<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failover IPSEC tunnels with tunnel monitor keeps both tunnels active in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/failover-ipsec-tunnels-with-tunnel-monitor-keeps-both-tunnels/m-p/591590#M117808</link>
    <description>&lt;P&gt;Thank you for that explanation.&amp;nbsp; Also is it normal to have repeated firewall alerts/emails stating that Tunnel A is up/down Tunnel B is up/down?&amp;nbsp; Or is this being generated due something going with the connection of the tunnels?&amp;nbsp; This is the experience we were having yesterday after configuring the dual tunnels.&amp;nbsp; The primary tunnel swapped over, and traffic was flowing properly, but got bombarded with tunnel up/down alerts.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2024 13:03:18 GMT</pubDate>
    <dc:creator>emarschang</dc:creator>
    <dc:date>2024-07-10T13:03:18Z</dc:date>
    <item>
      <title>Failover IPSEC tunnels with tunnel monitor keeps both tunnels active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-ipsec-tunnels-with-tunnel-monitor-keeps-both-tunnels/m-p/591510#M117792</link>
      <description>&lt;P&gt;We have just configured 2 IPSEC tunnels with a remote palo.&amp;nbsp; Both sides have 2 IPSEC tunnels with tunnel monitor and DPD configured.&amp;nbsp; For some odd reason, the when the primary tunnel is active and has active routes going to it, the secondary tunnel still shows active.&amp;nbsp; Traffic is still flowing the way it should, I never see the traffic change to the secondary tunnel.&amp;nbsp; The tunnel monitoring never disables the second tunnel.&amp;nbsp; Did we over look something in our configuration?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 22:18:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-ipsec-tunnels-with-tunnel-monitor-keeps-both-tunnels/m-p/591510#M117792</guid>
      <dc:creator>emarschang</dc:creator>
      <dc:date>2024-07-09T22:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Failover IPSEC tunnels with tunnel monitor keeps both tunnels active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-ipsec-tunnels-with-tunnel-monitor-keeps-both-tunnels/m-p/591520#M117797</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211188"&gt;@emarschang&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This would be expected behavior in a properly configured dual tunnel configuration. You want both tunnels to be online and established and your primary passing traffic until it goes down; once the primary goes down the route is removed and traffic just moves to the already established secondary tunnel that is just waiting to take over traffic from the primary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 01:49:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-ipsec-tunnels-with-tunnel-monitor-keeps-both-tunnels/m-p/591520#M117797</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-07-10T01:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Failover IPSEC tunnels with tunnel monitor keeps both tunnels active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-ipsec-tunnels-with-tunnel-monitor-keeps-both-tunnels/m-p/591590#M117808</link>
      <description>&lt;P&gt;Thank you for that explanation.&amp;nbsp; Also is it normal to have repeated firewall alerts/emails stating that Tunnel A is up/down Tunnel B is up/down?&amp;nbsp; Or is this being generated due something going with the connection of the tunnels?&amp;nbsp; This is the experience we were having yesterday after configuring the dual tunnels.&amp;nbsp; The primary tunnel swapped over, and traffic was flowing properly, but got bombarded with tunnel up/down alerts.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 13:03:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-ipsec-tunnels-with-tunnel-monitor-keeps-both-tunnels/m-p/591590#M117808</guid>
      <dc:creator>emarschang</dc:creator>
      <dc:date>2024-07-10T13:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Failover IPSEC tunnels with tunnel monitor keeps both tunnels active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/failover-ipsec-tunnels-with-tunnel-monitor-keeps-both-tunnels/m-p/615025#M121633</link>
      <description>&lt;P&gt;I have a similar issue. I have created 2 tunnels on single palo with 2 different peer ip’s ( remote end using different fw). Both tunnela at my end are active but traffic flows through primary only. Issue is when recently i tried to do resiliency test, i shut down primary , traffic disn’t moved to secondary. What do i need to check?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2024 22:11:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/failover-ipsec-tunnels-with-tunnel-monitor-keeps-both-tunnels/m-p/615025#M121633</guid>
      <dc:creator>qamarkhan</dc:creator>
      <dc:date>2024-10-25T22:11:26Z</dc:date>
    </item>
  </channel>
</rss>

