<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there any reason that tunnel interface will go down in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131171#M46921</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I reviewed ikemgr.log but could not find anything realted to this, I enabled debug for ikemgr.log as well but no luck.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2016 15:24:54 GMT</pubDate>
    <dc:creator>fozail</dc:creator>
    <dc:date>2016-12-05T15:24:54Z</dc:date>
    <item>
      <title>Is there any reason that tunnel interface will go down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/130997#M46889</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured two IPSEC VPN on PA, as PA has two ISP connectivity. Configured a PBF to forward the traffic through primary tunnel interface and enabled monitoring to monitor trust interface of remote PA. A route was configured to forward the traffic the traffic through secondary tunnel interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found that traffic was always forwarded through secondary tunnel interface. Reviewed and could see that PBF is in DISABLED state as I had enabled if monitor is not successfull disable this PBF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reviewed and could see that PBF moniotr got failed because tunnel interface was down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I am not doing any tunnel monitoring, tunnel monitor should not go down at all&amp;nbsp;if appliance is up and running.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please let me know how to find out why tunnel interface went down?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fozail&lt;/P&gt;</description>
      <pubDate>Sun, 04 Dec 2016 09:54:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/130997#M46889</guid>
      <dc:creator>fozail</dc:creator>
      <dc:date>2016-12-04T09:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any reason that tunnel interface will go down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131077#M46901</link>
      <description>&lt;P&gt;Maybe there was no traffic to keep that tunnel alive.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 09:01:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131077#M46901</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-12-05T09:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any reason that tunnel interface will go down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131099#M46905</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you check ikemgr.logs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; tail lines 100 mp-log ikemgr.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 10:13:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131099#M46905</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-05T10:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any reason that tunnel interface will go down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131171#M46921</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I reviewed ikemgr.log but could not find anything realted to this, I enabled debug for ikemgr.log as well but no luck.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 15:24:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131171#M46921</guid>
      <dc:creator>fozail</dc:creator>
      <dc:date>2016-12-05T15:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any reason that tunnel interface will go down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131172#M46922</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean to say that tunnel interface went down not IPSEC VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 15:25:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131172#M46922</guid>
      <dc:creator>fozail</dc:creator>
      <dc:date>2016-12-05T15:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any reason that tunnel interface will go down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131199#M46929</link>
      <description>&lt;P&gt;Do you have a static or dymaic IP on both ends of the tunnel? If you go into the Montior and then the System tab using the&amp;nbsp;( subtype eq vpn ) query string will show you all VPN events, it may show you that the IKE or IPSEC didn't negotiate correctly or possibly were deleted before negotiating a new set of keys.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 16:10:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131199#M46929</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-05T16:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any reason that tunnel interface will go down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131210#M46931</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked the system log with subtype as vpn, but could not find anything related to tunnel interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attempted to review the output of the command "show log system | match tunnel.5" but no luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IPSEC VPN gets negotiated successfully, both phase-I and phase-II reflects green, only tunnel interface is down and hence the routes associated with that tunnel interface gets removed from routing table.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 16:24:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131210#M46931</guid>
      <dc:creator>fozail</dc:creator>
      <dc:date>2016-12-05T16:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Is there any reason that tunnel interface will go down</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131248#M46939</link>
      <description>&lt;P&gt;If you run&amp;nbsp;&lt;EM&gt;show vpn ipsec-sa tunnel&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;*name*, do you show anything under the ipsec? It sounds like you likely have a part of the configuaration malformed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If tunnels are up but traffic is not passing through the tunnel:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Check security policy and routing.&lt;/LI&gt;&lt;LI&gt;Check for any devices upstream that perform port-and-address-translations. Because ESP is a layer 3 protocol, ESP packets do not have port numbers. When such devices receive ESP packets, there is a high possibility they may silently drop them, because they do not see the port numbers to translate.&lt;/LI&gt;&lt;LI&gt;Apply debug packet filters, captures or logs, if necessary, to isolate the issue where the traffic is getting dropped.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 05 Dec 2016 18:19:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-any-reason-that-tunnel-interface-will-go-down/m-p/131248#M46939</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-05T18:19:33Z</dc:date>
    </item>
  </channel>
</rss>

