<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec Tunnel fails after 1 packet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-fails-after-1-packet/m-p/507516#M105744</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/225351"&gt;@Bradmatix&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Additionally to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentioned, are we dealing with only PAN firewalls here? SiteA is a PAN clearly, but what firewall vendor are we working with on SiteB or SiteC?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jun 2022 20:21:15 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-06-30T20:21:15Z</dc:date>
    <item>
      <title>IPSec Tunnel fails after 1 packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-fails-after-1-packet/m-p/507374#M105720</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a number of Palo Alto firewalls at our satellite sites configured in a Mesh VPN.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Basic Setup.png" style="width: 910px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42100i747435B472826080/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Basic Setup.png" alt="Basic Setup.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site A, Site B, and Site C (Internal) all work successfully.&lt;/P&gt;&lt;P&gt;Site C DMZ can establish a tunnel to all the other sites, however as soon as the VPN is used, it immediately stops working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site C Internal and Site C DMZ are different Virtual Routers running on the same vsys.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Testing the VPN from SiteA to DMZ works&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;admin@SiteA(active)&amp;gt; test vpn ike-sa gateway DMZ&lt;/P&gt;&lt;P&gt;Start time: Jun.30 16:48:21&lt;BR /&gt;Initiate 1 IKE SA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sending a ping across the tunnel works for a single packet.&lt;/STRONG&gt;&lt;BR /&gt;admin@SiteA(active)&amp;gt; ping source 10.1.1.1 host 100.1.1.1&lt;BR /&gt;PING 100.1.1.1 (100.1.1.1) from 10.1.1.1 : 56(84) bytes of data.&lt;BR /&gt;64 bytes from 100.1.1.1: icmp_seq=1 ttl=64 time=2.09 ms&lt;BR /&gt;^C&lt;BR /&gt;--- 100.1.1.1 ping statistics ---&lt;BR /&gt;5 packets transmitted, 1 received, 80% packet loss, time 4058ms&lt;BR /&gt;rtt min/avg/max/mdev = 2.099/2.099/2.099/0.000 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Testing another separate ping fails&lt;/STRONG&gt;&lt;BR /&gt;admin@SiteA(active)&amp;gt; ping source 10.1.1.1 host 100.1.1.1&lt;BR /&gt;PING 100.1.1.1 (100.1.1.1) from 10.1.1.1 : 56(84) bytes of data.&lt;BR /&gt;^C&lt;BR /&gt;--- 100.1.1.1 ping statistics ---&lt;BR /&gt;2 packets transmitted, 0 received, 100% packet loss, time 1018ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Using TEST VPN to reinitiate some keys&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;admin@SiteA(active)&amp;gt; test vpn ike-sa gateway DMZ&lt;/P&gt;&lt;P&gt;Start time: Jun.30 16:48:51&lt;BR /&gt;Initiate 1 IKE SA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Ping works for 1 packet.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;admin@SiteA(active)&amp;gt; ping source 10.1.1.1 host 100.1.1.1&lt;BR /&gt;PING 100.1.1.1 (100.1.1.1) from 10.1.1.1 : 56(84) bytes of data.&lt;BR /&gt;64 bytes from 100.1.1.1: icmp_seq=1 ttl=64 time=2.31 ms&lt;BR /&gt;^C&lt;BR /&gt;--- 100.1.1.1 ping statistics ---&lt;BR /&gt;5 packets transmitted, 1 received, 80% packet loss, time 4082ms&lt;BR /&gt;rtt min/avg/max/mdev = 2.310/2.310/2.310/0.000 ms&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are seeing the exact same behaviour from&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site A -&amp;gt; Site C DMZ&lt;/P&gt;&lt;P&gt;Site B -&amp;gt; Site C DMZ&lt;/P&gt;&lt;P&gt;Site C Internal -&amp;gt; Site C DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some additional info:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This Mesh VPN was working prior to a cutover to Palo Alto firewalls. No Rules/Routing was changed, only the firewall devices. No blocks being seen on any devices between these firewalls.&lt;/LI&gt;&lt;LI&gt;DH groups, keys, etc have been checked. The VPN establishes successfully.&lt;/LI&gt;&lt;LI&gt;There is no Maximum Lifesize set on the tunnels.&lt;/LI&gt;&lt;LI&gt;Checked all the static routes. Traffic is going through the correct tunnels. Traffic in the logs looks correct&lt;/LI&gt;&lt;LI&gt;Have tried to change IPSec crypto suites&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone seen similar behaviour before or have any suggestions on what we can check next? Only thing I can think is that the Palo Alto doesn't like the 2 VPNs being created on the same vsys, despite different Virtual Routers, but would have thought other people would be doing this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 09:15:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-fails-after-1-packet/m-p/507374#M105720</guid>
      <dc:creator>Bradmatix</dc:creator>
      <dc:date>2022-06-30T09:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel fails after 1 packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-fails-after-1-packet/m-p/507444#M105739</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;How is routing handled, is it static or a dynamic protocol?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 14:23:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-fails-after-1-packet/m-p/507444#M105739</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-06-30T14:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel fails after 1 packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-fails-after-1-packet/m-p/507516#M105744</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/225351"&gt;@Bradmatix&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Additionally to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentioned, are we dealing with only PAN firewalls here? SiteA is a PAN clearly, but what firewall vendor are we working with on SiteB or SiteC?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 20:21:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-fails-after-1-packet/m-p/507516#M105744</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-06-30T20:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Tunnel fails after 1 packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-fails-after-1-packet/m-p/507583#M105753</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;- All the tunnel routing has been added statically. We also have a default route so traffic not destined for the tunnel can go out.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;- All 3 are PAN firewalls&lt;/P&gt;&lt;P&gt;Site A - PA 3220&lt;/P&gt;&lt;P&gt;Site B - PA 850&lt;/P&gt;&lt;P&gt;Site C - PA 3250&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 01:39:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-fails-after-1-packet/m-p/507583#M105753</guid>
      <dc:creator>Bradmatix</dc:creator>
      <dc:date>2022-07-01T01:39:31Z</dc:date>
    </item>
  </channel>
</rss>

