<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN Negotiation Issues in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-negotiation-issues/m-p/544151#M1366</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/251459"&gt;@Partner_Infra&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Am I understanding your question correctly:&lt;/P&gt;
&lt;P&gt;- You have multiple VPN tunnels&lt;/P&gt;
&lt;P&gt;- In some case your public Internet connection is going down and up again after some time&lt;/P&gt;
&lt;P&gt;- After the Internet line is restored most of the VPN tunnel are restored, but only one is not re-established and still show "red" status in GUI&lt;/P&gt;
&lt;P&gt;- When you execute the "test vpn" command tunnel is re-established successfully.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The majority of network devices will initiate VPN negotiation ONLY when they receive traffic that needs to be forwarded over the tunnel.&lt;/P&gt;
&lt;P&gt;From your explanation it seems that there is no traffic initiated/sourced from your internal network that will trigger VPN negotion. "test vpn" command is forcing the firewall to start VPN negotiation even if there is not actual traffic that will pass over the tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you just expect this tunnel to re-establish immediately, like the rest of the tunnel - it could be just that this tunnel is not used very often and and you need to wait longer for real traffic that it will initiate tunnel negotiation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 May 2023 12:02:00 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-05-31T12:02:00Z</dc:date>
    <item>
      <title>IPSec VPN Negotiation Issues</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-negotiation-issues/m-p/544077#M1362</link>
      <description>&lt;P&gt;Dear Members,&lt;/P&gt;
&lt;P&gt;Greeting to All!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Curranty, I'm using site to site multiple VPN configuration with Palo alto Firewall to different vendor site. All of the tunnel is working fine VPN ok.&lt;/P&gt;
&lt;P&gt;My main problem is inside of my firewall public internet down then coming to UP in case, Some of the tunnel is came to up and show green. But one of the tunnel status is still down even internet interface after UP. So, in case when I go to the CLI mode then type the following command the tunnel is came to UP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;test vpn ike-sa gateway IKE_Prod_V2&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Start time: May.31 10:16:15&lt;BR /&gt;Initiate 1 IKE SA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to clarify how can we solve for my current issues that we no need&amp;nbsp; to run without test vpn ike-sa gateway IKE_Prod_V2 command.&lt;/P&gt;
&lt;P&gt;Please kindly helps me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Pyie Phyo Htay.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 04:08:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-negotiation-issues/m-p/544077#M1362</guid>
      <dc:creator>Partner_Infra</dc:creator>
      <dc:date>2023-05-31T04:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN Negotiation Issues</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-negotiation-issues/m-p/544151#M1366</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/251459"&gt;@Partner_Infra&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Am I understanding your question correctly:&lt;/P&gt;
&lt;P&gt;- You have multiple VPN tunnels&lt;/P&gt;
&lt;P&gt;- In some case your public Internet connection is going down and up again after some time&lt;/P&gt;
&lt;P&gt;- After the Internet line is restored most of the VPN tunnel are restored, but only one is not re-established and still show "red" status in GUI&lt;/P&gt;
&lt;P&gt;- When you execute the "test vpn" command tunnel is re-established successfully.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The majority of network devices will initiate VPN negotiation ONLY when they receive traffic that needs to be forwarded over the tunnel.&lt;/P&gt;
&lt;P&gt;From your explanation it seems that there is no traffic initiated/sourced from your internal network that will trigger VPN negotion. "test vpn" command is forcing the firewall to start VPN negotiation even if there is not actual traffic that will pass over the tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you just expect this tunnel to re-establish immediately, like the rest of the tunnel - it could be just that this tunnel is not used very often and and you need to wait longer for real traffic that it will initiate tunnel negotiation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 12:02:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-vpn-negotiation-issues/m-p/544151#M1366</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-05-31T12:02:00Z</dc:date>
    </item>
  </channel>
</rss>

