<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No DPD message while peer tunnel is down in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/no-dpd-message-while-peer-tunnel-is-down/m-p/534386#M1019</link>
    <description>&lt;UL type="disc"&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;Problems with IPSEC VPN tunnel between PAN FW PLWALFWxx and the BlueCoat datacenters (Amsterdam, Frankfurt)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;DPD does not seem to work.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;Extra Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;PLWALFW = PANOS 10.2.2.h2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;INTERNET FW = PANOS 8.1.x&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;We have IPSEC tunnels between our PAN FW and BlueCoat Datacenters. BlueCoat were doing maintenance on their datapods last week.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL type="disc"&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;DPD on our PLWALFW did NOT kick in correctly. After tunnel down, IKE PHASE2 is being done for 7 or 8 hours without result. After that an IKE PHASE 1 is done and the tunnel comes back up correctly.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;BlueCoat support tells us that all other customers automatically RESTART the SAME tunnel and that the tunnel is automatically back up. These customers seemt o do IKE PHASE1 immediately after they have seen a problem with the tunnel. This same behaviour we see on our INTERNET FW, no IKE PHASE2, but IKE PHASE 1 immediately.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;We suspect a problem in PANOS10.2.2.h2.(pl confirm)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;We see the same behaviour on PLJELFWxx and FREDDFWxx. They are all in PANOS 10.2.2.h2.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;I have discussed this with BlueCoat Support. All customers fail over correctly to a different POD in the same datacenter, except our FW, who starts doing IKE PHASE2, which should not be the case.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;Please let us know what we need to do.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 14 Mar 2023 20:07:51 GMT</pubDate>
    <dc:creator>tusharbanik</dc:creator>
    <dc:date>2023-03-14T20:07:51Z</dc:date>
    <item>
      <title>No DPD message while peer tunnel is down</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/no-dpd-message-while-peer-tunnel-is-down/m-p/534386#M1019</link>
      <description>&lt;UL type="disc"&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;Problems with IPSEC VPN tunnel between PAN FW PLWALFWxx and the BlueCoat datacenters (Amsterdam, Frankfurt)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;DPD does not seem to work.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;Extra Information:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;PLWALFW = PANOS 10.2.2.h2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;INTERNET FW = PANOS 8.1.x&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;We have IPSEC tunnels between our PAN FW and BlueCoat Datacenters. BlueCoat were doing maintenance on their datapods last week.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL type="disc"&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;DPD on our PLWALFW did NOT kick in correctly. After tunnel down, IKE PHASE2 is being done for 7 or 8 hours without result. After that an IKE PHASE 1 is done and the tunnel comes back up correctly.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;BlueCoat support tells us that all other customers automatically RESTART the SAME tunnel and that the tunnel is automatically back up. These customers seemt o do IKE PHASE1 immediately after they have seen a problem with the tunnel. This same behaviour we see on our INTERNET FW, no IKE PHASE2, but IKE PHASE 1 immediately.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;We suspect a problem in PANOS10.2.2.h2.(pl confirm)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="x_xxxxmsolistparagraph"&gt;&lt;SPAN&gt;We see the same behaviour on PLJELFWxx and FREDDFWxx. They are all in PANOS 10.2.2.h2.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;I have discussed this with BlueCoat Support. All customers fail over correctly to a different POD in the same datacenter, except our FW, who starts doing IKE PHASE2, which should not be the case.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="x_xxxxmsonormal"&gt;&lt;SPAN&gt;Please let us know what we need to do.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 14 Mar 2023 20:07:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/no-dpd-message-while-peer-tunnel-is-down/m-p/534386#M1019</guid>
      <dc:creator>tusharbanik</dc:creator>
      <dc:date>2023-03-14T20:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: No DPD message while peer tunnel is down</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/no-dpd-message-while-peer-tunnel-is-down/m-p/534388#M1020</link>
      <description>&lt;P&gt;Attached the screenshot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 20:11:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/no-dpd-message-while-peer-tunnel-is-down/m-p/534388#M1020</guid>
      <dc:creator>tusharbanik</dc:creator>
      <dc:date>2023-03-14T20:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: No DPD message while peer tunnel is down</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/no-dpd-message-while-peer-tunnel-is-down/m-p/534394#M1021</link>
      <description>&lt;P&gt;Anyone?? need suggestion.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 21:18:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/no-dpd-message-while-peer-tunnel-is-down/m-p/534394#M1021</guid>
      <dc:creator>tusharbanik</dc:creator>
      <dc:date>2023-03-14T21:18:11Z</dc:date>
    </item>
  </channel>
</rss>

