Vigyata.AI
Is this your channel?

#paloaltofirewalltraining | Day 41 | Configure Ikev2 with Wireshek Detailed analysis

1.4K views· 36 likes· 14:07· Jul 13, 2025

🛍️ Products Mentioned (2)

Join this channel to get access to perks: https://www.youtube.com/channel/UCBujQdd5rBRg7n70vy7YmAQ/join Please checkout my new video on Configure Ikev2 with Wireshek Detailed analysis. If you like this video give it a thumps up and subscribe my channel for more video. Have any question put it on comment section Recommend Video https://youtu.be/8ZnpOhpVvBo Recommend Link (Playlist for EVE-NG LAB Setup) https://www.youtube.com/playlist?list=PLaUiizP3D7fPMmUQqS5QKX_FVSoMP68Z5 Palo Alto Certification information URL: https://www.paloaltonetworks.com/services/education For Palo Alto Documentation https://docs.paloaltonetworks.com/ Please follow me Instagram : https://www.instagram.com/bikashtech Twitter : https://twitter.com/Bikashshaw82 E-mail ID : bikashshaw261@gmail.com #Paloaltotraining ##bikashtech #paloaltofirewalltraining #paloaltonetworks #paloaltotraining #paloaltovpn #vpn #ike #ipsec

About This Video

Hello friends, welcome back—this is Day 41 of my PCNSA Palo Alto series. In this session I’m showing you how to configure an IKEv2 site-to-site IPsec VPN and, more importantly, how to validate what’s really happening using a Wireshark capture. I’m using the same lab topology we used for IKEv1, and I’ll clearly tell you what changes are required for IKEv2 (honestly, it’s just one or two key options). We go step-by-step: Phase 1 (IKE Crypto policy), Phase 2 (IPsec Crypto), IKE Gateway settings (peer IP, pre-shared key, local interface 1/2), and IKE version selection as v2. After the config, I commit on both firewalls and then I capture traffic on the outside interface to analyze the negotiation. In Wireshark, I show you how many messages are exchanged during tunnel formation and what is clear text vs encrypted. My key takeaway: IKEv2 completes negotiation faster—first two messages are clear text and after that it becomes encrypted, and the full tunnel establishment happens in fewer total messages compared to IKEv1. Finally, I verify the tunnel status in the Palo Alto UI (Network > IPsec), check IKEv2 mode, and confirm encaps/decaps counters while doing ping tests both ways between the subnets.

Frequently Asked Questions

🎬 More from Bikash's Tech