<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec tunnel takes long time to re-establish in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/531276#M109557</link>
    <description>&lt;P&gt;I am seeing a similar issue that I'm trying to work through. In your setup, is there is a single WAN interface at the site, or are you failing over to another WAN interface? Is either side of the tunnel in dynamic, or passive mode?&lt;/P&gt;
&lt;P&gt;Do you have "Liveness Check" enabled in the IKE settings?&lt;/P&gt;</description>
    <pubDate>Wed, 15 Feb 2023 18:56:16 GMT</pubDate>
    <dc:creator>ksalustro</dc:creator>
    <dc:date>2023-02-15T18:56:16Z</dc:date>
    <item>
      <title>IPsec tunnel takes long time to re-establish</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/518010#M107474</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 2 IPsec tunnels s2s between 2 Palo Alto firewalls.&lt;/P&gt;
&lt;P&gt;We are using ike-v2 gateways, and liveness check : 5s&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The WAN on one of the side is flapping, sometimes disconnect around 10min. After this disconnection, the tunnel does not re-establish immediately, it takes around 15min.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have also configured tunnel monitors on both sides, we have assigned IP addresses on tunnel interfaces, and we are monitoring these IPs, the monitor are UP and active.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you know why it's not reconnecting immediately after the WAN back up ? Is there something to do in terms of config ?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Oct 2022 06:16:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/518010#M107474</guid>
      <dc:creator>CTramier</dc:creator>
      <dc:date>2022-10-16T06:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel takes long time to re-establish</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/518514#M107570</link>
      <description>&lt;P&gt;In fact, when the public IP is reachable again, we can see the tunnel is briefly re-established then go down again, and we need to bounce it manually to have it reconnected.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 12:17:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/518514#M107570</guid>
      <dc:creator>CTramier</dc:creator>
      <dc:date>2022-10-20T12:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel takes long time to re-establish</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/531276#M109557</link>
      <description>&lt;P&gt;I am seeing a similar issue that I'm trying to work through. In your setup, is there is a single WAN interface at the site, or are you failing over to another WAN interface? Is either side of the tunnel in dynamic, or passive mode?&lt;/P&gt;
&lt;P&gt;Do you have "Liveness Check" enabled in the IKE settings?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 18:56:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/531276#M109557</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2023-02-15T18:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel takes long time to re-establish</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/531277#M109558</link>
      <description>&lt;P&gt;Also is there any NAT involved and if so, do you have NAT-T enabled?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 18:58:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/531277#M109558</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2023-02-15T18:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec tunnel takes long time to re-establish</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/531735#M109651</link>
      <description>&lt;P&gt;Better enable IKE debugs and to see what is happening as to not make wild suggestions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcKCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClcKCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PORsCAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 10:43:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-takes-long-time-to-re-establish/m-p/531735#M109651</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-02-20T10:43:43Z</dc:date>
    </item>
  </channel>
</rss>

