<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion: Bring down IPsec tunnel manually in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-bring-down-ipsec-tunnel-manually/ta-p/533772</link>
    <description>&lt;P&gt;This Nominated Discussion Article is based on the post "&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/bring-down-ipsec-tunnel-manually/m-p/532958" target="_blank" rel="noopener"&gt;Bring Down IPsec Tunnel Manually&lt;/A&gt;&lt;/STRONG&gt;&lt;/FONT&gt;" by &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/229126"&gt;@j.nepomuceno&lt;/a&gt;&lt;/STRONG&gt; and responded to by &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&lt;/STRONG&gt; and &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/STRONG&gt; . Read on to see the discussion and solution!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I am troubleshooting an issue where I need to bring down the IPsec tunnel manually, what is the best way to do this in GUI or CLI?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on whether you want to bounce the tunnel or actually disable it, you have different options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following CLI commands will tear down the VPN tunnel (phase1 &amp;amp; phase2 respectively):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Phase 1&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; clear vpn ike-sa gateway &amp;lt;gw-name&amp;gt;​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Phase 2&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; clear vpn ipsec-sa tunnel &amp;lt;tunnel-name&amp;gt;​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Follow these steps to clear (bounce) a tunnel using the GUI:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Phase 1
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Goto Network &amp;gt; IPsec&lt;/STRONG&gt; tunnels and select your tunnel&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;IKE-Info&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;At the bottom, click the action you want (Refresh or Restart)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1678370189717.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48583i54A51D1BC0488526/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_0-1678370189717.png" alt="kiwi_0-1678370189717.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Phase 2
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Goto Network &amp;gt; IPsec&lt;/STRONG&gt; tunnels and select your tunnel&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Tunnel-Info&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;At the bottom, click the action you want (Refresh or Restart)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_1-1678370393811.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48584i39596BF0B2CD3A42/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_1-1678370393811.png" alt="kiwi_1-1678370393811.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Instead of bouncing, you can also choose to &lt;STRONG&gt;disable/enable&lt;/STRONG&gt; IKE gateways or IPsec tunnels.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Enable/Disable an IKE Gateway
&lt;UL&gt;
&lt;LI&gt;Go to Network
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&amp;gt; Network Profiles &amp;gt; IKE Gateways and select the gateway in question.&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;Click Enable/Disable at the bottom of the screen&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_2-1678370792561.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48585iA0973FB4CB8AFDA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_2-1678370792561.png" alt="kiwi_2-1678370792561.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Enable/Disable an IPsec tunnel
&lt;UL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;Network&lt;/STRONG&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;gt; IPSec Tunnels&lt;/STRONG&gt; and select the tunnel in question&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Enable/Disable&lt;/STRONG&gt; at the bottom of the screen&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_3-1678371019353.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48586i66C0900DA02858B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_3-1678371019353.png" alt="kiwi_3-1678371019353.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;For more information:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVGCA0" target="_blank" rel="noopener"&gt;How to check Status, Clear, Restore, and Monitor an IPSEC VPN Tunnel&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/set-up-tunnel-monitoring/enable-or-disable-an-ike-gateway-or-ipsec-tunnel" target="_blank" rel="noopener"&gt;Enable, Disable, Refresh, or Restart an IKE Gateway or IPSec Tunnel&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank" rel="noopener"&gt;How to Troubleshoot IPSec VPN connectivity issues&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 05 Nov 2024 01:40:46 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2024-11-05T01:40:46Z</dc:date>
    <item>
      <title>Nominated Discussion: Bring down IPsec tunnel manually</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-bring-down-ipsec-tunnel-manually/ta-p/533772</link>
      <description>&lt;P&gt;This Nominated Discussion Article is based on the post "&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/bring-down-ipsec-tunnel-manually/m-p/532958" target="_blank" rel="noopener"&gt;Bring Down IPsec Tunnel Manually&lt;/A&gt;&lt;/STRONG&gt;&lt;/FONT&gt;" by &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/229126"&gt;@j.nepomuceno&lt;/a&gt;&lt;/STRONG&gt; and responded to by &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&lt;/STRONG&gt; and &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/STRONG&gt; . Read on to see the discussion and solution!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I am troubleshooting an issue where I need to bring down the IPsec tunnel manually, what is the best way to do this in GUI or CLI?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depending on whether you want to bounce the tunnel or actually disable it, you have different options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The following CLI commands will tear down the VPN tunnel (phase1 &amp;amp; phase2 respectively):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Phase 1&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; clear vpn ike-sa gateway &amp;lt;gw-name&amp;gt;​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Phase 2&lt;BR /&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; clear vpn ipsec-sa tunnel &amp;lt;tunnel-name&amp;gt;​&lt;/LI-CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Follow these steps to clear (bounce) a tunnel using the GUI:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Phase 1
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Goto Network &amp;gt; IPsec&lt;/STRONG&gt; tunnels and select your tunnel&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;IKE-Info&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;At the bottom, click the action you want (Refresh or Restart)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1678370189717.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48583i54A51D1BC0488526/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_0-1678370189717.png" alt="kiwi_0-1678370189717.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Phase 2
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Goto Network &amp;gt; IPsec&lt;/STRONG&gt; tunnels and select your tunnel&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Tunnel-Info&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;At the bottom, click the action you want (Refresh or Restart)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_1-1678370393811.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48584i39596BF0B2CD3A42/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_1-1678370393811.png" alt="kiwi_1-1678370393811.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Instead of bouncing, you can also choose to &lt;STRONG&gt;disable/enable&lt;/STRONG&gt; IKE gateways or IPsec tunnels.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Enable/Disable an IKE Gateway
&lt;UL&gt;
&lt;LI&gt;Go to Network
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&amp;gt; Network Profiles &amp;gt; IKE Gateways and select the gateway in question.&lt;/DIV&gt;
&lt;DIV style="display: inline;"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;Click Enable/Disable at the bottom of the screen&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_2-1678370792561.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48585iA0973FB4CB8AFDA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_2-1678370792561.png" alt="kiwi_2-1678370792561.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Enable/Disable an IPsec tunnel
&lt;UL&gt;
&lt;LI&gt;Go to &lt;STRONG&gt;Network&lt;/STRONG&gt;
&lt;DIV style="display: inline;"&gt;
&lt;DIV style="display: inline;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;gt; IPSec Tunnels&lt;/STRONG&gt; and select the tunnel in question&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Enable/Disable&lt;/STRONG&gt; at the bottom of the screen&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_3-1678371019353.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48586i66C0900DA02858B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="kiwi_3-1678371019353.png" alt="kiwi_3-1678371019353.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;For more information:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVGCA0" target="_blank" rel="noopener"&gt;How to check Status, Clear, Restore, and Monitor an IPSEC VPN Tunnel&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/set-up-tunnel-monitoring/enable-or-disable-an-ike-gateway-or-ipsec-tunnel" target="_blank" rel="noopener"&gt;Enable, Disable, Refresh, or Restart an IKE Gateway or IPSec Tunnel&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank" rel="noopener"&gt;How to Troubleshoot IPSec VPN connectivity issues&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 05 Nov 2024 01:40:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-bring-down-ipsec-tunnel-manually/ta-p/533772</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-11-05T01:40:46Z</dc:date>
    </item>
  </channel>
</rss>

