<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Issue on interface subnet change in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue-on-interface-subnet-change/m-p/448301#M100802</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109121"&gt;@a.jones&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is difficult to troubleshoot your issue without more details.&amp;nbsp; With that said, have you considered leaving the /30?&amp;nbsp; Since you are moving to active/passive, then you do not need separate IP addresses for the passive firewall.&amp;nbsp; The same IP addresses are configured on both.&amp;nbsp; The IP addresses on the passive firewall do not respond to traffic until it becomes active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 18 Nov 2021 00:37:56 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-11-18T00:37:56Z</dc:date>
    <item>
      <title>VPN Issue on interface subnet change</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue-on-interface-subnet-change/m-p/448284#M100801</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Help here will be appreciated.&lt;/P&gt;&lt;P&gt;I am migrating a pair of PA-5220's to Active-Passive as they are currently Active-Active. First job in the task is to change the interfaces from /30 to /29 subnets. This is to ensure that both firewalls sit within the same subnet rather than be in isolated /30s. The migration is needed as the VPNs only reside on the Active-Primary and not Active-Secondary so there is no VPN resilience. Floating IP can't be used as it doesn't work without the interfaces being in the same subnet (tried and tested).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue I have is when I change the interfaces to the /29 subnet - it is only the subnet mask changing, not the IP - I see the VPNs time out and fail. BGP to the local routers stays established, traffic flow through the firewall is good and unimpacted bar a ping or two drop during the interface change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have reselected the local peer IP in the IKE-GW settings and manually pushed a test vpn command to re-establish the VPN. Even after 20 minutes of trying the VPNs stay down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I revert back to the /30 interfaces, a test vpn command brings the VPN up immediately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas? System logs don't show errors, I could see the Ike request okay.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 23:51:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue-on-interface-subnet-change/m-p/448284#M100801</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2021-11-17T23:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Issue on interface subnet change</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue-on-interface-subnet-change/m-p/448301#M100802</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/109121"&gt;@a.jones&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is difficult to troubleshoot your issue without more details.&amp;nbsp; With that said, have you considered leaving the /30?&amp;nbsp; Since you are moving to active/passive, then you do not need separate IP addresses for the passive firewall.&amp;nbsp; The same IP addresses are configured on both.&amp;nbsp; The IP addresses on the passive firewall do not respond to traffic until it becomes active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 00:37:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue-on-interface-subnet-change/m-p/448301#M100802</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-11-18T00:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Issue on interface subnet change</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue-on-interface-subnet-change/m-p/465516#M102598</link>
      <description>&lt;P&gt;This was a funny one that I resolved in the end. For some reason in active-active mode it didn't like both interfaces in the same subnet with the VPN on one firewall. With only the Active Primary in a /29 and the Active Secondary isolated in a /30 the VPN stayed up. If both firewalls were part of the same /29 the VPN was pulled down. It was an acceptable configuration for 24 hours until we fully migrated to an active-passive scenario.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue-on-interface-subnet-change/m-p/465516#M102598</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2022-02-14T15:05:12Z</dc:date>
    </item>
  </channel>
</rss>

