<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC Tunnel messages and failure in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/179884#M55773</link>
    <description>&lt;P&gt;We have 5 different tunnels.&amp;nbsp; Even doing 2500 shows&amp;nbsp;less than 2hours of logs&lt;/P&gt;&lt;PRE&gt;tail lines 2500 mp-log ikemgr.log&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Oct 2017 17:05:51 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2017-10-03T17:05:51Z</dc:date>
    <item>
      <title>IPSEC Tunnel messages and failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/179629#M55713</link>
      <description>&lt;P&gt;On Weelkend, one of our tunnels was down for about an hour. I was checking system logs and found these messages repeatedly for that tunnel, even after it is up. Anybody knows what this means and what to look for in logs to find the cause of tunnel failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;'the packet retransmitted in a short time from x.x.x.x[500]'&lt;/P&gt;&lt;P&gt;'IKE phase-2 negotiation request received but no phase-1 SA is found. Message sent from IP x.x..x.x[500] to y.y.y.y[500]'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 17:40:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/179629#M55713</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-10-02T17:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel messages and failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/179753#M55723</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please post full log output from the CLI:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&amp;gt; tail lines 100 mp-log ikemgr.log&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This guide is quite good if you want to get an additional info:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/How-to-Open-a-Case-on-IPSec-VPN-Issues/ta-p/102233" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/How-to-Open-a-Case-on-IPSec-VPN-Issues/ta-p/102233&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 08:22:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/179753#M55723</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-10-03T08:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel messages and failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/179884#M55773</link>
      <description>&lt;P&gt;We have 5 different tunnels.&amp;nbsp; Even doing 2500 shows&amp;nbsp;less than 2hours of logs&lt;/P&gt;&lt;PRE&gt;tail lines 2500 mp-log ikemgr.log&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 17:05:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/179884#M55773</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-10-03T17:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel messages and failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/179909#M55783</link>
      <description>&lt;P&gt;Was this one time issue?&lt;/P&gt;&lt;P&gt;It it happens every now and then in this case check if DPD settings are same at both sides (either on or off).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://live.paloaltonetworks.com/t5/Configuration-Articles/Dead-Peer-Detection-and-Tunnel-Monitoring/ta-p/61371" href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Dead-Peer-Detection-and-Tunnel-Monitoring/ta-p/61371" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Dead-Peer-Detection-and-Tunnel-Monitoring/ta-p/61371&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 21:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/179909#M55783</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-03T21:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel messages and failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/180115#M55815</link>
      <description>&lt;P&gt;These messages are continous, but it was down this time only and there is no DPD configured on either side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;'the packet retransmitted in a short time from x.x.x.x[500]'&lt;/P&gt;&lt;P&gt;'IKE phase-2 negotiation request received but no phase-1 SA is found. Message sent from IP x.x..x.x[500] to y.y.y.y[500]'&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 20:32:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/180115#M55815</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-10-04T20:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel messages and failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/180189#M55821</link>
      <description>&lt;P&gt;Anything in Monitor &amp;gt; System log about phase 1 take down?&lt;/P&gt;&lt;P&gt;( subtype eq vpn ) and ( description contains 'phase-1' )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase 1 key lifetime values are same?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;less mp-log ikemgr.log&lt;/P&gt;&lt;P&gt;/&lt;SPAN&gt;x.x.x.x[500]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/following-searchkeyword - search function to look up logs for this partner&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 00:34:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/180189#M55821</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-10-05T00:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel messages and failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/180367#M55846</link>
      <description>&lt;P&gt;I see these 2 mesages related to phase 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Deleting a possible stale phase-1 SA. cookie:45d6eddfe123a631:437d84921654er2c&lt;/P&gt;&lt;P&gt;IKE protocol phase-1 SA delete message sent to peer. cookie:&lt;SPAN&gt;45d6eddfe123a631:437d84921654er2c&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have control on other end, will have to ask for it.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 19:07:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/180367#M55846</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2017-10-05T19:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel messages and failure</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/180378#M55849</link>
      <description>&lt;P&gt;Unfortunately, without the&amp;nbsp;full log files/messages we can only guess.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 19:34:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-messages-and-failure/m-p/180378#M55849</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-10-05T19:34:47Z</dc:date>
    </item>
  </channel>
</rss>

