<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intermittent IPsec connection in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/intermittent-ipsec-connection/m-p/1261085#M7079</link>
    <description>&lt;P&gt;Continuous rekey can be caused by ProxyID(s) (encryption domain, TS) not matching.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have&amp;nbsp;10.125.22.36/32 and&amp;nbsp;192.168.155.11/32 (and only this single one) at both sides?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Aug 2026 09:40:31 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2026-08-05T09:40:31Z</dc:date>
    <item>
      <title>Intermittent IPsec connection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/intermittent-ipsec-connection/m-p/1261059#M7078</link>
      <description>&lt;P&gt;We recently setup IPsec tunnel between PA-1410 and 3rd party device. We can see the tunnel is up, but when testing ping between endpoint on our side to endpoint on the peer's side there are frequents request timed out.&lt;BR /&gt;&lt;BR /&gt;Our configuration for IKE crypto using sha256, aes-256-cbc, DH group 19, lifetime 24 hours. For IPsec crypto we use sha256, aes-256-cbc, DH group 19 and key lifetime 1 hours. Our local IP is&amp;nbsp;&lt;STRONG&gt;10.121.0.78&lt;/STRONG&gt; and peer IP &lt;STRONG&gt;10.250.30.50&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From traffic log there are no packet drop, even packet capture from tunnel interface and the endpoint IP for destination doesn't show any packet drop.&lt;/P&gt;
&lt;P&gt;I have collected the debug using these following commands:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;debug ike global on debug&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;debug ike pcap on&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On ikemgr.log I have found that there is frequent&amp;nbsp;IPSEC KEY LIFETIME EXPIRED, even happened only a few seconds. From the system log, I didn't found tunnel down or tunnel up on a frequent basis. But, what I found weird is that IPSEC KEY LIFETIME EXPIRED is happened frequently.&lt;BR /&gt;Below is the example of the log&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [DEBG]: 10.86.51.3[500] - 10.86.51.1[500]:(nil) 1 times of 80 bytes message will be sent over socket 1025
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [PNTF]: {    4:   27}: ====&amp;gt; IPSEC KEY LIFETIME EXPIRED; tunnel ALTO-IPSEC-TUNNEL-DRC &amp;lt;====
2026/08/04 15:18:12                                                       ====&amp;gt; Expired SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0xFC61DEB1/0x9AD641EC &amp;lt;====
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [PNTF]: {    4:   27}: ====&amp;gt; IKEv2 CHILD SA DELETED AS RESPONDER, non-rekey; tunnel ALTO-IPSEC-TUNNEL-DRC &amp;lt;====
2026/08/04 15:18:12                                                       ====&amp;gt; Deleted SA: 10.121.0.78[500]-10.250.30.50[500] message id:0x00008536, SPI:0xFC61DEB1/0x9AD641EC parent SN:10069 &amp;lt;====
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [INFO]: {    4:     }: ikev2_request_initiator_start: SA state ESTABLISHED type 3 caller ikev2_child_delete
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [INFO]: {    4:     }: IKEv2 INFO transmit: gateway Alto-DRC, message_id: 0x00008535, type 3 SA state ESTABLISHED
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [DEBG]: 10.121.0.78[500] - 10.250.30.50[500]:(nil) 1 times of 80 bytes message will be sent over socket 1024
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [PNTF]: {    4:   27}: ====&amp;gt; IPSEC KEY DELETED; tunnel ALTO-IPSEC-TUNNEL-DRC &amp;lt;====
2026/08/04 15:18:12                                                       ====&amp;gt; Deleted SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0xFC61DEB1/0x9AD641EC &amp;lt;====
2026/08/04 15:18:12 2026-08-04 15:18:12.000 +0700  [INFO]: {    4:   27}: SADB_DELETE proto=255 src=10.250.30.50[0] dst=10.121.0.78[0] ESP spi=0xFC61DEB1
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: processing isakmp packet
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: ===
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: 80 bytes message received from 10.250.30.50
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    4:     }: [IKE Initiator] response message_id 34101 expected 34101
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    4:     }: response exch type 37
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    4:     }: update response message_id 0x8535
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [INFO]: {    4:     }: received DELETE payload, protocol ESP, num of SPI: 1 IKE SA state ESTABLISHED
