<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN restarts very often in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42533#M31229</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps to identify the problem but having to have replay-protection turned off for your vpn-tunnels is just bad...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Aug 2013 20:56:57 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-08-30T20:56:57Z</dc:date>
    <item>
      <title>IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42519#M31215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hallo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have defined a IPSec VPN connection with following params:&lt;/P&gt;&lt;P&gt;ike: 3des/sha1/dh5 Lifetime: 8 hours&lt;/P&gt;&lt;P&gt;ipsec: ESP/3des/sha1/dh5 Lifetime: 30 minutes (life size not set, shows 0MB)&lt;/P&gt;&lt;P&gt;ike gateway: main mode, DP enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The connection is established but in system log I see very often (every 5 sec.) tunnel is again and again down and up. We have packet lost about 0.5%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas? I've already configured the connection from scratch again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jacek.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log file:&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:39&amp;nbsp;&amp;nbsp;&amp;nbsp; ipsec-key-delete&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec key deleted. Deleted SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0x8C5FC8B5/0xFFFD0AD9.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:39&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-send-p2-delete&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE protocol IPSec SA delete message sent to peer. SPI:0x8C5FC8B5.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:38&amp;nbsp;&amp;nbsp;&amp;nbsp; ipsec-key-install&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec key installed. Installed SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0xDF1F9E37/0xFFFD0ADA lifetime 1800 Sec lifesize unlimited.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:38&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-nego-p2-succ&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE phase-2 negotiation is succeeded as initiator, quick mode. Established SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0xCFE39FEB, SPI:0xDF1F9E37/0xFFFD0ADA.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:38&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-nego-p2-start&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE phase-2 negotiation is started as initiator, quick mode. Initiated SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0xCFE39FEB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:35&amp;nbsp;&amp;nbsp;&amp;nbsp; ipsec-key-delete&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec key deleted. Deleted SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0xCDCD7E83/0xFFFD0AD8.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:35&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-send-p2-delete&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE protocol IPSec SA delete message sent to peer. SPI:0xCDCD7E83.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:34&amp;nbsp;&amp;nbsp;&amp;nbsp; ipsec-key-install&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec key installed. Installed SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0x8C5FC8B5/0xFFFD0AD9 lifetime 1800 Sec lifesize unlimited.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:34&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-nego-p2-succ&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE phase-2 negotiation is succeeded as initiator, quick mode. Established SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x756F7417, SPI:0x8C5FC8B5/0xFFFD0AD9.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:34&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-nego-p2-start&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE phase-2 negotiation is started as initiator, quick mode. Initiated SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x756F7417.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:31&amp;nbsp;&amp;nbsp;&amp;nbsp; ipsec-key-delete&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec key deleted. Deleted SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0xE36D50CD/0xFFFD0AD7.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:31&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-send-p2-delete&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE protocol IPSec SA delete message sent to peer. SPI:0xE36D50CD.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:30&amp;nbsp;&amp;nbsp;&amp;nbsp; ipsec-key-install&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec key installed. Installed SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0xCDCD7E83/0xFFFD0AD8 lifetime 1800 Sec lifesize unlimited.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:30&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-nego-p2-succ&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE phase-2 negotiation is succeeded as initiator, quick mode. Established SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x43C3E41C, SPI:0xCDCD7E83/0xFFFD0AD8.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:30&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-nego-p2-start&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE phase-2 negotiation is started as initiator, quick mode. Initiated SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x43C3E41C.