<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN not getting any response from peer in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-not-getting-any-response-from-peer/m-p/1229753#M124350</link>
    <description>&lt;P&gt;It might be the vpn tunnel can only be set up in 1 direction (this is usually a symptom of a deeper issue). You can try setting your side to 'passive' mode and have the remote end initiate the connection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this also has the added benefit of providing far more information in your logging since the recipient can see the incoming requests and the 'reply' (or denial) of the proposed negotiation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as to a cause, there could be a negotiation hickup where there's too many pairs etc. if you're able to switch the direction of the negotiation and become the receiver, if there's nothing obvious in the logs you can also go into CLI and enable debugging for IKE and IPSec and see what's happening at a lower level&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in troubleshooting ipsec, being the recipient is key &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 May 2025 08:04:27 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2025-05-22T08:04:27Z</dc:date>
    <item>
      <title>IPSec VPN not getting any response from peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-not-getting-any-response-from-peer/m-p/1229649#M124346</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm having a weird problem with an IPSec VPN on my Palo Alto.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This morning tunnel was working fine, but after mistakenly denying ike and ipsec requests on my firewall, the VPN went down. I obviously did a quick rollback and peer IP is now allowed to request IPSec and IKE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However the VPN won't go up again (other VPN with similar configurations did go UP again).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can ping the peer ip from my Palo Alto IPSec interface (x.175.253.123).&lt;/P&gt;
&lt;P&gt;I also did packet capture and i can see that i receive IKE requests from peer (x.151.254.90) :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="christopheguengant_1-1747859953364.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67708i2BFC067B13396E59/image-size/medium?v=v2&amp;amp;px=400" role="button" title="christopheguengant_1-1747859953364.png" alt="christopheguengant_1-1747859953364.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The palo alto logs only show my gateway is sending negociation requests but gets no responder state in return :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="christopheguengant_3-1747860298749.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67710iE342B68560C3B6CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="christopheguengant_3-1747860298749.png" alt="christopheguengant_3-1747860298749.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;VPN configuration is similar on both sides, no configuration changes were made on VPN at anytime. But i did check, just in case and everything is configured as i should be on both sides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried every debug command i can find, without any result. It seems the vpn isn't listening anymore. Can someone help me understand why ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, in traffic logs, i can't see IKE or IPSec traffic between both gateways. I can't figure why. Traffic rule exists and is logged at start and end of session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 20:49:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-not-getting-any-response-from-peer/m-p/1229649#M124346</guid>
      <dc:creator>christophe.guengant</dc:creator>
      <dc:date>2025-05-21T20:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN not getting any response from peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-not-getting-any-response-from-peer/m-p/1229658#M124347</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1467187213"&gt;@christophe.guengant&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend to clear out the current phase 1 and phase 2 SAs so the tunnel can start fresh. Go into the CLI and enter the following commands to clear the stale SAs:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;clear vpn ike-sa gateway &amp;lt;enter gateway name&amp;gt;
clear vpn ipsec-sa tunnel &amp;lt;enter tunnel name&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By doing this, you're telling the firewall to renegotiate a brand new connection with the peer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 21:46:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-not-getting-any-response-from-peer/m-p/1229658#M124347</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-05-21T21:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN not getting any response from peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-not-getting-any-response-from-peer/m-p/1229753#M124350</link>
      <description>&lt;P&gt;It might be the vpn tunnel can only be set up in 1 direction (this is usually a symptom of a deeper issue). You can try setting your side to 'passive' mode and have the remote end initiate the connection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this also has the added benefit of providing far more information in your logging since the recipient can see the incoming requests and the 'reply' (or denial) of the proposed negotiation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as to a cause, there could be a negotiation hickup where there's too many pairs etc. if you're able to switch the direction of the negotiation and become the receiver, if there's nothing obvious in the logs you can also go into CLI and enable debugging for IKE and IPSec and see what's happening at a lower level&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in troubleshooting ipsec, being the recipient is key &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 08:04:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-not-getting-any-response-from-peer/m-p/1229753#M124350</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-05-22T08:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN not getting any response from peer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-not-getting-any-response-from-peer/m-p/1229838#M124360</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your help. It seems i had some dead session blocking renegociation of the ike or ipsec.&lt;/P&gt;
&lt;P&gt;The "clear vpn" cli commands didn't seem to work, but did have better results one i killed dead ike or opsec sessions from the GUI (Monitor &amp;gt; Session Browser). (It is good to know that in the session browser it is possible to filter on remote gateway ip).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It appears to be a known issue on Palo Alto Firewalls.&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 19:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-not-getting-any-response-from-peer/m-p/1229838#M124360</guid>
      <dc:creator>christophe.guengant</dc:creator>
      <dc:date>2025-05-22T19:29:23Z</dc:date>
    </item>
  </channel>
</rss>