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [INFO]: {    4:     }: delete proto ESP spi 0x9AD641EC
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [PWRN]: {    4:     }: can't find sa for proto ESP spi 0x9AD641EC
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: processing isakmp packet
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: ===
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: 80 bytes message received from 10.86.51.1
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    1:     }: [IKE Initiator] response message_id 2818 expected 2818
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    1:     }: response exch type 37
2026/08/04 15:18:12 2026-08-04 15:18:12.003 +0700  [DEBG]: {    1:     }: update response message_id 0xb02
2026/08/04 15:18:13 2026-08-04 15:18:13.000 +0700  [PNTF]: {    4:   27}: ====&amp;gt; IPSEC KEY LIFETIME EXPIRED; tunnel ALTO-IPSEC-TUNNEL-DRC &amp;lt;====
2026/08/04 15:18:13                                                       ====&amp;gt; Expired SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0x9DC44DCA/0x9AD6423B &amp;lt;====

2026/08/04 15:18:13 2026-08-04 15:18:13.358 +0700  [DEBG]: processing isakmp packet
2026/08/04 15:18:13 2026-08-04 15:18:13.358 +0700  [DEBG]: ===
2026/08/04 15:18:13 2026-08-04 15:18:13.358 +0700  [DEBG]: 272 bytes message received from 10.250.30.50
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:     }: [IKE Responder] request message_id 34105 expected 34105
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:     }: request exch type 36
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:     }: update request message_id 0x8539
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: Parse Proposal: proposal #1 len=48
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [PNTF]: {    4:     }: ====&amp;gt; IKEv2 CHILD SA NEGOTIATION STARTED AS RESPONDER, non-rekey; gateway Alto-DRC &amp;lt;====
2026/08/04 15:18:13                                                       ====&amp;gt; Initiated SA: 10.121.0.78[500]-10.250.30.50[500] message id:0x00008539 parent SN:10069 &amp;lt;====
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [WARN]: {    4:   27}: selector ALTO-IPSEC-TUNNEL-DRC src is ambiguous, using the first one of the expanded addresses
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [WARN]: {    4:   27}: selector ALTO-IPSEC-TUNNEL-DRC dst is ambiguous, using the first one of the expanded addresses
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: TS matching for configured selector ALTO-IPSEC-TUNNEL-DRC 0.0.0.0[0]/0-0.0.0.0[0]/0 proto 0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: .. check local TS (num 1, TS0 is not specific) against selector 0:0.0.0.0[0]/0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {     :   27}: ... TS 0: 10.125.22.36-&amp;gt;10.125.22.36[0-65535](ts) is used as it is narrower
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: ... result: local TS &amp;lt; 0.0.0.0[0]/0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: .. check remote TS (num 1, TS0 is not specific) against selector 0:0.0.0.0[0]/0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {     :   27}: ... TS 0: 192.168.155.11-&amp;gt;192.168.155.11[0-65535](ts) is used as it is narrower
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: ... result: remote TS &amp;lt; 0.0.0.0[0]/0
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: TS matching result: TS_l match(&amp;lt;), TS_r match(&amp;lt;) *
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: selector chosen ALTO-IPSEC-TUNNEL-DRC: tid 27
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: see whether there's matching transform
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}: found same ID(12,12). compare attributes
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: ikev2_compare_attributes:   Matched ENCR kenlen 256
2026/08/04 15:18:13 2026-08-04 15:18:13.359 +0700  [DEBG]: {    4:   27}:  Matched ENCR: my  [12], peer  [12]
2026/08/04 15:18:13 OK; advance to next of my transform type

2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [PNTF]: {    4:   27}: ====&amp;gt; IPSEC KEY LIFETIME EXPIRED; tunnel ALTO-IPSEC-TUNNEL-DRC &amp;lt;====
2026/08/04 15:18:15                                                       ====&amp;gt; Expired SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0x8C1EB246/0x9AD64247 &amp;lt;====
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [PNTF]: {    4:   27}: ====&amp;gt; IKEv2 CHILD SA DELETED AS RESPONDER, non-rekey; tunnel ALTO-IPSEC-TUNNEL-DRC &amp;lt;====
