<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec Phase 2 Lifesize Coutdown in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29871#M21833</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it does show life&lt;STRONG&gt;time&lt;/STRONG&gt;. I was looking for the life&lt;STRONG&gt;size&lt;/STRONG&gt;. There is a mention of it in the flow output,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; packets received &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; when lifetime expired:0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; when lifesize expired:0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But that's not about what the current lifesize counter is at. I guess you can use the encapsulated and decapsupated byte counts to figure it out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Oct 2014 21:55:18 GMT</pubDate>
    <dc:creator>cosx</dc:creator>
    <dc:date>2014-10-27T21:55:18Z</dc:date>
    <item>
      <title>IPsec Phase 2 Lifesize Coutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29868#M21830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On an Phase 2 IPsec SA with a non-zero lifesize, I see the proposed initial lifesize in the "show vpn ipsec-sa" output,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;crclark@&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;redacted&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;-pa5050b(active)&amp;gt; show vpn ipsec-sa tunnel &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;redacted&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;-cisco-gw&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;GwID/client IP&amp;nbsp; TnID Peer-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel(Gateway)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Algorithm&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SPI(in)&amp;nbsp; SPI(out) life(Sec/KB)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;--------------- ---- ------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------&amp;nbsp; -------- ------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp; 190 &amp;lt;redacted&amp;gt;.4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;redacted&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;-cisco-gw:csx-net-192.168.0.0(&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;reda&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; ESP/3DES/SHA1 AE3A4D8C 46E57EF1&amp;nbsp;&amp;nbsp; 1549/4608000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp; 191 &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;redacted&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;.4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;redacted&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;-cisco-gw:csx-net-192.168.6.0(&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;reda&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; ESP/3DES/SHA1 CB4FE221 8B5EF149&amp;nbsp;&amp;nbsp; 1557/4608000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp; 194 &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;redacted&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;.4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;redacted&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;-cisco-gw:csx-net-192.168.1.0(&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;reda&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; ESP/3DES/SHA1 911952E8 F67725C5&amp;nbsp;&amp;nbsp; 1535/4608000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp; 195 &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;redacted&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;.4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;redacted&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;-cisco-gw:csx-net-192.168.108.0(&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;lt;re&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; ESP/3DES/SHA1 DF7DA529 2899C3B7&amp;nbsp;&amp;nbsp; 1011/4608000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Show IPSec SA: Total 6 tunnels found. 4 ipsec sa found.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unlike the lifetime, the lifesize is not decrementing as data goes over the tunnel. So I have two questions,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Where can I find the actual lifesize remaining on a tunnel?&lt;/P&gt;&lt;P&gt;2) Or does PAN-OS not actually track lifesize?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 18:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29868#M21830</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2013-02-15T18:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Phase 2 Lifesize Coutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29869#M21831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using this kb &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1236"&gt; CLI Commands to Status, Clear, Restore, and Monitor an IPSEC VPN Tunnel&lt;/A&gt; show vpn flow tunnel-id X, but I'm not sure&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Nov 2013 19:11:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29869#M21831</guid>
      <dc:creator>GLastra</dc:creator>
      <dc:date>2013-11-28T19:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Phase 2 Lifesize Coutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29870#M21832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;show&amp;nbsp; vpn flow tunnel-id will show the lifetime remaining&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2014 21:35:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29870#M21832</guid>
      <dc:creator>achalla</dc:creator>
      <dc:date>2014-10-27T21:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Phase 2 Lifesize Coutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29871#M21833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it does show life&lt;STRONG&gt;time&lt;/STRONG&gt;. I was looking for the life&lt;STRONG&gt;size&lt;/STRONG&gt;. There is a mention of it in the flow output,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; packets received &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; when lifetime expired:0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; when lifesize expired:0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But that's not about what the current lifesize counter is at. I guess you can use the encapsulated and decapsupated byte counts to figure it out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Oct 2014 21:55:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29871#M21833</guid>
      <dc:creator>cosx</dc:creator>
      <dc:date>2014-10-27T21:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Phase 2 Lifesize Coutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29872#M21834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hello &lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="7388" data-username="cosx" href="https://live.paloaltonetworks.com/people/cosx" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;cosx,&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Agree with you.&amp;nbsp; Life-size is the amount of data that the key can use for encryption and we do keep track of it being decremented so as to re-key once the lifesize limit is reached.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;But just that it is not displayed unlike Life-time. &lt;/STRONG&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Since it appears under IPsec crypto profiles, It can monitored through the "&amp;gt;show vpn ipsec-sa" command that you are already aware of.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;I believe the only way for us to track it live would be through "encap bytes" under show vpn flow command.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 12px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Oct 2014 00:33:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/29872#M21834</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-10-28T00:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Phase 2 Lifesize Coutdown</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/88525#M43495</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23921"&gt;@tshiv﻿&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your explanation it's clear about life-size.&lt;/P&gt;
&lt;P&gt;I have problem with a VPN Tunnel, for some reason peers involved are taking long time to re-establish it.&lt;/P&gt;
&lt;P&gt;What does it means this one:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"lifetime 3600 Sec lifesize unlimited"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can see this message in system logs; Can it cause issue when both peers are trying to re-negotiate VPN tunnel?&lt;/P&gt;
&lt;P&gt;I need to configure a specific parameter for life-size?&lt;/P&gt;
&lt;P&gt;Is that possible?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Luca&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS. Your image is the best that I ever seen on this community .. I'm Naruto's fan too haha &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 10:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-phase-2-lifesize-coutdown/m-p/88525#M43495</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-06-17T10:50:51Z</dc:date>
    </item>
  </channel>
</rss>

