<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DUAL Dynamic IPSEC Tunnels single VR in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-dynamic-ipsec-tunnels-single-vr/m-p/513263#M106633</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What IP are you using as your monitor? Also what happens if you disable ECMP and user weighted routes instead?&lt;/P&gt;
&lt;P&gt;Please advise,&lt;/P&gt;</description>
    <pubDate>Mon, 29 Aug 2022 15:29:45 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2022-08-29T15:29:45Z</dc:date>
    <item>
      <title>DUAL Dynamic IPSEC Tunnels single VR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-dynamic-ipsec-tunnels-single-vr/m-p/513199#M106621</link>
      <description>&lt;P&gt;Hi , have 2 dynamic isp at site 1 with single vr and &amp;nbsp;ECMP and 1 public ip at site 2 paloalto at OCI cloud , i have setup dual tunnels from site 1 to site 2 but its not stable at all , both tunnels will be up but if we simulate failover using either path monitoring or tunnel monitoring or making isp 1 or 2 down we can see that vpn is stuck in initiating phase. We used below guide&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POO0CAO" target="_blank" rel="nofollow noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POO0CAO&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Aug 2022 09:38:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-dynamic-ipsec-tunnels-single-vr/m-p/513199#M106621</guid>
      <dc:creator>mhm_ameen</dc:creator>
      <dc:date>2022-08-28T09:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: DUAL Dynamic IPSEC Tunnels single VR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-dynamic-ipsec-tunnels-single-vr/m-p/513263#M106633</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What IP are you using as your monitor? Also what happens if you disable ECMP and user weighted routes instead?&lt;/P&gt;
&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 15:29:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-dynamic-ipsec-tunnels-single-vr/m-p/513263#M106633</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-08-29T15:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: DUAL Dynamic IPSEC Tunnels single VR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-dynamic-ipsec-tunnels-single-vr/m-p/513340#M106644</link>
      <description>&lt;P&gt;using tunnels ip for monitor for IPSEC, i don't want to disable ECMP since requirements is to have load balancing internet connection. please find attached diagram.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we&amp;nbsp; are&amp;nbsp; using FQDN for dynamic peer&amp;nbsp; in ike gateway.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FQDN being used is ip address is it ok or it must be in form of name.domain.com ??&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 07:07:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-dynamic-ipsec-tunnels-single-vr/m-p/513340#M106644</guid>
      <dc:creator>mhm_ameen</dc:creator>
      <dc:date>2022-08-30T07:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: DUAL Dynamic IPSEC Tunnels single VR</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-dynamic-ipsec-tunnels-single-vr/m-p/513751#M106683</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I would make sure your monitor IP's for the tunnels are only sent down the tunnel that has the monitored IP address. I think ECMP might be messing up the tunnel monitor, ie sending traffic down one tunnel and reaching the IP address so the tunnel never goes down and routing gets goofed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So make sure the tunnel monitor is setup so tunnel 1 uses an IP address that is only accessible via tunnel 1. What I have done, since I use OSPF, is to have the tunnels have a /30 address and static routes that are only sent down that tunnel and not down OSPF.&lt;/P&gt;
&lt;P&gt;example: Tunnel1 has a /30 IP address and the other side of the tunnel has the other /30 address. The the static route for the /30 is sent to the tunnel interface and is not redistributed via OSPF so it cant reroute.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that makes sense.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 15:53:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-dynamic-ipsec-tunnels-single-vr/m-p/513751#M106683</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-09-01T15:53:52Z</dc:date>
    </item>
  </channel>
</rss>