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:27&amp;nbsp;&amp;nbsp;&amp;nbsp; ipsec-key-delete&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec key deleted. Deleted SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0x8D0BBED9/0xFFFD0AD6.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:27&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-send-p2-delete&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE protocol IPSec SA delete message sent to peer. SPI:0x8D0BBED9.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:26&amp;nbsp;&amp;nbsp;&amp;nbsp; ipsec-key-install&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec key installed. Installed SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0xE36D50CD/0xFFFD0AD7 lifetime 1800 Sec lifesize unlimited.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:26&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-nego-p2-succ&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE phase-2 negotiation is succeeded as initiator, quick mode. Established SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x15CF19C6, SPI:0xE36D50CD/0xFFFD0AD7.&lt;/P&gt;&lt;P&gt;2012/09/24 12:36:26&amp;nbsp;&amp;nbsp;&amp;nbsp; ike-nego-p2-start&amp;nbsp;&amp;nbsp;&amp;nbsp; IKE phase-2 negotiation is started as initiator, quick mode. Initiated SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x15CF19C6.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 10:52:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42519#M31215</guid>
      <dc:creator>chmielniak</dc:creator>
      <dc:date>2012-09-24T10:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42520#M31216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since it takes two to tango VPN - what do you have at the other side?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if possible, could you put one of those peers much closer to your PA to rule out any interference from the network(s) in between?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, how is your security policies setup for this traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And is your ipsec setup on a physical interface (which perhaps goes up and down?) or a loopback interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 03:58:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42520#M31216</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-09-25T03:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42521#M31217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have 3 VPNs running. The problem appeared after some update in 4.1.x with all 3 connections. I can control both sides of only one connection (it's cisco router IPSec with VTI). I've just deleted the configuration on both sides and recreated it with the same parameters and it works now.&lt;/P&gt;&lt;P&gt;The other two VPN partners haven't change a thing and it shows above problem.&lt;/P&gt;&lt;P&gt;All IPSec connections are setup on the same physical interface together with normal internet traffic. I observe no problems with the interface. Security policies allow ssh connections outgoing.&lt;/P&gt;&lt;P&gt;How can I see what makes the connections up and down?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 07:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42521#M31217</guid>
      <dc:creator>chmielniak</dc:creator>
      <dc:date>2012-09-25T07:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42522#M31218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure the Crypto settings are same on both the sides and try initiating the tunnel traffic from the remote side.&lt;/P&gt;&lt;P&gt;Also try configuring the ipsec-crypto to DH group to "no-pfs" on both the sides. Clear the VPN tunnels on the Palo Alto side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;admin@PA&amp;gt; clear vpn ike-sa gateway&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; &amp;lt;value&amp;gt;&amp;nbsp; clear for given IKE gateway&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;admin@PA&amp;gt; clear vpn ipsec-sa tunnel&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; &amp;lt;value&amp;gt;&amp;nbsp; clear for given VPN tunnel&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try initiate the tunnel from the cisco side. &lt;/P&gt;&lt;P&gt;Monitor the system logs on the firewall to see the IPSEC negotiation. Check to see if the tunnel comes up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which version of software are you using on the firewall? There is an issue with software release 4.1.5 where after an upgrade or intermittently IPSec VPN tunnel would not come up when Palo Alto Networks firewall initiates a &lt;/P&gt;&lt;P&gt;connection to a Cisco ASA device. [Bug # 39884] This issue was addressed in S/w 4.1.6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 08:10:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42522#M31218</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-09-25T08:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42523#M31219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have 4.1.7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot control the other side of tunnel. Those are partners, that request configuration according to their policy. I have checked the ipsec params requested. They are set correct on both sides. IPSec tunnel is established, but in log i can see those IKE deletes every ca. 10 sec. I had to disable information log on syslog.&lt;/P&gt;&lt;P&gt;One on VPNS ends on Fortinet. The only one VPN, that is working has no Proxy-ID defined. The other two with problems have Proxy Ids defined in IPSec tunnel.&lt;/P&gt;&lt;P&gt;I can see any reason for "IKE protocol IPSec SA delete message sent to peer". We experience long RTT and packet lost on those connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jacek.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 08:38:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42523#M31219</guid>
