gt;&lt;P&gt;I have played around trying to establish a GRE tunnel between my AP410C and a FortiGate but I wasn’t succeeding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 02:01:10 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78862#M53</guid>
      <dc:creator>CWurm</dc:creator>
      <dc:date>2021-01-25T02:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Connect AP150W to thrid-Party IPSec-Gateway</title>
      <link>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78863#M54</link>
      <description>&lt;P&gt;I had to go through the same process. I could not find a way to tunnel traffic&amp;nbsp;from a user profile to external. Neither XIQ-AP nor IPsec-GW. Documentation here is below 0.&lt;/P&gt;&lt;P&gt;There are a lot of configuraton paramters but not all are part of a documentation...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;br&lt;/P&gt;&lt;P&gt;Volker&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 20:24:14 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78863#M54</guid>
      <dc:creator>Volker_Kull</dc:creator>
      <dc:date>2021-02-26T20:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Connect AP150W to thrid-Party IPSec-Gateway</title>
      <link>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78864#M55</link>
      <description>&lt;P&gt;Hi Volker,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have managed to get IPSec tunneling to work between two XIQ APs but thats not really useful in my opinion &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I can’t tell our customers to keep one AP in the central DC to have this AP as a tunnel endpoint.&lt;/P&gt;&lt;P&gt;But I totally agree. Documentation on this topic is very bad.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 20:29:38 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78864#M55</guid>
      <dc:creator>CWurm</dc:creator>
      <dc:date>2021-02-26T20:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Connect AP150W to thrid-Party IPSec-Gateway</title>
      <link>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78865#M56</link>
      <description>&lt;P&gt;Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;trouble with IQEngine-based gear (cloud APs and XRs) is that they use IPSEC implementation that is just old. It only supports IKEv1 and is somewhat rigid with attributes etc.&lt;BR /&gt;There is work underway to upgrade IPSEC to modern standards, at which point you will be able to terminate tunnels on any decent GW, for instance XCC or VOSS FIGW, if that matters&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 23:14:58 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/hero-discussions/connect-ap150w-to-thrid-party-ipsec-gateway/m-p/78865#M56</guid>
      <dc:creator>AlexN</dc:creator>
      <dc:date>2021-04-09T23:14:58Z</dc:date>
    </item>
  </channel>
</rss>

