<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC-Tunnel Monitoring &amp;quot;tunnel-status-down&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17346#M12665</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I found the reason for the constant re-keying. The two tunnels mentioned have two Proxy IDs configured:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA-ProxyIDs.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3797_PA-ProxyIDs.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we remove the 2nd entry the tunnel monitoring seems to work just fine...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Aug 2012 11:19:03 GMT</pubDate>
    <dc:creator>oschuler</dc:creator>
    <dc:date>2012-08-16T11:19:03Z</dc:date>
    <item>
      <title>IPSEC-Tunnel Monitoring "tunnel-status-down"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17339#M12658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I`ve created some IPSEC-Tunnel .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I try to monitor the connection using "Tunnel Monitor" option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During the commit off the configration to the applince I'll see in System - LOG:&amp;nbsp;&amp;nbsp;&amp;nbsp; ﻿&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example:&lt;BR /&gt;﻿&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10/10 11:26:52 vpn; informational;&amp;nbsp; &lt;STRONG&gt;tunnel-status-up&lt;/STRONG&gt;; &lt;SPAN style="font-size: 10pt;"&gt;&lt;EM&gt;VPN_TEST:t_test&lt;/EM&gt;; Tunnel &lt;EM&gt;VPN_Test:t_test&lt;/EM&gt; is up&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;some seconds later&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10/10/11:27:03 vpn; low; &lt;STRONG&gt;tunnel-status-down&lt;/STRONG&gt;; &lt;SPAN style="font-size: 10pt;"&gt;&lt;EM&gt;﻿﻿VPN_TEST:t_test&lt;/EM&gt;; Tunnel &lt;EM&gt;VPN_Test:t_test&lt;/EM&gt; is down&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Later I never can see, any&amp;nbsp; "monitor status is up" - message again,&amp;nbsp; but the ipsec-tunnel is working well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anybody a the same problem resoved yet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Annotation:&lt;/P&gt;&lt;P&gt;The asscociated interface "tunnel.x" has a valid IP adress, the tunnel endpoint also.&lt;/P&gt;&lt;P&gt;From CLI&amp;nbsp; a ping to the tunnel endpoint-IP with sourceaddress of the tunnel.x - interface works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;ping source 172.20.49.8 host 172.20.22.1 &lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 09:52:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17339#M12658</guid>
      <dc:creator>rainer.kranz@sab.sachsen.de</dc:creator>
      <dc:date>2011-10-10T09:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC-Tunnel Monitoring "tunnel-status-down"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17340#M12659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you saying that this issue only took place upon a commit and that the tunnel is consistently staying up? What PANOS are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 17:32:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17340#M12659</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-10-10T17:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC-Tunnel Monitoring "tunnel-status-down"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17341#M12660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;also: what hardware platform are you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 21:01:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17341#M12660</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-10-10T21:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC-Tunnel Monitoring "tunnel-status-down"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17342#M12661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿&lt;BR /&gt; I&amp;nbsp; running PanOS 4.05 on Hardware PA2050.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tunnel works fine all the time. The problem is only in using the monitoring feature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 07:29:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17342#M12661</guid>
      <dc:creator>rainer.kranz@sab.sachsen.de</dc:creator>
      <dc:date>2011-10-11T07:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC-Tunnel Monitoring "tunnel-status-down"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17343#M12662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The feature checks the health of the remote system. If the threshold(number of pings missed) is met, the PAdevice will tear down the local tunnel, clearing the SA's and will force an IKE rekey event. Are you not seeing this in the syslogs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 17:13:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17343#M12662</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-10-11T17:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC-Tunnel Monitoring "tunnel-status-down"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17344#M12663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There has been a bug identified in 4.0.5 in which the tunnel monitor packets do not get sent over the tunnel properly. This causes the VPN tunnel monitor to improperly report the tunnel as down and will keep trying to rekey the tunnel. Currently the only workaround in 4.0.5 is to disable tunnel monitoring or downgrade to 4.0.4. *Correction* This will be fixed in 4.0.7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 07:13:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17344#M12663</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2011-10-12T07:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC-Tunnel Monitoring "tunnel-status-down"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17345#M12664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could it be that this bug is back in OS 4.1.6? We're also having problems with some VPN tunnels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have around 20 VPN tunnels configured with tunnel monitoring on most of them. For two tunnels we had to disable the monitoring feature because these tunnels got re-keyed constantly (every 30 seconds). The monitor is configured with 10 sec interval and 3 retries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some debugging-hours later we are sure that the remote firewall gets the ping packets and send a reply. Why the PA firewall doesn't recognize/process this ping reply - we don't know. The VPN settings are the same, on both ends (IP and PSK vary of course). Any ideas how we can further troubleshoot the issue on the PA device? I didn't found much documentation on monitor debugging...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, is &lt;STRONG style="font-size: 11px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1109" data-externalid="" data-presence="null" data-userid="5002" data-username="rkalugdan" href="https://live.paloaltonetworks.com/people/rkalugdan" id="jive-500216296593962632155" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #316989;"&gt;rkalugdan&lt;/A&gt;&lt;/STRONG&gt;'s answer really correct that the monitor will delete the SA's ? The following doc tells another story: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2826"&gt;https://live.paloaltonetworks.com/docs/DOC-2826&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 14:33:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17345#M12664</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-08-14T14:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC-Tunnel Monitoring "tunnel-status-down"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17346#M12665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I found the reason for the constant re-keying. The two tunnels mentioned have two Proxy IDs configured:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA-ProxyIDs.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3797_PA-ProxyIDs.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we remove the 2nd entry the tunnel monitoring seems to work just fine...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2012 11:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17346#M12665</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-08-16T11:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC-Tunnel Monitoring "tunnel-status-down"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17347#M12666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm wondering if this bug came back in 5.0.2 also...&amp;nbsp; I've got a fully meshed vpn network of 5 PA's that are connected on fiber as well as broadband.&amp;nbsp;&amp;nbsp; Everything works and is pingable, with the exception of two of the sites are unable to ping each other on the inside tunnel IP address.&amp;nbsp; I get a constant rekey every couple of seconds.&amp;nbsp; Disabling monitor causes the tunnel to stay up and remain stable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 15:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-monitoring-quot-tunnel-status-down-quot/m-p/17347#M12666</guid>
      <dc:creator>rkramer</dc:creator>
      <dc:date>2013-02-04T15:36:45Z</dc:date>
    </item>
  </channel>
</rss>