      <dc:creator>chmielniak</dc:creator>
      <dc:date>2012-09-25T08:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42524#M31220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to have a look at the ikemgr log on the firewall.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;admin@PA&amp;gt; tail follow yes mp-log ikemgr.log&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;The above log will be able to give detailed logging on the ike negotiation process that is done by the firewall&lt;/P&gt;&lt;P&gt;Try to clear the vpn flow using the commands that were given before and run the tail command.&lt;/P&gt;&lt;P&gt;Please open a support ticket with TAC to troubleshoot the issue if it is still not resolving. It would be great to have access to both the sides of the tunnel to debug/troubleshoot Ipsec.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 08:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42524#M31220</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-09-25T08:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42525#M31221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have disabled one vpn, so that I could cut the debug log for only one VPN. I set level with: &lt;EM&gt;debug ike global on normal&lt;BR /&gt;&lt;/EM&gt;I have resetted the connection. I have cut three phases delete/establish: (XX.XX.XX.XX is own IP, YY.YY.YY.YY is partner IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: panike_keyacquire_cb 2fe29fa8&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: IPsec-SA request for YY.YY.YY.YY queued since no phase1 found&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [PROTO_NOTIFY]: ====&amp;gt; PHASE-1 NEGOTIATION STARTED AS INITIATOR, MAIN MODE &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Initiated SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] cookie:6041d73ad3ab677f:0000000000000000 &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: received Vendor ID: DPD&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [PROTO_NOTIFY]: ====&amp;gt; PHASE-1 NEGOTIATION SUCCEEDED AS INITIATOR, MAIN MODE &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Established SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] cookie:6041d73ad3ab677f:90e8c84f5cf54d25 lifetime 28800 Sec &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Initiated SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x9395643A &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION SUCCEEDED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Established SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x9395643A, SPI:0xC1B84E56/0xFFFD4D90 &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: SADB_UPDATE ul_proto=255 src=YY.YY.YY.YY[500] dst=XX.XX.XX.XX[500] satype=ESP samode=tunl spi=0xC1B84E56 authtype=SHA1 enctype=3DES lifetime soft time=1800 bytes=0 hard time=1800 bytes=0&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: SADB_ADD ul_proto=255 src=XX.XX.XX.XX[500] dst=YY.YY.YY.YY[500] satype=ESP samode=tunl spi=0xFFFD4D90 authtype=SHA1 enctype=3DES lifetime soft time=1800 bytes=0 hard time=1800 bytes=0&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: IPsec-SA established: ESP/Tunnel YY.YY.YY.YY[500]-&amp;gt;XX.XX.XX.XX[500] spi=3250081366(0xc1b84e56)&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [PROTO_NOTIFY]: ====&amp;gt; IPSEC KEY INSTALLATION SUCCEEDED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Installed SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0xC1B84E56/0xFFFD4D90 lifetime 1800 Sec lifesize unlimited &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: keymirror add start ++++++++++++++++&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: keymirror add for gw 4, tn 8, selfSPI C1B84E56, retcode 0.&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: keymirror del start ----------------&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: keymirror del for gw 4, tn 8, selfSPI F703F0F5, retcode 0.&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [PROTO_NOTIFY]: ====&amp;gt; IPSEC KEY DELETED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Deleted SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0xF703F0F5/0xFFFD4D8E &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: SADB_DELETE ul_proto=0 src=XX.XX.XX.XX[500] dst=YY.YY.YY.YY[500] satype=ESP spi=0xF703F0F5&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:47 [INFO]: received PFKEY_DELETE seq=0 satype=ESP spi=0xF703F0F5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: panike_keyacquire_cb 2fe2ad98&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Initiated SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x173FBEFA &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION SUCCEEDED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Established SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0x173FBEFA, SPI:0x8605AB62/0xFFFD4D91 &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: SADB_UPDATE ul_proto=255 src=YY.YY.YY.YY[500] dst=XX.XX.XX.XX[500] satype=ESP samode=tunl spi=0x8605AB62 authtype=SHA1 enctype=3DES lifetime soft time=1800 bytes=0 hard time=1800 