<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto  Site to Site IPsec VPN went down in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-site-to-site-ipsec-vpn-went-down/m-p/540197#M1182</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've setup Site to Site IPsec VPN between Palo Alto Firewalls. The tunnel was up and working but it went down after some time.&lt;/P&gt;
&lt;P&gt;Look like the tunnel went down because there is no traffic passing through the tunnel. Everytime we&amp;nbsp;need to trigger IPsec tunnel by using &amp;gt;&lt;EM&gt;test vpn ike-sa gateway &lt;/EM&gt;to bring up.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How can we configure the tunnel to be up all the time even there is no traffic passing through the tunnel?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do we need to enable tunnel-monitor ? Are there any other ways to make the tunnel up all the time?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are using IKEv2 preferred mode and we already enabled DPD for Ikev1 and liveliness check for ikev2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help suggest.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Apr 2023 13:24:36 GMT</pubDate>
    <dc:creator>EvanRaci</dc:creator>
    <dc:date>2023-04-26T13:24:36Z</dc:date>
    <item>
      <title>Palo Alto  Site to Site IPsec VPN went down</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-site-to-site-ipsec-vpn-went-down/m-p/540197#M1182</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've setup Site to Site IPsec VPN between Palo Alto Firewalls. The tunnel was up and working but it went down after some time.&lt;/P&gt;
&lt;P&gt;Look like the tunnel went down because there is no traffic passing through the tunnel. Everytime we&amp;nbsp;need to trigger IPsec tunnel by using &amp;gt;&lt;EM&gt;test vpn ike-sa gateway &lt;/EM&gt;to bring up.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How can we configure the tunnel to be up all the time even there is no traffic passing through the tunnel?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do we need to enable tunnel-monitor ? Are there any other ways to make the tunnel up all the time?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are using IKEv2 preferred mode and we already enabled DPD for Ikev1 and liveliness check for ikev2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please help suggest.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 13:24:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-site-to-site-ipsec-vpn-went-down/m-p/540197#M1182</guid>
      <dc:creator>EvanRaci</dc:creator>
      <dc:date>2023-04-26T13:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  Site to Site IPsec VPN went down</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-site-to-site-ipsec-vpn-went-down/m-p/540224#M1183</link>
      <description>&lt;P&gt;Either tunnel monitor or path monitoring inside virtual router.&lt;/P&gt;
&lt;P&gt;Without them tunnel will not be renegotiated if no interesting traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 18:08:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-site-to-site-ipsec-vpn-went-down/m-p/540224#M1183</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-04-26T18:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  Site to Site IPsec VPN went down</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-site-to-site-ipsec-vpn-went-down/m-p/544747#M1386</link>
      <description>&lt;P&gt;After Checking Config , the issue is DH value mismatch. Change both side to same DH Value and now working fine&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 06:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/palo-alto-site-to-site-ipsec-vpn-went-down/m-p/544747#M1386</guid>
      <dc:creator>EvanRaci</dc:creator>
      <dc:date>2023-06-05T06:25:08Z</dc:date>
    </item>
  </channel>
</rss>

