<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN tunnel getting disconnected. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-getting-disconnected/m-p/442591#M100117</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195574"&gt;@RPrasad3&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It could be a good idea to review and confirm if all the settings from both sides are the same (phase 1 &amp;amp; 2 lifetime amongst other things).&amp;nbsp; When there is a mismatch, the most common result is that the VPN stops functioning when one site's lifetime expires.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more verbose logging information you might want to increase logging level to 'debug' if the problem persists.&lt;/P&gt;
&lt;P&gt;Also check the system logs in the same time frame as they might highlight proposal, negotiation and/or other issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 21 Oct 2021 14:49:41 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2021-10-21T14:49:41Z</dc:date>
    <item>
      <title>IPSEC VPN tunnel getting disconnected.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-getting-disconnected/m-p/441912#M100047</link>
      <description>&lt;P&gt;&lt;SPAN&gt;IPSEC VPN tunnel got disconnected abruptly. We need to find out what could have caused this from the logs and adjust the VPN parameters accordingly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From logs i found this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;2021-10-15 03:35:11.814 +0000 [PNTF]: { 5: }: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS RESPONDER, (QUICK MODE) &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;====&amp;gt; Initiated SA: 10.67.2.4[500]-129.146.18.218[500] message id:0x7AEB6BD2 &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;2021-10-15 03:35:11.874 +0000 [PNTF]: { : 11}: ====&amp;gt; PHASE-2 NEGOTIATION SUCCEEDED AS RESPONDER, (QUICK MODE) &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;====&amp;gt; Established SA: 10.67.2.4[500]-129.146.18.218[500] message id:0x7AEB6BD2, SPI:0xFF264BC0/0x2E688DE1 &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;2021-10-15 03:35:11.874 +0000 [INFO]: { 5: 11}: SADB_UPDATE proto=255 129.146.18.218[500]=&amp;gt;10.67.2.4[500] ESP tunl spi 0xFF264BC0 auth=SHA1 enc=AES256/32 lifetime soft 3600/0 hard 3600/0&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;2021-10-15 03:35:11.874 +0000 [INFO]: { 5: 11}: SADB_ADD proto=255 10.67.2.4[500]=&amp;gt;129.146.18.218[500] ESP tunl spi 0x2E688DE1 auth=SHA1 enc=AES256/32 lifetime soft 3040/0 hard 3600/0&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;2021-10-15 03:35:11.874 +0000 [INFO]: { 5: 11}: IPsec-SA established: ESP/Tunnel 129.146.18.218[500]-&amp;gt;10.67.2.4[500] spi=4280699840(0xff264bc0)&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;2021-10-15 03:35:11.874 +0000 [PNTF]: { : 11}: ====&amp;gt; IPSEC KEY INSTALLATION SUCCEEDED &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;====&amp;gt; Installed SA: 10.67.2.4[500]-129.146.18.218[500] SPI:0xFF264BC0/0x2E688DE1 lifetime 3600 Sec lifesize unlimited &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;2021-10-15 03:35:11.875 +0000 [INFO]: { 5: 11}: SPI FF264BC0 inserted by IPSec responder, return 0 0.&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;2021-10-15 03:35:11.876 +0000 [INFO]: { 5: 11}: SPI AD383876 removed by keymodify, return 0 0.&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 03:35:11&lt;BR /&gt;2021-10-15 03:35:11.926 +0000 [PNTF]: { 4: }: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=c7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2021-10-15 05:40:14.000 +0000 [PNTF]: { : 3}: ====&amp;gt; IPSEC KEY LIFETIME EXPIRED &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 05:40:14&lt;BR /&gt;====&amp;gt; Expired SA: 10.67.2.4[500]-193.122.168.108[500] SPI:0x89D515AF/0x9B4C01EE &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 05:40:14&lt;BR /&gt;2021-10-15 05:40:14.000 +0000 [PNTF]: { : 3}: ====&amp;gt; IPSEC KEY DELETED &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 05:40:14&lt;BR /&gt;====&amp;gt; Deleted SA: 10.67.2.4[500]-193.122.168.108[500] SPI:0x89D515AF/0x9B4C01EE &amp;lt;====&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 05:40:14&lt;BR /&gt;2021-10-15 05:40:14.000 +0000 [INFO]: { 2: 3}: SADB_DELETE proto=0 src=10.67.2.4[500] dst=193.122.168.108[500] ESP spi=0x89D515AF&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 05:40:14&lt;BR /&gt;2021-10-15 05:40:14.003 +0000 [INFO]: { 2: }: IKE IPSEC KEY_DELETE recvd: SPI:0x9B4C01EE.&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 05:40:14&lt;BR /&gt;2021-10-15 05:40:14.003 +0000 [PWRN]: { : 3}: phase-2 sa purge mismatch SPI:0x00000000/0x9B4C01EE.&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 05:40:16&lt;BR /&gt;2021-10-15 05:40:16.476 +0000 [PNTF]: { 5: }: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=d28831c36d68199a df9f3ea275e758eb (size=16).&lt;BR /&gt;ikemgr.log&lt;BR /&gt;2021-10-15 05:40:17&lt;BR /&gt;2021-10-15 05:40:17.231 +0000 [PNTF]: { 4: }: notification message 36136:R-U-THERE, doi=1 proto_id=1 spi=c7831ca6999b3f2d 61b387c15d5e8f48 (size=16).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help on this.&lt;/P&gt;&lt;P&gt;One one side it is palo alto the other side it is oracle.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 12:10:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-getting-disconnected/m-p/441912#M100047</guid>
      <dc:creator>RPrasad3</dc:creator>
      <dc:date>2021-10-19T12:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN tunnel getting disconnected.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-getting-disconnected/m-p/442591#M100117</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195574"&gt;@RPrasad3&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It could be a good idea to review and confirm if all the settings from both sides are the same (phase 1 &amp;amp; 2 lifetime amongst other things).&amp;nbsp; When there is a mismatch, the most common result is that the VPN stops functioning when one site's lifetime expires.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more verbose logging information you might want to increase logging level to 'debug' if the problem persists.&lt;/P&gt;
&lt;P&gt;Also check the system logs in the same time frame as they might highlight proposal, negotiation and/or other issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 21 Oct 2021 14:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-getting-disconnected/m-p/442591#M100117</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-10-21T14:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN tunnel getting disconnected.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-getting-disconnected/m-p/442739#M100133</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195574"&gt;@RPrasad3&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;already mentioned review your settings and ensure that both sides actually match. From your logs it appears that lifetime values don't match on both sides which would lead to this sort of problem.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 00:41:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-getting-disconnected/m-p/442739#M100133</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-10-22T00:41:20Z</dc:date>
    </item>
  </channel>
</rss>

