<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN tunnel no longer working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29458#M21498</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case it was the combination of downgrading and clearing the ike session in Discard state.&lt;/P&gt;&lt;P&gt;Tunnels did not come up after downgrade as their was a stale ike session&amp;nbsp; on the firewall.&lt;/P&gt;&lt;P&gt;Typically in this case ike-manager logs would show&amp;nbsp; message "&lt;SPAN style="font-size: 8.5pt; font-family: 'MS Shell Dlg','sans-serif'; color: black;"&gt;Phase-2 rekey request ignored: previous request still in progress&lt;/SPAN&gt;"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jul 2012 17:41:57 GMT</pubDate>
    <dc:creator>UhMayYeah</dc:creator>
    <dc:date>2012-07-06T17:41:57Z</dc:date>
    <item>
      <title>IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29451#M21491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a few VPN tunnels between our PA-2050 (in HA cluster) and some WatchGuard firewalls (different models). We migrated these tunnels to the PA-2050 a few weeks ago and they ran stable. Now suddenly two of 10 tunnels are down and we don't get them back up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what we tried so far:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Rebooting the WatchGuard firewalls&lt;/P&gt;&lt;P&gt;- Suspending the active PA-2050 so the standby HA device takes over&lt;/P&gt;&lt;P&gt;- Removing the VPN config on the WatchGuards and rebuild them (only VPN part)&lt;/P&gt;&lt;P&gt;- Overwrite the PSK on both ends&lt;/P&gt;&lt;P&gt;- On the PA-2050 CLI: &lt;SPAN style="color: #000000; font-family: 'courier new', courier; font-size: 12px; background-color: #ffffff;"&gt;clear vpn ike-sa gateway&lt;/SPAN&gt; &amp;lt;gw-name&amp;gt; and &lt;SPAN style="color: #000000; font-family: 'courier new', courier; font-size: 12px; background-color: #ffffff;"&gt;clear vpn ipsec-sa tunnel &amp;lt;tunnel-name&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- some more small stuff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config is the same on all tunnels, including the two not working...&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA_Gateway_Settings.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3191_PA_Gateway_Settings.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA_Tunnel_Settings.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3192_PA_Tunnel_Settings.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PA_Logs.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3193_PA_Logs.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any inputs would on how we can further troubleshoot the issue would be much appreciated. The connection by the way is working. We can ping the endpoints mutually and we can also access the external admin interface of the remote WatchGuard firewalls...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 16:47:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29451#M21491</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-05T16:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29452#M21492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you try downgrading to Content version : &lt;SPAN style="color: #666666; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: -webkit-auto; background-color: #f3f3f3;"&gt;315-1427&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Saw couple of cases where this worked for&amp;nbsp; me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 18:42:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29452#M21492</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-07-05T18:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29453#M21493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We managed to get one of the two tunnels up by changing the external IP address of the tunnel endpoint on the PA-2050 side. We have multiple external IP addresses and all tunnels were configured to use the same IP. At the time we changed the IP on one of the tunnels not working it came back up... We tried the same for the other tunnel still down and it didn't help...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of the reverts back to any of the following versions worked for us:&lt;/P&gt;&lt;P&gt;- 316-1432&lt;/P&gt;&lt;P&gt;- 315-1427&lt;/P&gt;&lt;P&gt;- 314-1424&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the last two (315 and 314) we could only install the Content package using Panorama. It was not possible to also install the App package of that version (error message we got was: No matching contents package found in panupv2-all-apps-&amp;lt;version&amp;gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 20:12:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29453#M21493</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-05T20:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29454#M21494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After countless trials we finally got the last tunnel up as well. It came back up when we cleared the IPSec/IKE session for that tunnel on the PA-2050.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 21:14:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29454#M21494</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-05T21:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29455#M21495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A longshot here but did these problems start last sunday (1st july)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im thinking of the leapsecond stuff...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 12:21:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29455#M21495</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-07-06T12:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29456#M21496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having the same issue, VPN tunnels are not working to a Fortigate 310B. Rebooting the PA-500 solves it temporarily and then it dies again a day later. Clearing out the VPN IKE, IPSEC, and flow does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just keep getting IKE timeouts. I will try to revert content but I have a feeling it might be a software issue. Currently running 4.1.6. Any known issues with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-J&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 12:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29456#M21496</guid>
      <dc:creator>jthompson1</dc:creator>
      <dc:date>2012-07-06T12:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29457#M21497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We're running OS 4.1.6 as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It might be that the issue has been fixed on our side by reverting back to Content version older than 316-1432 as Ameya suggested. We tested so many different settings to get the tunnel up that we're now unable to tell what setting(s) fixed it in the end...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 15:46:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29457#M21497</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-06T15:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29458#M21498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case it was the combination of downgrading and clearing the ike session in Discard state.&lt;/P&gt;&lt;P&gt;Tunnels did not come up after downgrade as their was a stale ike session&amp;nbsp; on the firewall.&lt;/P&gt;&lt;P&gt;Typically in this case ike-manager logs would show&amp;nbsp; message "&lt;SPAN style="font-size: 8.5pt; font-family: 'MS Shell Dlg','sans-serif'; color: black;"&gt;Phase-2 rekey request ignored: previous request still in progress&lt;/SPAN&gt;"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 17:41:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29458#M21498</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-07-06T17:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29459#M21499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've downgraded to 4.1.4. The content change didn't work. We'll see how long the tunnel stays up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-J&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 17:45:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29459#M21499</guid>
