<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable an IPSec Tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38368#M28105</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree that this would be a nice feature. I ran into an issue a couple of days ago where the VPN link between our PA and a Cisco ASA died after a software upgrade on the PA. I had no way kick start the PA to get it to retry making a connection to the remote site. I had to go into the CLI to do this. Having buttons on the GUI to be able to test the link or reset the link would be handy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also noticed that the link status never even updated when the link went down, which is concerning.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Apr 2014 16:08:38 GMT</pubDate>
    <dc:creator>carpediem79</dc:creator>
    <dc:date>2014-04-25T16:08:38Z</dc:date>
    <item>
      <title>Disable an IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38363#M28100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to disable an IPSec VPN. I have currently blocked traffic both directions to the tunnel by using a Security Policies, but there should be a way to disable the tunnel in the IPSec configuration (or alternatively, disable the tunnel interface). I don't want to delete it, but I don't want it taking up processor speed for a tunnel that I don't want turned on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2014 14:23:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38363#M28100</guid>
      <dc:creator>blandis</dc:creator>
      <dc:date>2014-04-25T14:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Disable an IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38364#M28101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently, there isn't a nice "disable" button for IPSec Tunnel Configuration - but I do see the value in being able to disable tunnels at-will.&amp;nbsp; For this case, I have created an "IKE Gateway" called "disabled" and populated it with bogus information.&amp;nbsp; Then, when I need to disable a tunnel, I go change the IKE Gateway to "disabled" and commit.&amp;nbsp; It has the same effect - and I've deleted nothing.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2014 14:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38364#M28101</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2014-04-25T14:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Disable an IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38365#M28102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is a possible workaround, but it will still try to connect, using CPU and continuous log messages.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2014 14:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38365#M28102</guid>
      <dc:creator>blandis</dc:creator>
      <dc:date>2014-04-25T14:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Disable an IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38366#M28103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agreed - it's a workaround - not a complete solution. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ultimately, if you want a "disable" button in the IPSec configuration, you'll need to file a Feature Request with your local Palo Alto Networks sales engineer.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2014 14:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38366#M28103</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2014-04-25T14:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Disable an IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38367#M28104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually, this might cause alarms on the opposing firewall, which I don't want, so maybe a security block is a better solution anyways.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2014 15:26:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38367#M28104</guid>
      <dc:creator>blandis</dc:creator>
      <dc:date>2014-04-25T15:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Disable an IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38368#M28105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree that this would be a nice feature. I ran into an issue a couple of days ago where the VPN link between our PA and a Cisco ASA died after a software upgrade on the PA. I had no way kick start the PA to get it to retry making a connection to the remote site. I had to go into the CLI to do this. Having buttons on the GUI to be able to test the link or reset the link would be handy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also noticed that the link status never even updated when the link went down, which is concerning.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Apr 2014 16:08:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disable-an-ipsec-tunnel/m-p/38368#M28105</guid>
      <dc:creator>carpediem79</dc:creator>
      <dc:date>2014-04-25T16:08:38Z</dc:date>
    </item>
  </channel>
</rss>

