<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC tunnel not working post HA failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/467544#M102797</link>
    <description>&lt;P&gt;The same issue on&amp;nbsp;10.1.3&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;test vpn ike-sa&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;test vpn &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;ipsec-sa&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;helps to make tunnels functional. but after the next HA failover the issue return&lt;/P&gt;</description>
    <pubDate>Tue, 22 Feb 2022 16:42:50 GMT</pubDate>
    <dc:creator>Olha_Osadcha</dc:creator>
    <dc:date>2022-02-22T16:42:50Z</dc:date>
    <item>
      <title>IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/309958#M80290</link>
      <description>&lt;P&gt;Hello Friends,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have Palo Alto firewalls (various models like 3050, 5220 and 3220) which are in HA (active-passive mode).&amp;nbsp; IPSEC tunnels are working fine when traffic is on active gateway. The issue is, when we failover traffic on passive gateway, internet works fine but my tunnel resources becomes unreachable. When i checked tunnel status on gateway, it shows Phase-2 is up but Phase-1 is down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then we had to manually initiate traffic from gateway by test vpn commands and after 2-3 mins, tunnel resources becomes reachable. my HA1 and HA2 links are up. Also i see IPSEC SAs getting copied from active to passive. But facing this issues when failover happens. All gateways are running on 9.0.3-h3 but we had this issue on 8.1.x also. Also this issue is not gateway specific, we are facing it on all HA clusters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is any one faced such issues ??&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 07:59:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/309958#M80290</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-07T07:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/309995#M80299</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you confgure Tunnel Monitor ?&lt;/P&gt;
&lt;P&gt;I'm guessing the tunnel should come back up after the re-key interval but with tunnel monitor it will be faster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 07 Feb 2020 10:00:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/309995#M80299</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-02-07T10:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/309998#M80300</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;I dont think tunnel monitor will help here. I do not want to failover IPSEC traffic from tunnel one to other. I have only one IPSEC tunnel and traffic should get failover to other firewall when i do firewall HA failover.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 10:18:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/309998#M80300</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-07T10:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/310001#M80301</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seemed to have helped here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/PA-HA-failover-and-IPSEC-connection-shows-inactive/td-p/259907" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/PA-HA-failover-and-IPSEC-connection-shows-inactive/td-p/259907&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 07 Feb 2020 11:12:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/310001#M80301</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-02-07T11:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/310946#M80508</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;I'll try it out and let you know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 04:12:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/310946#M80508</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-13T04:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/414381#M93112</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Did configuring Tunnel monitor fix the issue? Or did you solve it in some other way?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 22:28:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/414381#M93112</guid>
      <dc:creator>triceh</dc:creator>
      <dc:date>2021-06-21T22:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/415795#M93305</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/160432"&gt;@triceh&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Somehow issue got disappeared post moving fw to 9.1.x. I didn't made any changes.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 02:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/415795#M93305</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-06-29T02:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/415811#M93306</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Alright, i appreciate the response.&lt;BR /&gt;Thanks for sharing.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Brgds,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 06:41:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/415811#M93306</guid>
      <dc:creator>triceh</dc:creator>
      <dc:date>2021-06-29T06:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/463327#M102356</link>
      <description>&lt;P&gt;We are facing similar issue with a HA pair. Can you share&amp;nbsp; which PANOS version in 9.1.x resolved the issue ?? our firewalls are on 9.1.12-h3.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be highly appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 01:42:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/463327#M102356</guid>
      <dc:creator>NaveenAlakurthi</dc:creator>
      <dc:date>2022-02-04T01:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/467544#M102797</link>
      <description>&lt;P&gt;The same issue on&amp;nbsp;10.1.3&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;test vpn ike-sa&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;test vpn &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;ipsec-sa&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;helps to make tunnels functional. but after the next HA failover the issue return&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 16:42:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/467544#M102797</guid>
      <dc:creator>Olha_Osadcha</dc:creator>
      <dc:date>2022-02-22T16:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/507550#M105751</link>
      <description>&lt;P&gt;Did you every determine a fix beyond issuing the test vpn commands? I have one tunnel that requires this anytime we fail from active to passive.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 21:40:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/507550#M105751</guid>
      <dc:creator>bmartinsmm</dc:creator>
      <dc:date>2022-06-30T21:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC tunnel not working post HA failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/515810#M107133</link>
      <description>&lt;P&gt;9.1.14 h4-- just upgraded HA pair.&amp;nbsp; When failed over to secondary fw the phase 2 indicators (10 tunnels) typically are red.&amp;nbsp; We run the cli test vpn ipsec-sa tunnel commands to trigger them to go green which most do within a couple of seconds. However some tunnels will not go green unless we disable the tunnel on the primary fw. ?&amp;nbsp; &amp;nbsp; &amp;nbsp;We usually wait several minutes before we do the disable thing..&amp;nbsp; When all are indicators (phase 2) go green we failback to primary fw and again have to now disable the tunnels on the secondary before the primary indicators go green.&amp;nbsp; Comments welcome.&amp;nbsp; thnks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 12:55:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-not-working-post-ha-failover/m-p/515810#M107133</guid>
      <dc:creator>vnt90</dc:creator>
      <dc:date>2022-09-23T12:55:44Z</dc:date>
    </item>
  </channel>
</rss>