      <dc:creator>jthompson1</dc:creator>
      <dc:date>2012-07-06T17:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29460#M21500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason, I think Ameya is totally right. Reverting back to an older apps/content version alone didn't work for me. I had to explicitly close the stale IKE sessions using the Session Browser. I guess your OS downgrade worked because your box restarted after the downgrade which also clears out all stale sessions...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OS version 4.1.6 works great for us.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 18:43:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29460#M21500</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-06T18:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29461#M21501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah I'll have to see... problem is I can reboot and it just comes back. I will try other methods of clearing out the stale sessions but it's still a problem Palo Alto has to address. When a session ends a tunnel should re-establish and it doesn't, instead it just hangs. Not good. I'll update this thread if I find anything else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-J&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 19:26:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29461#M21501</guid>
      <dc:creator>jthompson1</dc:creator>
      <dc:date>2012-07-06T19:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29462#M21502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your side gets this "timeouts" log entries it would be interesting to see what the logs on the other side are (if its possible to get them).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 21:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29462#M21502</guid>
      <dc:creator>User_333</dc:creator>
      <dc:date>2012-07-06T21:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29463#M21503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For our client problems started with&lt;/P&gt;&lt;P&gt;"&lt;EM class="t a"&gt;&lt;EM class="t"&gt;Application&lt;/EM&gt;&lt;/EM&gt; &lt;EM class="t"&gt;Identification&lt;/EM&gt; &lt;EM class="t"&gt;package&lt;/EM&gt; &lt;EM class="t"&gt;upgraded&lt;/EM&gt; &lt;EM class="t"&gt;from&lt;/EM&gt; &lt;EM class="t"&gt;version&lt;/EM&gt; &lt;EM class="t"&gt;&lt;EM class="t"&gt;316&lt;/EM&gt;-&lt;EM class="t"&gt;1432&lt;/EM&gt;&lt;/EM&gt; &lt;EM class="t"&gt;to&lt;/EM&gt; &lt;EM class="t"&gt;&lt;EM class="t"&gt;317&lt;/EM&gt;-&lt;EM class="t"&gt;1438&lt;/EM&gt;&lt;/EM&gt; &lt;EM class="t"&gt;by&lt;/EM&gt; &lt;EM class="t"&gt;Auto&lt;/EM&gt; &lt;EM class="t"&gt;update&lt;/EM&gt; &lt;EM class="t h"&gt;agent"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;and the ike traffic was sometimes recognized or maybe not recognized as "unknown-udp".&lt;/P&gt;&lt;P&gt;I added a rule with service to allow udp:500 between VPN peers as a quick fix which seems to work so far.&lt;EM class="t h"&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM class="t h"&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;You might also want to verify ike sessions (show session all filter destination-port 500) and do some cleanup if they are in discard state.&lt;EM class="t h"&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2012 15:26:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29463#M21503</guid>
      <dc:creator>Support_CC</dc:creator>
      <dc:date>2012-07-07T15:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29464#M21504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We suddenly started getting in the last couple of weeks.&amp;nbsp; Our VPN had been solid as rock for a few months and then after an issue with the routing along the way (our ISP) the VPN refused to recover unless we rebooted.&amp;nbsp; It happened again over the weekend.&amp;nbsp; I am not aware of any issues with the ISP this time however we had to reboot our PA-500 (4.1.5) to get the connection back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will see if next time this occurs I can clear out the stale sessions&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 07:44:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29464#M21504</guid>
      <dc:creator>pg_itdept</dc:creator>
      <dc:date>2012-07-09T07:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29465#M21505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We noticed that it's somtimes necessary to not only clear the stale session but also to clear the vpn flow of that tunnel:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. &lt;SPAN style="font-family: 'courier new', courier;"&gt;clear session id &amp;lt;value&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2. &lt;SPAN style="font-family: 'courier new', courier;"&gt;clear vpn flow tunnel-id &amp;lt;value&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 07:53:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29465#M21505</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-09T07:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29466#M21506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for that oschuler will try it next time&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 08:00:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29466#M21506</guid>
      <dc:creator>pg_itdept</dc:creator>
      <dc:date>2012-07-09T08:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29467#M21507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like the latest release (version 318) contains modifications on the 'ike' decoder. We'll install it on Sunday, hopefully the issues are gone with it...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 06:11:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29467#M21507</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-07-11T06:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29468#M21508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK our VPN is lasting for 28 hours with an 8 hour lifetime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having just got it back, it would appear that the UDP packets are not being correctly identified as IKE and being dropped at the firewall. I am guessing this is on a re-negotiation of the link.&amp;nbsp; I just looked for 318 and there was no sign of it so I will keep an eye on it being available&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 09:59:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29468#M21508</guid>
      <dc:creator>pg_itdept</dc:creator>
      <dc:date>2012-07-11T09:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN tunnel no longer working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29469#M21509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't had an issue since reverting back to 4.1.4. Perhaps there was just an issue with the install...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When 4.1.7 is released I'll try that along with the 318 content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-J&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 13:53:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-tunnel-no-longer-working/m-p/29469#M21509</guid>
      <dc:creator>jthompson1</dc:creator>
      <dc:date>2012-07-12T13:53:17Z</dc:date>
    </item>
  </channel>
</rss>

