<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec tunnel, delayed status update in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22385#M16320</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Were the colours of the VPN, green and red, even with multiple page refreshes? The screenshot below shows the status of the IKE and the IPSEC. The first one on the left, shows the status of IPSEC-ESP and the one on the right, shows the status of the IKE.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="IKe-statis.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10830_IKe-statis.JPG.jpg" style="width: 620px; height: 82px;" /&gt;&lt;/P&gt;&lt;P&gt;Again that depends on how long the outage was. All though the Lifetime of IPSEC-ESP and IKE can be ( like by default ) 1 hour and 8 hours respectively, the session timeout values for IPSEC-ESP and IKE are 3600 secs and 30 secs respectively. Lifetime determines the amount of time that the parties have to wait before they rekey again. Once a VPN is up, the firewall maintains sessions for IKE and IPSEC-ESP. If the firewall doesn't receive packets within the session timeout values, it discards the session. That being the case, had there been an outage, the session for IPSEC-ESP would still remain active for a longer duration than the IKE session ( When there is an ISP outage, no ESP or IKE packets would reach either firewall).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever a tunnel goes down, the firewall logs these events with a high severity, and we have the ability to send these events to a syslog server. You can get faster alerts of VPNs going down, by using SNMP servers, or through syslog servers, instead of relying on the WEB GUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Jan 2014 15:19:40 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2014-01-10T15:19:40Z</dc:date>
    <item>
      <title>IPSec tunnel, delayed status update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22384#M16319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had one of our remote sites go offline two days ago due to an ISP outage. However, the site to site link showed as up for several hours before it finally dropped and showed as offline. IS there a setting to have this respond faster so it shows offline within minutes? Or is this working as designed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 14:43:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22384#M16319</guid>
      <dc:creator>carpediem79</dc:creator>
      <dc:date>2014-01-10T14:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel, delayed status update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22385#M16320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Were the colours of the VPN, green and red, even with multiple page refreshes? The screenshot below shows the status of the IKE and the IPSEC. The first one on the left, shows the status of IPSEC-ESP and the one on the right, shows the status of the IKE.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="IKe-statis.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10830_IKe-statis.JPG.jpg" style="width: 620px; height: 82px;" /&gt;&lt;/P&gt;&lt;P&gt;Again that depends on how long the outage was. All though the Lifetime of IPSEC-ESP and IKE can be ( like by default ) 1 hour and 8 hours respectively, the session timeout values for IPSEC-ESP and IKE are 3600 secs and 30 secs respectively. Lifetime determines the amount of time that the parties have to wait before they rekey again. Once a VPN is up, the firewall maintains sessions for IKE and IPSEC-ESP. If the firewall doesn't receive packets within the session timeout values, it discards the session. That being the case, had there been an outage, the session for IPSEC-ESP would still remain active for a longer duration than the IKE session ( When there is an ISP outage, no ESP or IKE packets would reach either firewall).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever a tunnel goes down, the firewall logs these events with a high severity, and we have the ability to send these events to a syslog server. You can get faster alerts of VPNs going down, by using SNMP servers, or through syslog servers, instead of relying on the WEB GUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 15:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22385#M16320</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2014-01-10T15:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel, delayed status update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22386#M16321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All 3 status lights were green even after multiple refreshes. This was 3 hours after the outage occurred. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Whenever a tunnel goes down, the firewall logs these events with a high severity, and we have the ability to send these events to a syslog server. You can get faster alerts of VPNs going down, by using SNMP servers, or through syslog servers, instead of relying on the WEB GUI.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not accept that as a proper method of knowing what is going on. If they have status indicators on the web gui, then they should do what is expected of them and properly indicate the status. If it requires some config changes to make it work better, that is fine, but the PA appliance should be able to provide us with adequate monitoring information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 15:36:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22386#M16321</guid>
      <dc:creator>carpediem79</dc:creator>
      <dc:date>2014-01-10T15:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel, delayed status update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22387#M16322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Carpediem,&lt;/P&gt;&lt;P&gt;Do you mean that the outage was for 3 hours, and yet the status lights were green during these 3 hours? We dont have any other extra configuration for the WEB GUI to reflect the correct status. In all my prior experience, I have seen the appropriate status show up whenever the tunnel went down ( even with both automatic and manual page refreshes, and on the cli ). The next time you encounter this issue, please raise a ticket with the TAC. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 15:49:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22387#M16322</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2014-01-10T15:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel, delayed status update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22388#M16323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will do. Just wanted to see if anyone else had run into a similar issue.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 15:50:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22388#M16323</guid>
      <dc:creator>carpediem79</dc:creator>
      <dc:date>2014-01-10T15:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel, delayed status update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22389#M16324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please try with tunnel monitoring to bring the tunnel down, while there will be an outage from ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="10819" alt="tunnel-monitoring.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/10819_tunnel-monitoring.JPG.jpg" style="width: 620px; height: 520px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also refer below mentioned knowledge base article for more information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6070"&gt;How to Verify if the IPSec Tunnel Monitoring is Working?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1323"&gt;Dead Peer Detection and Tunnel Monitoring&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/9909"&gt;Re: IPSEC-Tunnel Monitoring "tunnel-status-down"&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 15:52:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22389#M16324</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-10T15:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel, delayed status update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22390#M16325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did the system logs show that the VPN was down? If so, I think its then a GUI issue. What is the PANOS version that the box is running on? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 16:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22390#M16325</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2014-01-10T16:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel, delayed status update</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22391#M16326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tunnel monitoring sounds like it may do the trick. I am guessing that uses ping to verify the connection is up and then shows status as down once it fails to receive a response for the allotted time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, that is something I will test during one of our upcoming maintenance windows.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jan 2014 16:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-delayed-status-update/m-p/22391#M16326</guid>
      <dc:creator>carpediem79</dc:creator>
      <dc:date>2014-01-10T16:21:48Z</dc:date>
    </item>
  </channel>
</rss>

