<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto - Barracuda IPsec VPN problems in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/1248893#M126045</link>
    <description>&lt;P&gt;We had the exact same issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the situation:&lt;/P&gt;
&lt;P&gt;PA-5250 PANOS 10.2.7-h24.&amp;nbsp; Had to upgrad due to packet buffer congestion issues on this PANOS version (supposedly fixed but not).&lt;/P&gt;
&lt;P&gt;Upgraded to PANOS 11.1.10-h1.&amp;nbsp; This version has a known issue with IPSEC tunnels and Dynamic NATs, but since we're not using Dynamic NATs, we have been cleared.&lt;/P&gt;
&lt;P&gt;After upgrading to 11.1.10-h1, we started noticing daily that 1/7 Proxy IDs would drop for hours.&amp;nbsp; Come back, drop later.&amp;nbsp; Once traffic died down, everything seemed to stabilize.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We found this post, and the mention about too many proxy IDs resonated with us.&amp;nbsp; We provide this link to TAC to look into it and confirm, and crickets.&amp;nbsp; Not sure they even read it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We contacted the other vendor using Barracuda firewalls, and worked with them to remove 7 individual Proxy IDs and replace with a /23 subnet, and things have been stable since.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's apparent that Barracuda has issues, with too many Proxy IDs, and this post here is what we attribute to resolving our issue.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Feb 2026 14:23:28 GMT</pubDate>
    <dc:creator>CGoulard</dc:creator>
    <dc:date>2026-02-24T14:23:28Z</dc:date>
    <item>
      <title>Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/447624#M100724</link>
      <description>&lt;P&gt;We've a IPsec-VPN IKEv2 between Palo Alto (10.0.7) and Barracuda (8.0.5-0341) with 10 IPsec tunnels, one VPN-tunnel per subnet-pair, on Palo side "proxy IDs".&lt;/P&gt;&lt;P&gt;At least once every day, some of these ipsec-tunnels go down and can only be forced to come up again with manual "initiate" on Barracuda.&lt;BR /&gt;The Palo Alto is set to passive.&lt;/P&gt;&lt;P&gt;Normally, every 35 - 45 minutes a new ipsec-tunnel for a subnet-pair is installed and the old one deleted (logs on both sides). But when the error occurs, the newly established ipsec-tunnel is deleted immediatly (in the same second) after is has been installed.&lt;BR /&gt;These logs also are seen on both ends of the tunnel, so it can not be sayed&amp;nbsp; which end causes the problem and why.&lt;BR /&gt;Then it is down until manual "initiate".&lt;BR /&gt;Any ideas?&lt;BR /&gt;Of course we checked timers, subnets and masks etc.&lt;BR /&gt;Thanks.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 14:12:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/447624#M100724</guid>
      <dc:creator>ChrisCon</dc:creator>
      <dc:date>2021-11-15T14:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/447655#M100727</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;When the tunnels go down, is there lack of traffic? Meaning some devices, not sure about Barracuda, will drop tunnels if no traffic is going across them. If you setup tunnel monitor, the PAN will send a ping periodically across the tunnel to help keep it up.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/vpns/set-up-site-to-site-vpn/set-up-tunnel-monitoring.html#ida640225c-92d3-4fcb-a4b3-274777fd063c" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/vpns/set-up-site-to-site-vpn/set-up-tunnel-monitoring.html#ida640225c-92d3-4fcb-a4b3-274777fd063c&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 15:41:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/447655#M100727</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-11-15T15:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/447674#M100732</link>
      <description>&lt;P&gt;Thanks four reply.&lt;BR /&gt;But we already are pinging through some of the tunnels (5 minutes intervall) and there it also happens.&lt;BR /&gt;And I think the ipsec-tunnel should be coming up when traffic is going through it, even when there was some time without traffic, otherwise it is useless.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 15:58:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/447674#M100732</guid>
      <dc:creator>ChrisCon</dc:creator>
      <dc:date>2021-11-15T15:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/486289#M104591</link>
      <description>&lt;P&gt;Hey &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the same issue. Could you figure out what the problem was?&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 06:52:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/486289#M104591</guid>
      <dc:creator>Iselith</dc:creator>
      <dc:date>2022-05-11T06:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/486295#M104593</link>
      <description>&lt;P&gt;Unfortunately not. We moved from Barracuda (Azure cloud) to the Azure-VPN-GW&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 07:28:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/486295#M104593</guid>
      <dc:creator>ChrisCon2355</dc:creator>
      <dc:date>2022-05-11T07:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/486892#M104664</link>
      <description>&lt;P&gt;Hmm &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; We have a F280 on Prem at our office and have the issue you have described with a palo alto on the other side.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A fix would be great &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Or when someone has an idea.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question in my opinion is which firewall causes this. Barracuda or Palo.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 21:06:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/486892#M104664</guid>