2026/08/04 15:18:15                                                       ====&amp;gt; Deleted SA: 10.121.0.78[500]-10.250.30.50[500] message id:0x00008538, SPI:0x8C1EB246/0x9AD64247 parent SN:10069 &amp;lt;====
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [INFO]: {    4:     }: ikev2_request_initiator_start: SA state ESTABLISHED type 3 caller ikev2_child_delete
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [INFO]: {    4:     }: IKEv2 INFO transmit: gateway Alto-DRC, message_id: 0x00008537, type 3 SA state ESTABLISHED
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [DEBG]: 10.121.0.78[500] - 10.250.30.50[500]:(nil) 1 times of 80 bytes message will be sent over socket 1024
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [PNTF]: {    4:   27}: ====&amp;gt; IPSEC KEY DELETED; tunnel ALTO-IPSEC-TUNNEL-DRC &amp;lt;====
2026/08/04 15:18:15                                                       ====&amp;gt; Deleted SA: 10.121.0.78[500]-10.250.30.50[500] SPI:0x8C1EB246/0x9AD64247 &amp;lt;====
2026/08/04 15:18:15 2026-08-04 15:18:15.000 +0700  [INFO]: {    4:   27}: SADB_DELETE proto=255 src=10.250.30.50[0] dst=10.121.0.78[0] ESP spi=0x8C1EB246
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: processing isakmp packet
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: ===
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: 80 bytes message received from 10.250.30.50
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: {    4:     }: [IKE Initiator] response message_id 34103 expected 34103
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: {    4:     }: response exch type 37
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [DEBG]: {    4:     }: update response message_id 0x8537
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [INFO]: {    4:     }: received DELETE payload, protocol ESP, num of SPI: 1 IKE SA state ESTABLISHED
2026/08/04 15:18:15 2026-08-04 15:18:15.003 +0700  [INFO]: {    4:     }: delete proto ESP spi 0x9AD64247&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;I don't know if this is the reason why intermittent connection between our side and peer side.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 07:18:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/intermittent-ipsec-connection/m-p/1261059#M7078</guid>
      <dc:creator>i.rifai</dc:creator>
      <dc:date>2026-08-05T07:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent IPsec connection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/intermittent-ipsec-connection/m-p/1261085#M7079</link>
      <description>&lt;P&gt;Continuous rekey can be caused by ProxyID(s) (encryption domain, TS) not matching.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have&amp;nbsp;10.125.22.36/32 and&amp;nbsp;192.168.155.11/32 (and only this single one) at both sides?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 09:40:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/intermittent-ipsec-connection/m-p/1261085#M7079</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2026-08-05T09:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent IPsec connection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/intermittent-ipsec-connection/m-p/1261090#M7082</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;, thank you for pointing this out. We have tried to add remote IP 192.168.155.11/32 for Proxy ID and after that we did not found request timed out when pinging.&lt;BR /&gt;May I know why we need to setup Proxy ID in this case? I'm not really understand about Proxy ID, all I know is we need to use Proxy ID is the peer is using policy-based VPN.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Moch. Imam Rifai&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 10:46:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/intermittent-ipsec-connection/m-p/1261090#M7082</guid>
      <dc:creator>i.rifai</dc:creator>
      <dc:date>2026-08-05T10:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent IPsec connection</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/intermittent-ipsec-connection/m-p/1261092#M7083</link>
      <description>&lt;P&gt;Do you manage other side to check what subnets are in VPN policy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can switch Palo side to passive mode (in IKE gateway settings), initiate traffic from peer side so that Palo would be responder and then you see in logs what TS (ProxyID) peer side has configured. This allows to match Palo side to peer side.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2026 11:38:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/intermittent-ipsec-connection/m-p/1261092#M7083</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2026-08-05T11:38:53Z</dc:date>
    </item>
  </channel>
</rss>