bytes=0&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: SADB_ADD ul_proto=255 src=XX.XX.XX.XX[500] dst=YY.YY.YY.YY[500] satype=ESP samode=tunl spi=0xFFFD4D91 authtype=SHA1 enctype=3DES lifetime soft time=1800 bytes=0 hard time=1800 bytes=0&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: IPsec-SA established: ESP/Tunnel YY.YY.YY.YY[500]-&amp;gt;XX.XX.XX.XX[500] spi=2248518498(0x8605ab62)&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [PROTO_NOTIFY]: ====&amp;gt; IPSEC KEY INSTALLATION SUCCEEDED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Installed SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0x8605AB62/0xFFFD4D91 lifetime 1800 Sec lifesize unlimited &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: keymirror add start ++++++++++++++++&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: keymirror add for gw 4, tn 8, selfSPI 8605AB62, retcode 0.&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: keymirror del start ----------------&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: keymirror del for gw 4, tn 8, selfSPI C1B84E56, retcode 0.&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [PROTO_NOTIFY]: ====&amp;gt; IPSEC KEY DELETED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Deleted SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0xC1B84E56/0xFFFD4D90 &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: SADB_DELETE ul_proto=0 src=XX.XX.XX.XX[500] dst=YY.YY.YY.YY[500] satype=ESP spi=0xC1B84E56&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:54 [INFO]: received PFKEY_DELETE seq=0 satype=ESP spi=0xC1B84E56&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:58 [INFO]: panike_keyacquire_cb 2fe29fa8&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:58 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION STARTED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Initiated SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0xFB43C451 &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:58 [PROTO_NOTIFY]: ====&amp;gt; PHASE-2 NEGOTIATION SUCCEEDED AS INITIATOR, (QUICK MODE) &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Established SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] message id:0xFB43C451, SPI:0x9838E09A/0xFFFD4D92 &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:58 [INFO]: SADB_UPDATE ul_proto=255 src=YY.YY.YY.YY[500] dst=XX.XX.XX.XX[500] satype=ESP samode=tunl spi=0x9838E09A authtype=SHA1 enctype=3DES lifetime soft time=1800 bytes=0 hard time=1800 bytes=0&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:58 [INFO]: SADB_ADD ul_proto=255 src=XX.XX.XX.XX[500] dst=YY.YY.YY.YY[500] satype=ESP samode=tunl spi=0xFFFD4D92 authtype=SHA1 enctype=3DES lifetime soft time=1800 bytes=0 hard time=1800 bytes=0&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:58 [INFO]: IPsec-SA established: ESP/Tunnel YY.YY.YY.YY[500]-&amp;gt;XX.XX.XX.XX[500] spi=2553864346(0x9838e09a)&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:58 [PROTO_NOTIFY]: ====&amp;gt; IPSEC KEY INSTALLATION SUCCEEDED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Installed SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0x9838E09A/0xFFFD4D92 lifetime 1800 Sec lifesize unlimited &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:58 [INFO]: keymirror add start ++++++++++++++++&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:58 [INFO]: keymirror add for gw 4, tn 8, selfSPI 9838E09A, retcode 0.&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:59 [INFO]: keymirror del start ----------------&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:59 [INFO]: keymirror del for gw 4, tn 8, selfSPI 8605AB62, retcode 0.&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:59 [PROTO_NOTIFY]: ====&amp;gt; IPSEC KEY DELETED &amp;lt;====&lt;/P&gt;&lt;P&gt;====&amp;gt; Deleted SA: XX.XX.XX.XX[500]-YY.YY.YY.YY[500] SPI:0x8605AB62/0xFFFD4D91 &amp;lt;====&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:59 [INFO]: SADB_DELETE ul_proto=0 src=XX.XX.XX.XX[500] dst=YY.YY.YY.YY[500] satype=ESP spi=0x8605AB62&lt;/P&gt;&lt;P&gt;2012-09-25 12:00:59 [INFO]: received PFKEY_DELETE seq=0 satype=ESP spi=0x8605AB62&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 10:16:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42525#M31221</guid>
      <dc:creator>chmielniak</dc:creator>
      <dc:date>2012-09-25T10:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42526#M31222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had similar problem with 4.1.6, after we changed our public ip where IPSEC terminated, after that VPN didnt work. Afcourse we adjusted configs &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;, only thing that was left is to do a restart. So i did restart dataplane, and everything start working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Nov 2012 17:25:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42526#M31222</guid>
      <dc:creator>agrgic</dc:creator>
      <dc:date>2012-11-25T17:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42527#M31223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you find a solution to your problem? We are experiencing the same thing on 5.0.3&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Mar 2013 04:41:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42527#M31223</guid>
      <dc:creator>rzg62s_BPC</dc:creator>
      <dc:date>2013-03-28T04:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42528#M31224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have disabled "Tunel Monitor" in IPSec Tunnels. It works only on PA-PA Connections.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Apr 2013 08:01:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42528#M31224</guid>