      <dc:creator>Iselith</dc:creator>
      <dc:date>2022-05-12T21:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/487151#M104688</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I just reread the initial issue, any reason you have 10 tunnels between the two devices? 1 is sufficient, its all encrypted.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 20:08:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/487151#M104688</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-13T20:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/487336#M104702</link>
      <description>&lt;P&gt;We have only 1 Tunnel with 8 local networks as an IKEv2 Tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But we have the same problem as in the beginning question.&lt;/P&gt;&lt;P&gt;We run a Barracuda F280. The other Side has a Palo Alto PA-5250&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2022 06:59:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/487336#M104702</guid>
      <dc:creator>Iselith</dc:creator>
      <dc:date>2022-05-16T06:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/487709#M104737</link>
      <description>&lt;P&gt;So no one has an idea ?&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 07:04:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/487709#M104737</guid>
      <dc:creator>Iselith</dc:creator>
      <dc:date>2022-05-17T07:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/487940#M104762</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The only other thing I could suggest is to try Ikev1.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 19:41:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/487940#M104762</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-05-17T19:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/507633#M105756</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we had the same issue you're describing and got the recommendation from Barracuda Support to use&amp;nbsp;&lt;SPAN&gt;"IKE Reauthentication" and disable&amp;nbsp;"Restart SA on Close" at the tunnel settings if the partner is a Palo Alto.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That worked for us and the tunnel is stable since we changed the settings.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 09:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/507633#M105756</guid>
      <dc:creator>maierfl</dc:creator>
      <dc:date>2022-07-01T09:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/508960#M105929</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We had this problem, tried a lot of things and were getting nowhere. We were using multiple Proxy IDs /24 networks on the Palo Altos as well.&lt;/P&gt;
&lt;P&gt;We changed IKE Phase 1 lifetime to 86400 seconds (24 hours)&lt;/P&gt;
&lt;P&gt;Kept IKE Phase 2 lifetime to 3600 seconds&lt;/P&gt;
&lt;P&gt;And what I believe resolved the issue, summarized the /24 Proxy ID networks to a couple of /19 Proxy IDs that covered most networks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This reduced the IPSec VPN tunnels being created and resolved the issue. We still kept a couple of /24 networks that couldn't be summarized, but we reduced the Proxy ID entries from 20+ to 5.&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Simon&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 13:28:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/508960#M105929</guid>
      <dc:creator>SimonStef</dc:creator>
      <dc:date>2022-07-14T13:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/511550#M106345</link>
      <description>&lt;P&gt;No one here who has an other idea except Ikev1 ?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 10:11:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/511550#M106345</guid>
      <dc:creator>Iselith</dc:creator>
      <dc:date>2022-08-11T10:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto - Barracuda IPsec VPN problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/1248893#M126045</link>
      <description>&lt;P&gt;We had the exact same issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the situation:&lt;/P&gt;
&lt;P&gt;PA-5250 PANOS 10.2.7-h24.&amp;nbsp; Had to upgrad due to packet buffer congestion issues on this PANOS version (supposedly fixed but not).&lt;/P&gt;
&lt;P&gt;Upgraded to PANOS 11.1.10-h1.&amp;nbsp; This version has a known issue with IPSEC tunnels and Dynamic NATs, but since we're not using Dynamic NATs, we have been cleared.&lt;/P&gt;
&lt;P&gt;After upgrading to 11.1.10-h1, we started noticing daily that 1/7 Proxy IDs would drop for hours.&amp;nbsp; Come back, drop later.&amp;nbsp; Once traffic died down, everything seemed to stabilize.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We found this post, and the mention about too many proxy IDs resonated with us.&amp;nbsp; We provide this link to TAC to look into it and confirm, and crickets.&amp;nbsp; Not sure they even read it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We contacted the other vendor using Barracuda firewalls, and worked with them to remove 7 individual Proxy IDs and replace with a /23 subnet, and things have been stable since.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's apparent that Barracuda has issues, with too many Proxy IDs, and this post here is what we attribute to resolving our issue.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 14:23:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-barracuda-ipsec-vpn-problems/m-p/1248893#M126045</guid>
      <dc:creator>CGoulard</dc:creator>
      <dc:date>2026-02-24T14:23:28Z</dc:date>
    </item>
  </channel>
</rss>

