<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site 2 Site VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158543#M51870</link>
    <description>And (or only) application: ike&lt;BR /&gt;&lt;BR /&gt;Do you have drops in the traffic log between your gw ip and the other side?</description>
    <pubDate>Sat, 27 May 2017 09:28:58 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2017-05-27T09:28:58Z</dc:date>
    <item>
      <title>Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158538#M51866</link>
      <description>&lt;P&gt;We have a S2S VPN set up with a Juniper SRX at a partner site.&lt;/P&gt;&lt;P&gt;The P1 key life time is 8hr and P2 life time is 1hr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are seeing that the VPN drops quite frequiently. After they have had a look at the logs they are saying that during the re-key phase our end is timeing out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure how to get debug logs , we run PAN OS 7.1.7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The have provided some logs from their appliance&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]P1 SA 298686138 timer expiry. ref cnt 2, timer reason Force delete timer expired (1), flags 0x0.&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]iked_pm_ike_sa_delete_done_cb: For p1 sa index 298686138, ref cnt 2, status: Error ok&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]ike_remove_callback: Start, delete SA = { 9199f4de 2130d33b - 00000000 00000000}, nego = -1&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]&lt;A href="https://protect-eu.mimecast.com/s/p118BUbDnKTq?domain=185.10.91.254" target="_blank"&gt;185.xx.xx.xx:500&lt;/A&gt; (Initiator) &amp;lt;-&amp;gt; &lt;A href="https://protect-eu.mimecast.com/s/LKKGBt7novsM?domain=212.240.89.187" target="_blank"&gt;212.xx.xx.xx:500&lt;/A&gt; { 9199f4de 2130d33b - 00000000 00000000 [-1] / 0x00000000 } IP; Connection timed out or error, calling callback&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]ikev2_fb_v1_encr_id_to_v2_id: Unknown IKE encryption identifier -1&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]ikev2_fb_v1_hash_id_to_v2_prf_id: Unknown IKE hash alg identifier -1&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]ikev2_fb_v1_hash_id_to_v2_integ_id: Unknown IKE hash alg identifier -1&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]iked_pm_ike_sa_done: UNUSABLE p1_sa 298686138&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]&amp;nbsp; IKEv1 Error : Timeout&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]IPSec Rekey for SPI 0x0 failed&lt;/P&gt;&lt;P&gt;[May 26 14:59:13 PIC 2/1/0 KMD2]IPSec SA done callback called for sa-cfg GT-ike-vpn- local:185.10.xx.xx, remote:212.240.xx.xx IKEv1 with status Timed out&lt;/P&gt;&lt;P&gt;++++++++++++++&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can any one point me in the right direction.&lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2017 00:00:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158538#M51866</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2017-05-27T00:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158542#M51869</link>
      <description>&lt;P&gt;Do you allow ipsec traffic&amp;nbsp;from another end to your external interface:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9421iD96BBF94C32D27E7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="policy.JPG" alt="policy.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://protect-eu.mimecast.com/s/p118BUbDnKTq?domain=185.10.91.254" target="_blank" rel="nofollow noopener noreferrer"&gt;185.xx.xx.xx:500&lt;/A&gt;&lt;SPAN&gt; (Initiator) my understanding this is SRX interface? If this ip is initiator make sure&amp;nbsp;you allow above app&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2017 08:34:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158542#M51869</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-27T08:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158543#M51870</link>
      <description>And (or only) application: ike&lt;BR /&gt;&lt;BR /&gt;Do you have drops in the traffic log between your gw ip and the other side?</description>
      <pubDate>Sat, 27 May 2017 09:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158543#M51870</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-05-27T09:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158641#M51928</link>
      <description>&lt;P&gt;Yes I have some dropped traffic comeing from the remote end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pa.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9444i2788B70EA05415A3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="pa.png" alt="pa.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am unclear of is why does the dest end deemed to be internal , when it is my public IP.&lt;/P&gt;&lt;P&gt;Do I need a new rule to allow this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 17:09:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158641#M51928</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2017-05-29T17:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158643#M51929</link>
      <description>&lt;P&gt;Interesting. I think l had this before (or very similar issue). Can you please make sure to clear all active sessions from the session browser on your box from the external&amp;nbsp;ip address&amp;nbsp;(SRX):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Z.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9445iC1E85D16D900C2F1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Z.JPG" alt="Z.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For sure your destination zone should be External &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 17:17:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158643#M51929</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-29T17:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158644#M51930</link>
      <description>&lt;P&gt;I also had a very similar issue where we had dropped packets when a rekey occured. Maybe you should give 7.1.9 (thats the version where the problem was gone in my case) or 7.1.10 a chance ...&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 17:21:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158644#M51930</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-05-29T17:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Site 2 Site VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158709#M51958</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32033"&gt;@RC-BHF&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I've noticed this with quite a few ASAs; upgrading to 7.1.9 seems to have fixed the issue for us in our case; before the upgrade I had simply just set the key life to the point where it wouldn't rekey in business hours, kind of a hacky solution but it worked fine until I could upgrade the unit.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2017 15:47:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-2-site-vpn/m-p/158709#M51958</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-30T15:47:21Z</dc:date>
    </item>
  </channel>
</rss>

