<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic site-to-site VPN / no &amp;quot;IKE Info&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-no-quot-ike-info-quot/m-p/195617#M58402</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a couple of VPN's which have just been transitioned to the PA firewall. Under network &amp;gt; ipsec tunnels &amp;gt; the VPN status shows as up, but the "IKE info" shows as down, with no info. If I run: "show vpn ike-sa detail gateway" there is nothing listed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I run "test vpn ipsec-sa tunnel" it brings it up and shows&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKE Phase1 SA:&lt;BR /&gt;Cookie: FFAFE29D66F1B89F:ECC8B630093A918E Init&lt;BR /&gt;State: Dying&lt;BR /&gt;Mode: Main&lt;BR /&gt;Authentication: PSK&lt;BR /&gt;Proposal: 3DES/SHA1/DH2&lt;BR /&gt;NAT: PEER&lt;BR /&gt;Message ID: 0, phase 2: 0&lt;BR /&gt;Phase 2 SA created : 1&lt;BR /&gt;Created: Jan.18 12:47:21, 1 minute 58 seconds ago&lt;BR /&gt;Expires: Jan.19 12:47:21&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I then run "clear vpn ipsec-sa tunnel" it reverts to the down state, and remains there until I re-run "test..."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My concern is that is shows state "Dying" and that at some point soon it will "die" and won't come back without my intervention.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone seen this, or can they please explain what this means and how to resolve?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2018 23:56:14 GMT</pubDate>
    <dc:creator>SARowe_NZ</dc:creator>
    <dc:date>2018-01-17T23:56:14Z</dc:date>
    <item>
      <title>site-to-site VPN / no "IKE Info"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-no-quot-ike-info-quot/m-p/195617#M58402</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a couple of VPN's which have just been transitioned to the PA firewall. Under network &amp;gt; ipsec tunnels &amp;gt; the VPN status shows as up, but the "IKE info" shows as down, with no info. If I run: "show vpn ike-sa detail gateway" there is nothing listed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I run "test vpn ipsec-sa tunnel" it brings it up and shows&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKE Phase1 SA:&lt;BR /&gt;Cookie: FFAFE29D66F1B89F:ECC8B630093A918E Init&lt;BR /&gt;State: Dying&lt;BR /&gt;Mode: Main&lt;BR /&gt;Authentication: PSK&lt;BR /&gt;Proposal: 3DES/SHA1/DH2&lt;BR /&gt;NAT: PEER&lt;BR /&gt;Message ID: 0, phase 2: 0&lt;BR /&gt;Phase 2 SA created : 1&lt;BR /&gt;Created: Jan.18 12:47:21, 1 minute 58 seconds ago&lt;BR /&gt;Expires: Jan.19 12:47:21&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I then run "clear vpn ipsec-sa tunnel" it reverts to the down state, and remains there until I re-run "test..."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My concern is that is shows state "Dying" and that at some point soon it will "die" and won't come back without my intervention.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone seen this, or can they please explain what this means and how to resolve?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 23:56:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-no-quot-ike-info-quot/m-p/195617#M58402</guid>
      <dc:creator>SARowe_NZ</dc:creator>
      <dc:date>2018-01-17T23:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: site-to-site VPN / no "IKE Info"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-no-quot-ike-info-quot/m-p/195809#M58425</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58478"&gt;@SARowe_NZ&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is normal behavior depending on your tunnel setup. Here is a document that discusses what exactly is going on, but essentially your Phase 1 is down because it doesn't need to be up once Phase2 is operational.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/IPSec-VPN-IKE-Phase-1-is-Down-but-Tunnel-is-Active/ta-p/53085" target="_blank"&gt;HERE&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 20:58:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-no-quot-ike-info-quot/m-p/195809#M58425</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-18T20:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: site-to-site VPN / no "IKE Info"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-no-quot-ike-info-quot/m-p/195812#M58426</link>
      <description>&lt;P&gt;Perfect thank you! Suprised those articles did not come up in my searches.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 21:03:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-no-quot-ike-info-quot/m-p/195812#M58426</guid>
      <dc:creator>SARowe_NZ</dc:creator>
      <dc:date>2018-01-18T21:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: site-to-site VPN / no "IKE Info"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-no-quot-ike-info-quot/m-p/196172#M58475</link>
      <description>&lt;P&gt;you will also reset the phases if you face issue.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 11:38:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-no-quot-ike-info-quot/m-p/196172#M58475</guid>
      <dc:creator>Fahadvu</dc:creator>
      <dc:date>2018-01-22T11:38:42Z</dc:date>
    </item>
  </channel>
</rss>

