<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN phase 1 renegotiation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase-1-renegotiation/m-p/34540#M25343</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hulk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;I enabled passive setting and was getting packet drops. It was working before I enabled the passive setting. I removed the setting and the pings are working now again. But I am sure the packet with drop once the renegotiation starts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shyam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Nov 2013 04:03:58 GMT</pubDate>
    <dc:creator>shyams</dc:creator>
    <dc:date>2013-11-06T04:03:58Z</dc:date>
    <item>
      <title>IPSEC VPN phase 1 renegotiation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase-1-renegotiation/m-p/34538#M25341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing packet drops whenever the phase 1 re-negotiates. The SA gets expired and deleted but it takes 20 minutes for it to start the P1 phase again. In that period the traffic times out until the P1 starts again after 20 minutes. Below are the logs. I have replaced&amp;nbsp; our gateway address with xx.xx.xx.xx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2013-11-05 10:24:02 [INFO]: ====&amp;gt; PHASE-1 SA LIFETIME EXPIRED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Expired SA: xx.xx.xx.xx[500]-211.13.205.150[500] cookie:cf98f03c954db3ed:53951433f27d287ci &amp;lt;====&lt;/P&gt;&lt;P&gt;2013-11-05 10:24:02 [INFO]: ====&amp;gt; PHASE-1 SA DELETED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Deleted SA: xx.xx.xx.xx[500]-211.13.205.150[500] cookie:cf98f03c954db3ed:53951433f27d287ci &amp;lt;====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2013-11-05 10:43:59 [INFO]: IPsec-SA request for 211.13.205.150 queued since no phase1 found&lt;/P&gt;&lt;P&gt;2013-11-05 10:43:59 [PROTO_NOTIFY]: ====&amp;gt; PHASE-1 NEGOTIATION STARTED AS INITIATOR, MAIN MODE &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Initiated SA: xx.xx.xx.xx[500]-211.13.205.150[500] cookie:a6f4545850bdaa6c:0000000000000000 &amp;lt;====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2013-11-05 10:44:00 [PROTO_NOTIFY]: ====&amp;gt; PHASE-1 NEGOTIATION SUCCEEDED AS INITIATOR, MAIN MODE &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Established SA: xx.xx.xx.xx[500]-211.13.205.150[500] cookie:a6f4545850bdaa6c:c8f5e6db76ec5d46 lifetime 6400 Sec &amp;lt;====&lt;/P&gt;&lt;P&gt;2013-11-05 10:44:00 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Initiated SA: xx.xx.xx.xx[500]-211.13.205.150[500] message id:0xB0FD55D5 &amp;lt;====&lt;/P&gt;&lt;P&gt;2013-11-05 10:44:00 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION SUCCEEDED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Established SA: xx.xx.xx.xx[500]-211.13.205.150[500] message id:0xB0FD55D5, SPI:0x9AD00707/0x0F93DFE1 &amp;lt;====&lt;/P&gt;&lt;P&gt;2013-11-05 10:44:00 [INFO]: SADB_UPDATE ul_proto=255 src=211.13.205.150[500] dst=xx.xx.xx.xx[500] satype=ESP samode=tunl spi=0x9AD00707 authtype=MD5 enctype=NULL_ENC lifetime soft time=6400 bytes=0 hard time=6400 bytes=0&lt;/P&gt;&lt;P&gt;2013-11-05 10:44:00 [INFO]: SADB_ADD ul_proto=255 src=xx.xx.xx.xx[500] dst=211.13.205.150[500] satype=ESP samode=tunl spi=0x0F93DFE1 authtype=MD5 enctype=NULL_ENC lifetime soft time=6400 bytes=0 hard time=6400 bytes=0&lt;/P&gt;&lt;P&gt;2013-11-05 10:44:00 [INFO]: IPsec-SA established: ESP/Tunnel 211.13.205.150[500]-&amp;gt;xx.xx.xx.xx[500] spi=2597324551(0x9ad00707)&lt;/P&gt;&lt;P&gt;2013-11-05 10:44:00 [PROTO_NOTIFY]: ====&amp;gt; IPSEC KEY INSTALLATION SUCCEEDED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Installed SA: xx.xx.xx.xx[500]-211.13.205.150[500] SPI:0x9AD00707/0x0F93DFE1 lifetime 6400 Sec lifesize unlimited &amp;lt;====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shyam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 03:12:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase-1-renegotiation/m-p/34538#M25341</guid>
      <dc:creator>shyams</dc:creator>
      <dc:date>2013-11-05T03:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN phase 1 renegotiation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase-1-renegotiation/m-p/34539#M25342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shyam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the log messages &lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; 10:24:02 -------- we received the phase-I delete message --------- &amp;gt; [INFO]: ====&amp;gt; PHASE-1 SA DELETED &amp;lt;====&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; 10:43:59 [PROTO_NOTIFY]: ====&amp;gt; PHASE-1 NEGOTIATION STARTED AS INITIATOR, MAIN MODE &amp;lt;====&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;After 20 minutes we got the Phase-I negotiation messages and PAN &lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;were acting&lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt; as an initiator.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;Could you please set the PAN device as a responder ( passive mode) and let me know if that makes any difference. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;FYI..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;&lt;IMG alt="IPSec-passive.jpg" class="jive-image" height="404" src="https://live.paloaltonetworks.com/legacyfs/online/9646_IPSec-passive.jpg" style="width: 485.77562326869804px; height: 405px;" width="486" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 02:51:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase-1-renegotiation/m-p/34539#M25342</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-11-06T02:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN phase 1 renegotiation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase-1-renegotiation/m-p/34540#M25343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hulk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;I enabled passive setting and was getting packet drops. It was working before I enabled the passive setting. I removed the setting and the pings are working now again. But I am sure the packet with drop once the renegotiation starts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shyam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 04:03:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-phase-1-renegotiation/m-p/34540#M25343</guid>
      <dc:creator>shyams</dc:creator>
      <dc:date>2013-11-06T04:03:58Z</dc:date>
    </item>
  </channel>
</rss>

