<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKEv2 renegotiation on acceptor gateway reboot in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-renegotiation-on-acceptor-gateway-reboot/m-p/209873#M61325</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did use tunnel-monitoring with the following params, and associated it with the IPSec tunnel:&lt;/P&gt;&lt;P&gt;1. Action - Wait-Recover&lt;/P&gt;&lt;P&gt;2. Interval - 2 secs&lt;/P&gt;&lt;P&gt;3. Threshold - 2 secs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Apr 2018 19:50:18 GMT</pubDate>
    <dc:creator>rameshgi</dc:creator>
    <dc:date>2018-04-12T19:50:18Z</dc:date>
    <item>
      <title>IKEv2 renegotiation on acceptor gateway reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-renegotiation-on-acceptor-gateway-reboot/m-p/209833#M61312</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a site-to-site IPSec connectivity with Palo Alto gateway (PA-VM 8.0.5 on kvm hypervisor - CentOS 7 host) on one end as initiator and Vyatta OS based gateway on the other end as acceptor.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When IKEv2 and IPSec (and BGP) are in established state, and the Vyatta OS reboots, it takes about 6 minutes for PA-VM to detect outage and renegotiate IKEv2.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The IKE Crypto has "Key Lifetime" set to 8 hours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question:&lt;/P&gt;&lt;P&gt;1. What configuration needs to be done (or can be done) in PA-VM for IKE to negotiate sooner ? (Is it a good idea to set Key Lifetime param in IKE Crypto to 3 minutes ?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. What is the industry best practice for setting up site-to-site VPNs in order to minimize outages due to peer firewall going down ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 17:37:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-renegotiation-on-acceptor-gateway-reboot/m-p/209833#M61312</guid>
      <dc:creator>rameshgi</dc:creator>
      <dc:date>2018-04-12T17:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 renegotiation on acceptor gateway reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-renegotiation-on-acceptor-gateway-reboot/m-p/209872#M61324</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87432"&gt;@rameshgi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I imagine that you are not doing any tunnel monitoring?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 19:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-renegotiation-on-acceptor-gateway-reboot/m-p/209872#M61324</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-12T19:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 renegotiation on acceptor gateway reboot</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-renegotiation-on-acceptor-gateway-reboot/m-p/209873#M61325</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did use tunnel-monitoring with the following params, and associated it with the IPSec tunnel:&lt;/P&gt;&lt;P&gt;1. Action - Wait-Recover&lt;/P&gt;&lt;P&gt;2. Interval - 2 secs&lt;/P&gt;&lt;P&gt;3. Threshold - 2 secs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 19:50:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-renegotiation-on-acceptor-gateway-reboot/m-p/209873#M61325</guid>
      <dc:creator>rameshgi</dc:creator>
      <dc:date>2018-04-12T19:50:18Z</dc:date>
    </item>
  </channel>
</rss>

