<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ikev2 site to site VPN between Arista ETM and Palo Alto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220462#M123300</link>
    <description>&lt;P&gt;Hello Mams and Sirs,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need your advice here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured an ikev2 policy based site to site VPN between our Palo Alto and client Arista ETM. I manage the Palo Alto.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The status of the VPN shows up. But, communication between the subnets(local and remote) stop abruptly until, I generate some traffic by pinging each of their VLANs/subnets from our server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the parameters look correct on both sides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I observed is that continuous pings from the Palo Alto side keep the communication up.&lt;/P&gt;
&lt;P&gt;Is this a normal behaviour or does any change have to be made on either device? Please help.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Feb 2025 13:53:22 GMT</pubDate>
    <dc:creator>msdphi</dc:creator>
    <dc:date>2025-02-17T13:53:22Z</dc:date>
    <item>
      <title>Ikev2 site to site VPN between Arista ETM and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220462#M123300</link>
      <description>&lt;P&gt;Hello Mams and Sirs,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need your advice here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured an ikev2 policy based site to site VPN between our Palo Alto and client Arista ETM. I manage the Palo Alto.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The status of the VPN shows up. But, communication between the subnets(local and remote) stop abruptly until, I generate some traffic by pinging each of their VLANs/subnets from our server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the parameters look correct on both sides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I observed is that continuous pings from the Palo Alto side keep the communication up.&lt;/P&gt;
&lt;P&gt;Is this a normal behaviour or does any change have to be made on either device? Please help.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 13:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220462#M123300</guid>
      <dc:creator>msdphi</dc:creator>
      <dc:date>2025-02-17T13:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 site to site VPN between Arista ETM and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220675#M123301</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/722572629"&gt;@msdphi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes,&amp;nbsp;&lt;SPAN&gt;IPSec tunnel comes up only when there is an interesting traffic destined to the tunnel.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Check the bullet "&lt;STRONG class="ph b"&gt;Interesting Traffic or On-Demand" &lt;/STRONG&gt;on this page which explains:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG class="ph b"&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/ipsec-vpn-basics/ipsec-vpn-tunnels" target="_blank"&gt;https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/ipsec-vpn-basics/ipsec-vpn-tunnels&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To provide uninterrupted VPN service, you can use the Dead Peer Detection capability along with the tunnel monitoring capability on the firewall:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/set-up-tunnel-monitoring" target="_blank"&gt;&lt;STRONG&gt;https://docs.paloaltonetworks.com/network-security/ipsec-vpn/administration/set-up-tunnel-monitoring&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kim.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 16:47:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220675#M123301</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-02-17T16:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 site to site VPN between Arista ETM and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220679#M123302</link>
      <description>&lt;P&gt;Thank you, Kim.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already have liveliness check enabled and tunnel monitoring won't be possible. Because the client has multiple VLANs. But, configure multiple monitoring IP address is not possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I may be wrong. Please advise.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 18:51:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220679#M123302</guid>
      <dc:creator>msdphi</dc:creator>
      <dc:date>2025-02-17T18:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 site to site VPN between Arista ETM and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220723#M123307</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/722572629"&gt;@msdphi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Correct, tunnel monitoring only allows you to monitor one IP.&lt;/P&gt;
&lt;P&gt;Why would you monitor more ? For Tunnel monitoring you usually monitor an IP closest to the tunnel IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to check on different VLANs being available I think you should look into path monitoring instead.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 09:10:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220723#M123307</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-02-18T09:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Ikev2 site to site VPN between Arista ETM and Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220728#M123308</link>
      <description>&lt;P&gt;Why would you monitor more ? For Tunnel monitoring you usually monitor an IP closest to the tunnel IP--- so, the problem is that unless I keep continuous pings going to each of their LAN gateways, the communication stops, though the vpn shows as up. But that's not a good solution. I thought we might phase 2 parameters&amp;nbsp; there&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to check on different VLANs being available I think you should look into path monitoring instead.--- okay will check ..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 10:01:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-site-to-site-vpn-between-arista-etm-and-palo-alto/m-p/1220728#M123308</guid>
      <dc:creator>msdphi</dc:creator>
      <dc:date>2025-02-18T10:01:00Z</dc:date>
    </item>
  </channel>
</rss>

