<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vpn issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20566#M15018</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;There are couple of reasons for that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) The sites lost networks connectivity between them for a certain duration and during that time the ike and esp sessions timed out on the firewall&lt;/P&gt;&lt;P&gt;2) Either of the site did not rekey and hence after the session key became invalid, that the sites couldnt process the ike traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How long were the VPNs up and running prior to seeing this issue. Are both the devices PANFWs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Aug 2013 13:18:05 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2013-08-02T13:18:05Z</dc:date>
    <item>
      <title>vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20565#M15017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After side to side vpn established correctly after sometime(I do not know how many hours) Phase1 becomes passive.Side1 cannot access Side2.&lt;/P&gt;&lt;P&gt;when we try to use test vpn command for ike it becomes up and it works.What can be reason for that ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 12:35:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20565#M15017</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-02T12:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20566#M15018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;There are couple of reasons for that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) The sites lost networks connectivity between them for a certain duration and during that time the ike and esp sessions timed out on the firewall&lt;/P&gt;&lt;P&gt;2) Either of the site did not rekey and hence after the session key became invalid, that the sites couldnt process the ike traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How long were the VPNs up and running prior to seeing this issue. Are both the devices PANFWs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 13:18:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20566#M15018</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-02T13:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20567#M15019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;juniper other side&lt;/P&gt;&lt;P&gt;I don't know how long but I'll look forward to catch time details.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 13:23:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20567#M15019</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-02T13:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20568#M15020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suspect that either site did not rekey, to be the primary reason. Its not a mandatory setting for the rekeying timing to match on both the devices, but keeping the same value on both the devices, would force both the devices to rekey after the lifetime of the session keys have expired.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you notice just the phase 1 going down, with the actual tunnel traffic still flowing (phase-2 being up and passing ESP traffic), or were both phase 1 and phase 2 down?&lt;/P&gt;&lt;P&gt;If its the latter, then I would suspect the lost internet connectivity between them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 13:31:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20568#M15020</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-02T13:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20569#M15021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If there was no traffic passing through the tunnel the tunnel might have come down.&lt;/P&gt;&lt;P&gt;As you said as soon as you ran test command the tunnel came back up.&lt;/P&gt;&lt;P&gt;Next time if you see tunnel go down. I will suggest rather than running the test command send some traffic from the host machines over the tunnel and see if the traffic is dropped or if it pass through and tunnel comes up.&lt;/P&gt;&lt;P&gt;If this is the case then it should be working as expected,&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 17:36:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20569#M15021</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-02T17:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20570#M15022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already wrote it does not work when tunnel is down.(with ping or something etc.)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 20:32:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20570#M15022</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-02T20:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20571#M15023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We can enable tunnel monitoring so that there is at least some traffic flowing through the tunnel. ( tunnel monitoring forces the firewalls to rekey ). The system logs on the PANFW is the best place to look for the reasons the tunnel going down. Similarly the kmd logs ( &amp;gt;show log kmd )&amp;nbsp; on the Juniper ( if its an SRX ) will give you the reasons for the tunnel to go down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 20:49:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20571#M15023</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-02T20:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20572#M15024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That will work I think.Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 20:53:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-issue/m-p/20572#M15024</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-02T20:53:33Z</dc:date>
    </item>
  </channel>
</rss>

