<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec  intermittent disconnection issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224113#M123687</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1227661985"&gt;@AY_FASAR&lt;/a&gt;&amp;nbsp;to clarify your issue - the tunnel states it is up on both ends, but there is no traffic flowing through it? Working through something similar to this myself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A few thoughts:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Could a Zone Protection Profile be blocking traffic?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;I believe a packet capture may be best, especially with logging packet-diag features enabled.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;An easy win - make sure NTP settings are valid on both ends of the tunnel.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;It could be worthwhile to follow up with the ISP.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Is the far end device also a Palo Alto Networks NGFW?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Wildcard thought - MTU size?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;What version of PAN-OS are you running?&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Will keep you updated if I find RCA in my case.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Mar 2025 16:23:34 GMT</pubDate>
    <dc:creator>nohash4u</dc:creator>
    <dc:date>2025-03-18T16:23:34Z</dc:date>
    <item>
      <title>IPSec  intermittent disconnection issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224018#M123671</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a command to check if a tunnel went down on a specific time and why it happened.&lt;/P&gt;
&lt;P&gt;I have a tunnel set-up to a 3rd party where they keep monitoring some of their servers. They inform me that they receive alarms every hour that the endpoint is down and its not coming back up for about 15 min.&lt;/P&gt;
&lt;P&gt;I cant see anything obvious. I have done show vpn flow name ...&amp;nbsp; but I cant see any error there. is there any other logs that I could check to see those disconnections that 3rd party mentioning and if I can get any clue from the output why the tunnels going down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 14:22:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224018#M123671</guid>
      <dc:creator>AY_FASAR</dc:creator>
      <dc:date>2025-03-17T14:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  intermittent disconnection issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224033#M123675</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1227661985"&gt;@AY_FASAR&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a command to check if a tunnel went down on a specific time and why it happened.&lt;/P&gt;
&lt;P&gt;I have a tunnel set-up to a 3rd party where they keep monitoring some of their servers. They inform me that they receive alarms every hour that the endpoint is down and its not coming back up for about 15 min.&lt;/P&gt;
&lt;P&gt;I cant see anything obvious. I have done show vpn flow name ...&amp;nbsp; but I cant see any error there. is there any other logs that I could check to see those disconnections that 3rd party mentioning and if I can get any clue from the output why the tunnels going down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If you look in the GUI logs, (system) and filter on type of "VPN" (I think.) that should give you the logs you're looking for.&amp;nbsp; I would also add&amp;nbsp;time stamps filters with a "geq" (after - greater than equal to) &amp;amp; "leq" (before - less than equal to) for the time period you had VPN issues.&amp;nbsp; You can look through the logs and find errors much easier that way.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 17:58:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224033#M123675</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-03-17T17:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  intermittent disconnection issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224088#M123685</link>
      <description>&lt;P&gt;all I can see is just the key negotiation, nothing else to suggest there is an issue. 3rd party insists that they sent traffic down the tunnel to us and that they get dropped our end. if they keep sending traffic, means the tunnel stays up all the time but there is some other issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could the traffic getting dropped some how during the rekey phase? if there is possibility, is there a debug or packet capture to prove this? with packet capture it might be a bit tricky as the issue is intermittent.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 10:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224088#M123685</guid>
      <dc:creator>AY_FASAR</dc:creator>
      <dc:date>2025-03-18T10:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  intermittent disconnection issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224113#M123687</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1227661985"&gt;@AY_FASAR&lt;/a&gt;&amp;nbsp;to clarify your issue - the tunnel states it is up on both ends, but there is no traffic flowing through it? Working through something similar to this myself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A few thoughts:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Could a Zone Protection Profile be blocking traffic?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;I believe a packet capture may be best, especially with logging packet-diag features enabled.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;An easy win - make sure NTP settings are valid on both ends of the tunnel.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;It could be worthwhile to follow up with the ISP.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Is the far end device also a Palo Alto Networks NGFW?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Wildcard thought - MTU size?&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;What version of PAN-OS are you running?&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Will keep you updated if I find RCA in my case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 16:23:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224113#M123687</guid>
      <dc:creator>nohash4u</dc:creator>
      <dc:date>2025-03-18T16:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  intermittent disconnection issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224139#M123689</link>
      <description>&lt;P&gt;I dont believe its NTP or anything similar, all other tunnels working fine. it's only this tunnel's 3rd party and the issue is intermittent.&lt;/P&gt;
&lt;P&gt;Not sure what vendor is 3rd party's gateway but I can check.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 21:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224139#M123689</guid>
      <dc:creator>AY_FASAR</dc:creator>
      <dc:date>2025-03-18T21:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  intermittent disconnection issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224323#M123722</link>
      <description>&lt;P&gt;Ok, sounds good. I will likely be opening a TAC case. I will keep you posted.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 15:38:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1224323#M123722</guid>
      <dc:creator>nohash4u</dc:creator>
      <dc:date>2025-03-20T15:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec  intermittent disconnection issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1226444#M123977</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1227661985"&gt;@AY_FASAR&lt;/a&gt;&amp;nbsp;did you ever get a resolution? I thought I would provide an update from my end. The TAC case unfortunately fizzled out as dump level debugging was not enabled, and it was deemed unwise to leave this level of debugging on until the issue reoccurred given the strain it puts on the firewall. That being said, a senior engineer I work with noticed two things:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;An unusual frequency of IKE rekeying.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;The source IP of the IKE rekeying not aligning with the expected configuration on the firewall. This was attributed to an issue with the ISP, and is being investigated.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I hope this helps.&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 16:34:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-intermittent-disconnection-issue/m-p/1226444#M123977</guid>
      <dc:creator>nohash4u</dc:creator>
      <dc:date>2025-04-14T16:34:25Z</dc:date>
    </item>
  </channel>
</rss>

