How to make Palo Alto Networks firewalls Responder-only in an IPSec tunnel

How to make Palo Alto Networks firewalls Responder-only in an IPSec tunnel

Created On 09/25/18 18:00 PM - Last Modified 06/14/23 07:18 AM


The IKE Initiator is the device initiating the IKE VPN tunnel negotiation request and the IKE Responder is the device receiving the request to establish an IKE VPN tunnel. Using a simple check box, we can make the firewall act as a 'Responder-only' in the negotiation. With this option enabled, the firewall responds to incoming connection negotiations as it would normally do, but it will no longer initiate outgoing negotiations. 


How to enable responder-only setting

To enable this setting, navigate to Network > network profiles > IKE Gateways and open the IKE Gateway relevant to the IPSEC tunnel. Then access the 'Advanced Options' tab and check the box for 'Enable Passive Mode'.


Responder.JPGCommit is necessary to enable this change


See Also:

IPsec resources list


owner: ansharma

  • Print
  • Copy Link

Choose Language