<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tunnel Monitor - PAN-OS SDWAN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/579701#M116163</link>
    <description>&lt;P&gt;I've had an issue recently where randomly I've had members of my VPN mesh start to have the tunnel monitors going up and down constantly which causes BGP to never be able to establish with the peer since the static routes to the loopbacks are pulled from the route table.&amp;nbsp; This has happened randomly to 2-3 sites back to either of the hubs.&amp;nbsp; When the SD-WAN module creates all of the ipsec tunnels it addresses them from a pool you configure (10.254.0.0/16) for example.&amp;nbsp; Then it sets up the tunnel address on the other side as the monitored IP.&amp;nbsp; Since tunnel monitoring isn't subject to the normal flow of the data plate (NAT, etc) and is sourced from the local tunnel interface to the IP of the remote interface, as long as phase 1 and 2 are established there shouldn't be anything that can cause the tunnel monitor to fail as reachability would always be there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm struggling to find a remedy to this.&amp;nbsp; We haven't upgraded firmware or the sd-wan module since well before this started occurring. Most of the branch firewalls are on 10.2.7h3.&amp;nbsp; One hub is on 10.2.6 and the other 10.2.4-h4. Reboots of the firewalls do not resolve the issue.&amp;nbsp; Has anyone else encountered this before?&lt;/P&gt;</description>
    <pubDate>Thu, 07 Mar 2024 19:47:16 GMT</pubDate>
    <dc:creator>Clint_Phelps</dc:creator>
    <dc:date>2024-03-07T19:47:16Z</dc:date>
    <item>
      <title>Tunnel Monitor - PAN-OS SDWAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/579701#M116163</link>
      <description>&lt;P&gt;I've had an issue recently where randomly I've had members of my VPN mesh start to have the tunnel monitors going up and down constantly which causes BGP to never be able to establish with the peer since the static routes to the loopbacks are pulled from the route table.&amp;nbsp; This has happened randomly to 2-3 sites back to either of the hubs.&amp;nbsp; When the SD-WAN module creates all of the ipsec tunnels it addresses them from a pool you configure (10.254.0.0/16) for example.&amp;nbsp; Then it sets up the tunnel address on the other side as the monitored IP.&amp;nbsp; Since tunnel monitoring isn't subject to the normal flow of the data plate (NAT, etc) and is sourced from the local tunnel interface to the IP of the remote interface, as long as phase 1 and 2 are established there shouldn't be anything that can cause the tunnel monitor to fail as reachability would always be there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm struggling to find a remedy to this.&amp;nbsp; We haven't upgraded firmware or the sd-wan module since well before this started occurring. Most of the branch firewalls are on 10.2.7h3.&amp;nbsp; One hub is on 10.2.6 and the other 10.2.4-h4. Reboots of the firewalls do not resolve the issue.&amp;nbsp; Has anyone else encountered this before?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 19:47:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/579701#M116163</guid>
      <dc:creator>Clint_Phelps</dc:creator>
      <dc:date>2024-03-07T19:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitor - PAN-OS SDWAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/579706#M116165</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I've seen issues with routing protocols not being able to establish neighbors when a circuit is having issues. Our solution at the time was to down the interface of the circuit associated with the circuit until the provider stabilized it. Not sure if there is a flap detection threshold for a situation such as yours. Would be a useful tool to have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 20:04:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/579706#M116165</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-03-07T20:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitor - PAN-OS SDWAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/579716#M116170</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; I'm not seeing any issues on the circuits these tunnels are terminating at but I will look a little deeper and see if there is some debugging I can turn on that may show more info that I'm missing.&amp;nbsp; The firewall shows the tunnels up with active SAs on phase 1 and 2.&amp;nbsp; No other apparent issues other than the monitor itself going up and down constantly.&amp;nbsp; Like every few seconds.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 20:49:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/579716#M116170</guid>
      <dc:creator>Clint_Phelps</dc:creator>
      <dc:date>2024-03-07T20:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitor - PAN-OS SDWAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/593300#M118083</link>
      <description>&lt;P&gt;Hi Clint, did you ever find a resolution to this. I am experiencing same issue at the moment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 11:16:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/593300#M118083</guid>
      <dc:creator>kdaniels</dc:creator>
      <dc:date>2024-07-29T11:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Tunnel Monitor - PAN-OS SDWAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/593311#M118086</link>
      <description>&lt;P&gt;Unfortunately we did not.&amp;nbsp; I hope you have better luck than we did.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 12:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tunnel-monitor-pan-os-sdwan/m-p/593311#M118086</guid>
      <dc:creator>Clint_Phelps</dc:creator>
      <dc:date>2024-07-29T12:23:14Z</dc:date>
    </item>
  </channel>
</rss>

