<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 6.1.2 LSVPN/VPN Hang - Reboot Required in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/6-1-2-lsvpn-vpn-hang-reboot-required/m-p/39139#M28699</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;I am having some issues as well with 6.1.2 and LSVPN to hub which is on 6.0.5h3.&amp;nbsp; This is vaguely referenced here by others &lt;A href="https://live.paloaltonetworks.com/message/50436"&gt;Anyone use 6.1.2? Is it stable&lt;/A&gt; where everyone affected, says yeah there's this IPSEC issue and never actually describes what they are seeing.&amp;nbsp; So I'm going to detail what I am seeing.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;I had two PA-200 devices overnight go offline, same ISP&lt;SPAN style="font-size: 13.3333330154419px;"&gt;(Could have been coincidence)&lt;/SPAN&gt; on US-EST but at different times.&amp;nbsp; My routers could see each other properly at either end but the PA-200 satellite devices would not respond on their public facing IP's at all.&amp;nbsp; I could route right up to the devices but could not get in on https via port 4443 or via ssh.&amp;nbsp; Definitely seemed like a bug that might have been caused by some blip in the ISP maybe but the only way to fix it was to reboot the devices.&amp;nbsp; As soon as they rebooted LSVPN came back up.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reading through the satellite's syslogs at the time the device went down, there's no particular indication other than 'GlobalProtect Satellite connection to gateway failed.&amp;nbsp; Satellite failed to connect to Gateway 'IP-w.x.y.z' due to "connection failed".'&amp;nbsp; This error continued until we rebooted the PA-200's at which point they immediately came back.&amp;nbsp; Devices showed in ARP on routers and everything but they wouldn't respond whatsoever to any Layer3 requests/comm.&amp;nbsp; It's like the security and interface management policies just plain failed.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** An additional but somewhat related issue I have been having is with devices indicating active LSVPN connections but in fact they are not passing any traffic.&amp;nbsp; Tunnel monitor is set to the hub device's tunnel interface IP.&amp;nbsp; This only happens to one device at a time and all other of my 40 or so PA-200's stay active without issue.&amp;nbsp; It seems sometimes this happens when the IP changes in a failover scenario and others it seems like it just drops off after a rekey.&amp;nbsp; I know there are some fixes in indicated in 6.1.2 for this and since my hubs are not yet on 6.1.2 I did not reach out to support on this yet.&amp;nbsp; But now I don't think we can go to 6.1.2 if there is a known bug/issue.&amp;nbsp; I had to have people drive in and reboot these thigns in the middle of the night.&amp;nbsp; Needless to say they are not feeling very happy about our 'upgrade' to Palo Alto from tried and true but old Netscreen/SSGs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Mar 2015 13:45:06 GMT</pubDate>
    <dc:creator>dusk2dusk</dc:creator>
    <dc:date>2015-03-12T13:45:06Z</dc:date>
    <item>
      <title>6.1.2 LSVPN/VPN Hang - Reboot Required</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/6-1-2-lsvpn-vpn-hang-reboot-required/m-p/39139#M28699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;I am having some issues as well with 6.1.2 and LSVPN to hub which is on 6.0.5h3.&amp;nbsp; This is vaguely referenced here by others &lt;A href="https://live.paloaltonetworks.com/message/50436"&gt;Anyone use 6.1.2? Is it stable&lt;/A&gt; where everyone affected, says yeah there's this IPSEC issue and never actually describes what they are seeing.&amp;nbsp; So I'm going to detail what I am seeing.&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;I had two PA-200 devices overnight go offline, same ISP&lt;SPAN style="font-size: 13.3333330154419px;"&gt;(Could have been coincidence)&lt;/SPAN&gt; on US-EST but at different times.&amp;nbsp; My routers could see each other properly at either end but the PA-200 satellite devices would not respond on their public facing IP's at all.&amp;nbsp; I could route right up to the devices but could not get in on https via port 4443 or via ssh.&amp;nbsp; Definitely seemed like a bug that might have been caused by some blip in the ISP maybe but the only way to fix it was to reboot the devices.&amp;nbsp; As soon as they rebooted LSVPN came back up.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reading through the satellite's syslogs at the time the device went down, there's no particular indication other than 'GlobalProtect Satellite connection to gateway failed.&amp;nbsp; Satellite failed to connect to Gateway 'IP-w.x.y.z' due to "connection failed".'&amp;nbsp; This error continued until we rebooted the PA-200's at which point they immediately came back.&amp;nbsp; Devices showed in ARP on routers and everything but they wouldn't respond whatsoever to any Layer3 requests/comm.&amp;nbsp; It's like the security and interface management policies just plain failed.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*** An additional but somewhat related issue I have been having is with devices indicating active LSVPN connections but in fact they are not passing any traffic.&amp;nbsp; Tunnel monitor is set to the hub device's tunnel interface IP.&amp;nbsp; This only happens to one device at a time and all other of my 40 or so PA-200's stay active without issue.&amp;nbsp; It seems sometimes this happens when the IP changes in a failover scenario and others it seems like it just drops off after a rekey.&amp;nbsp; I know there are some fixes in indicated in 6.1.2 for this and since my hubs are not yet on 6.1.2 I did not reach out to support on this yet.&amp;nbsp; But now I don't think we can go to 6.1.2 if there is a known bug/issue.&amp;nbsp; I had to have people drive in and reboot these thigns in the middle of the night.&amp;nbsp; Needless to say they are not feeling very happy about our 'upgrade' to Palo Alto from tried and true but old Netscreen/SSGs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Mar 2015 13:45:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/6-1-2-lsvpn-vpn-hang-reboot-required/m-p/39139#M28699</guid>
      <dc:creator>dusk2dusk</dc:creator>
      <dc:date>2015-03-12T13:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: 6.1.2 LSVPN/VPN Hang - Reboot Required</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/6-1-2-lsvpn-vpn-hang-reboot-required/m-p/39140#M28700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;This is bug in panos (any version). My problem is similar but effect is the same – FW hangs and reboot required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 11.0pt; font-family: 'Calibri',sans-serif; color: #1f497d;"&gt;Palo write: &lt;/SPAN&gt;&lt;/P&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;&amp;gt; Do we know what is the main reason of this problem ?&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt; &lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;so far we know that one of the internal timers gets stuck, it is not&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;clear in which conditions that happens&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt; &lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;&amp;gt; Is there any configuration change we can do to minimize these downsides ?&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt; &lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;disabling the qos, which you already did is the only one known so far to&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;limit how often it happens&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt; &lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;&amp;gt; When do you plan to fully address this issue ?&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt; &lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;once the releases with additional debugs are out in the field this&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;should accelerate the resolution. No other time frame can be provided at&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt;the moment&lt;/EM&gt;&lt;/PRE&gt;&lt;PRE style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;EM&gt; &lt;/EM&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt; &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt; &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Mar 2015 13:18:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/6-1-2-lsvpn-vpn-hang-reboot-required/m-p/39140#M28700</guid>
      <dc:creator>LCMember2041</dc:creator>
      <dc:date>2015-03-18T13:18:26Z</dc:date>
    </item>
  </channel>
</rss>