      <dc:creator>chmielniak</dc:creator>
      <dc:date>2013-04-04T08:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42529#M31225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all, We have had this issue on one of our boxes, it has been present in v4.16, v4.18h3 and v5.05.&lt;/P&gt;&lt;P&gt;We have stripped the VPN options back to the basics and checked all settings together but still we have issues.&lt;/P&gt;&lt;P&gt;This is between a PA and a Cisco ASA. It takes around 1-3hrs to re-establish the tunnel once the timeouts are hit.&lt;/P&gt;&lt;P&gt;I have tried clearing the SA's to refresh the tunnel but makes no difference, however restarting the dataplane although not instant&lt;/P&gt;&lt;P&gt;does bring the tunnel back up in around five minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If PA could chime in on this is would be appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Jul 2013 14:47:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42529#M31225</guid>
      <dc:creator>Mark1Sewell</dc:creator>
      <dc:date>2013-07-10T14:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42530#M31226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about the Cisco ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It wouldnt be the first time Cisco has a malfunction in their code...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jul 2013 08:09:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42530#M31226</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-07-11T08:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42531#M31227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In our case it was caused by the tunnel monitor, after un-selecting the tunnel monitor the phase 2 deletes were back to normal (instead of every 4 sec)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Aug 2013 18:21:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42531#M31227</guid>
      <dc:creator>Support_LTC</dc:creator>
      <dc:date>2013-08-26T18:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42532#M31228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also it's worth to try to deactivate the replay-protection on phase 2. This just helped in my case dealing with inter vendor VPN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 05:43:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42532#M31228</guid>
      <dc:creator>Unibw</dc:creator>
      <dc:date>2013-08-30T05:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42533#M31229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps to identify the problem but having to have replay-protection turned off for your vpn-tunnels is just bad...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Aug 2013 20:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42533#M31229</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-08-30T20:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42534#M31230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@Support_LTC:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was also our experience. Your suggestion to remove the tunnel monitor resolved our identical problem. Many thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jun 2014 11:15:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42534#M31230</guid>
      <dc:creator>jstacey</dc:creator>
      <dc:date>2014-06-25T11:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42535#M31231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why did deactivation the replay-protection resolve your issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jun 2014 14:12:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42535#M31231</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-06-25T14:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42536#M31232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I was not logged in for a while.&lt;/P&gt;&lt;P&gt;I am not really sure. The tunnel between PA-VM and ScreenOS 6.3. did not become stable for long. (300Mbit max throughput , 20ms latency, no measurable packet loss).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2014 11:26:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/42536#M31232</guid>
      <dc:creator>Unibw</dc:creator>
      <dc:date>2014-09-17T11:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN restarts very often</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/381119#M89727</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were also running into same issue, with NO tunnel monitors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every 3 seconds or 5 seconds our SPI will change, or reset to different; indicating that new 'interesting traffic' has been selected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was very weird behavior, certain hosts could ping fine but others wouldn't, tunnel kept resetting every 3-5 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The remote end/peer was Fortinet firewall.&amp;nbsp; Turns out, our peer was doing 'strict phase 2 IP selection' in Route-Based Tunnel.&amp;nbsp; In other words, in palo alto, even in route-based tunnel, we had to define proxy ID, and everything started to come normal!!!!!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 03:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-vpn-restarts-very-often/m-p/381119#M89727</guid>
      <dc:creator>ahmadzubair654</dc:creator>
      <dc:date>2021-01-21T03:55:58Z</dc:date>
    </item>
  </channel>
</rss>

