<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSEC_ESP port 50 Traffic even when IKE Phase-1 is not up in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-esp-port-50-traffic-even-when-ike-phase-1-is-not-up/m-p/597589#M3727</link>
    <description>&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;We are running into an issue, where we have 2 Palo Firewalls and we are trying toe establish S@S VPN between them. Both the tunnels are behind NAT devices and we do have NAT-T Enabled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;BR /&gt;&lt;SPAN&gt;We can see in IKE MGR.logs that the initiator is trying to reach out on 4500 after initial Port 500 traffic.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;BR /&gt;&lt;SPAN&gt;The issue we see is that there is "IPSEC-ESP" port 50 traffic even though the phase-1 is not coming up on Session Browser and if we try to clear the traffic the session ID changes but this traffic does not get cleared.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;BR /&gt;&lt;SPAN&gt;The issue this causes is that even if we clear VPN ike-sa and ipsec-sa tunnels from the firewall we are not seeing port 500 traffic being generated again when we try to initiate the tunnel using "test VPN" command.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;The only time we are trying to generate this traffic again is by rebooting the firewall completely. We are running PanOS-11.1.4-h2 on the firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Initially, we had a "Tunnel Monitoring" set. However, we cleared this, deleted the tunnel, and recreated we still see "IPSEC-ESP" port 50 traffic but no port 500 traffic was generated after a few initial packets.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Has anyone faced this issue? We do not see any timeouts or any other stating why the tunnel is not coming up.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2024 21:53:54 GMT</pubDate>
    <dc:creator>UtkarshKumar</dc:creator>
    <dc:date>2024-09-11T21:53:54Z</dc:date>
    <item>
      <title>IPSEC_ESP port 50 Traffic even when IKE Phase-1 is not up</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-esp-port-50-traffic-even-when-ike-phase-1-is-not-up/m-p/597589#M3727</link>
      <description>&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;We are running into an issue, where we have 2 Palo Firewalls and we are trying toe establish S@S VPN between them. Both the tunnels are behind NAT devices and we do have NAT-T Enabled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;BR /&gt;&lt;SPAN&gt;We can see in IKE MGR.logs that the initiator is trying to reach out on 4500 after initial Port 500 traffic.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;BR /&gt;&lt;SPAN&gt;The issue we see is that there is "IPSEC-ESP" port 50 traffic even though the phase-1 is not coming up on Session Browser and if we try to clear the traffic the session ID changes but this traffic does not get cleared.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;BR /&gt;&lt;SPAN&gt;The issue this causes is that even if we clear VPN ike-sa and ipsec-sa tunnels from the firewall we are not seeing port 500 traffic being generated again when we try to initiate the tunnel using "test VPN" command.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;The only time we are trying to generate this traffic again is by rebooting the firewall completely. We are running PanOS-11.1.4-h2 on the firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Initially, we had a "Tunnel Monitoring" set. However, we cleared this, deleted the tunnel, and recreated we still see "IPSEC-ESP" port 50 traffic but no port 500 traffic was generated after a few initial packets.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;Has anyone faced this issue? We do not see any timeouts or any other stating why the tunnel is not coming up.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="first:mt-0 last:mb-0" dir="ltr"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 21:53:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/ipsec-esp-port-50-traffic-even-when-ike-phase-1-is-not-up/m-p/597589#M3727</guid>
      <dc:creator>UtkarshKumar</dc:creator>
      <dc:date>2024-09-11T21:53:54Z</dc:date>
    </item>
  </channel>
</rss>

