<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Frequent re-keying of ipsec tunnels in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-re-keying-of-ipsec-tunnels/m-p/78070#M42808</link>
    <description>&lt;P&gt;When I look under Monitor -&amp;gt; Logs -&amp;gt; System, I see the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. ipsec-key-delete: IPSec key deleted. &amp;nbsp;Deleted SA &amp;lt;SA info&amp;gt; SPI:&amp;lt;hex dump&amp;gt;&lt;/P&gt;
&lt;P&gt;2. ike-nego-p2-succ: IKE phase-2 negotiation is succeeded as responder, quick mode. &amp;nbsp;Established SA &amp;lt;SA info&amp;gt; SPI: &amp;lt;hex dump&amp;gt;&lt;/P&gt;
&lt;P&gt;3. ipsec-key-install: IPSec key installed. &amp;nbsp;Installed SA &amp;lt;SA info&amp;gt; SPI: &amp;lt;hex dump&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have several site to site tunnels on this firewall, some of them with multiple proxy id's. &amp;nbsp;If I filter based on one specific proxy id, I see it going through this process frequently. &amp;nbsp;Sometimes it is multiple times per minute, sometimes it goes ~5 minutes or so. &amp;nbsp;The same occurs for numerous other proxy id's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this something to be concerned about? It seems that I'm receiving delete messages that correspond to this behavior:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ike-recv-p2-delete: IKE protocol IPSec SA delete message received from peer. &amp;nbsp;SPI: &amp;lt;hex dump&amp;gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2016 17:54:35 GMT</pubDate>
    <dc:creator>PatrickWalton</dc:creator>
    <dc:date>2016-05-13T17:54:35Z</dc:date>
    <item>
      <title>Frequent re-keying of ipsec tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-re-keying-of-ipsec-tunnels/m-p/78070#M42808</link>
      <description>&lt;P&gt;When I look under Monitor -&amp;gt; Logs -&amp;gt; System, I see the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. ipsec-key-delete: IPSec key deleted. &amp;nbsp;Deleted SA &amp;lt;SA info&amp;gt; SPI:&amp;lt;hex dump&amp;gt;&lt;/P&gt;
&lt;P&gt;2. ike-nego-p2-succ: IKE phase-2 negotiation is succeeded as responder, quick mode. &amp;nbsp;Established SA &amp;lt;SA info&amp;gt; SPI: &amp;lt;hex dump&amp;gt;&lt;/P&gt;
&lt;P&gt;3. ipsec-key-install: IPSec key installed. &amp;nbsp;Installed SA &amp;lt;SA info&amp;gt; SPI: &amp;lt;hex dump&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have several site to site tunnels on this firewall, some of them with multiple proxy id's. &amp;nbsp;If I filter based on one specific proxy id, I see it going through this process frequently. &amp;nbsp;Sometimes it is multiple times per minute, sometimes it goes ~5 minutes or so. &amp;nbsp;The same occurs for numerous other proxy id's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this something to be concerned about? It seems that I'm receiving delete messages that correspond to this behavior:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ike-recv-p2-delete: IKE protocol IPSec SA delete message received from peer. &amp;nbsp;SPI: &amp;lt;hex dump&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 17:54:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frequent-re-keying-of-ipsec-tunnels/m-p/78070#M42808</guid>
      <dc:creator>PatrickWalton</dc:creator>
      <dc:date>2016-05-13T17:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: Frequent re-keying of ipsec tunnels</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-re-keying-of-ipsec-tunnels/m-p/78260#M42877</link>
      <description>&lt;P&gt;Phase 2 (Each proxy ID) should be negotiated according to the key lifetime, so if in one side it's set to 5 minutes that's normal. You don't usually want to re-ley that often, if you're receiving delete messages the re-keys need to be troubleshooted in the side deleting the SA. If the other side it's also a palo alto a rekey can be triggered if tunnel monitoring is detected as "down",&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Understanding-behavior-of-PBF-and-Tunnel-monitoring-probes/ta-p/68666" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Understanding-behavior-of-PBF-and-Tunnel-monitoring-probes/ta-p/68666&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can check the remaining lifetime for your Phases 2 with the following command,&lt;/P&gt;
&lt;P&gt;&amp;gt;show vpn flow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gerardo.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 03:57:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frequent-re-keying-of-ipsec-tunnels/m-p/78260#M42877</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2016-05-18T03:57:34Z</dc:date>
    </item>
  </channel>
</rss>

