<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN flapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-flapping/m-p/32655#M23917</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this was the problem &lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="loading" href="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB8530" title="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB8530"&gt;http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB8530&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Jul 2015 17:58:39 GMT</pubDate>
    <dc:creator>SOC_CSG</dc:creator>
    <dc:date>2015-07-30T17:58:39Z</dc:date>
    <item>
      <title>VPN flapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-flapping/m-p/32653#M23915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, we have configured a VPN site-to-site between Juniper SSG and PA3020. The tunnel is flapping up/down. The VPN is well-configured and we have configured VPN monitor with Rekey option in the SSG.&amp;nbsp; How could we know why the tunnel is flapping all the time???&amp;nbsp; i attached the PA logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2015-07-30 16:52:11 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION SUCCEEDED AS RESPONDER, (QUICK MODE) &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Established SA: 116.x.x.x[500]-121.x.x.x[500] message id:0xF6C5386E, SPI:0xB9D02A28/0x598B9BDB &amp;lt;====&lt;/P&gt;&lt;P&gt;2015-07-30 16:52:11 [INFO]: SADB_UPDATE ul_proto=255 src=121.x.x.x[500] dst=&lt;SPAN style="font-size: 13.3333330154419px;"&gt;116.x.x.x&lt;/SPAN&gt;[500] satype=ESP samode=tunl spi=0xB9D02A28 authtype=SHA1 enctype=3DES lifetime soft time=3600 bytes=0 hard time=3600 bytes=0&lt;/P&gt;&lt;P&gt;2015-07-30 16:52:11 [INFO]: SADB_ADD ul_proto=255 src=&lt;SPAN style="font-size: 13.3333330154419px;"&gt;116.x.x.x&lt;/SPAN&gt;[500] dst=&lt;SPAN style="font-size: 13.3333330154419px;"&gt;121.x.x.x&lt;/SPAN&gt;[500] satype=ESP samode=tunl spi=0x598B9BDB authtype=SHA1 enctype=3DES lifetime soft time=3600 bytes=0 hard time=3600 bytes=0&lt;/P&gt;&lt;P&gt;2015-07-30 16:52:11 [INFO]: IPsec-SA established: ESP/Tunnel &lt;SPAN style="font-size: 13.3333330154419px;"&gt;121.x.x.x&lt;/SPAN&gt;[500]-&amp;gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;116.x.x.x&lt;/SPAN&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;[500]&lt;/SPAN&gt;[500] spi=3117427240(0xb9d02a28)&lt;/P&gt;&lt;P&gt;2015-07-30 16:52:11 [PROTO_NOTIFY]: ====&amp;gt; IPSEC KEY INSTALLATION SUCCEEDED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Installed SA: &lt;SPAN style="font-size: 13.3333330154419px;"&gt;116.x.x.x&lt;/SPAN&gt;[500]-&lt;SPAN style="font-size: 13.3333330154419px;"&gt;121.x.x.x&lt;/SPAN&gt;[500] SPI:0xB9D02A28/0x598B9BDB lifetime 3600 Sec lifesize unlimited &amp;lt;====&lt;/P&gt;&lt;P&gt;2015-07-30 16:52:11 [INFO]: keymirror add start ++++++++++++++++&lt;/P&gt;&lt;P&gt;2015-07-30 16:52:11 [INFO]: keymirror add for gw e, tn 20, selfSPI B9D02A28, retcode 0.&lt;/P&gt;&lt;P&gt;[PROTO_NOTIFY]: ====&amp;gt; IPSEC KEY DELETED &amp;lt;====&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 15:20:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-flapping/m-p/32653#M23915</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-07-30T15:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN flapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-flapping/m-p/32654#M23916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please provide a output of the command&lt;/P&gt;&lt;P&gt;tail lines 300 mp-log ikemgr.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run the above command when rekey is happening. Also make sure that lifetime is matching on both side for both phases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase 2 lifetime should be less than phase 1 lifetime.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 16:15:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-flapping/m-p/32654#M23916</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-07-30T16:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN flapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-flapping/m-p/32655#M23917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this was the problem &lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="loading" href="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB8530" title="http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB8530"&gt;http://kb.juniper.net/InfoCenter/index?page=content&amp;amp;id=KB8530&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 17:58:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-flapping/m-p/32655#M23917</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-07-30T17:58:39Z</dc:date>
    </item>
  </channel>
</rss>

